Security estimation method and system based on attack separation and reconstruction of unknown input

By designing a fully symmetric multicellular unknown input observer, the security state estimation problem under the joint existence of network attacks and unknown inputs is solved, the separation and reconstruction of attacks is realized, and the stability and performance of the system are improved.

CN120277663BActive Publication Date: 2025-09-05WUHAN INST OF TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510721108.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-09-05
Estimated Expiration
2045-05-30

AI Technical Summary

Technical Problem

In a network control system, when unknown inputs and network attacks coexist, it is difficult for the prior art to effectively perform security state estimation, attack separation and reconstruction, affecting system stability and performance.

Method used

An unknown input observer based on a fully symmetric multicellular method is designed. By constructing multiple unknown input observers, the attack model and unknown set of attack actuators and sensors are determined, and attack separation and reconstruction are achieved.

Benefits of technology

It effectively solves the impact of unknown inputs and network attacks on the system, realizes the separation and reconstruction of security state estimation and attacks, and improves the stability and performance of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120277663B_ABST
    Figure CN120277663B_ABST
Patent Text Reader

Abstract

The present invention relates to a security estimation method and system based on attack separation and reconstruction of unknown inputs. The method comprises: constructing a system model based on the state variables and system matrix of the target system; determining an attack model and an unknown set of attacked actuators and sensors based on the system model and a data injection attack; constructing multiple unknown input observers based on a fully symmetric polytope method and the unknown set of attacked actuators and sensors; and determining an attack separation and reconstruction method based on each unknown input observer. The present invention addresses the problems of security state estimation, attack separation, and reconstruction in the presence of network attacks by designing unknown input observers for linear discrete systems containing unknown but bounded noise. The method is suitable for application scenarios requiring security state estimation and attack separation for systems containing unknown inputs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of wireless communication encryption, and in particular relates to a security estimation method and system based on attack separation and reconstruction of unknown input. Background Art

[0002] With the development of communication networks, cyberattacks have attracted increasing attention from researchers. In networked control systems, designing secure control estimators and controllers in the presence of cyberattacks is crucial, as it affects the stability of the system. Furthermore, in practical systems, unknown inputs are inevitable and may even degrade system performance. For example, in existing research, process disturbances, model errors, and system failures can all be considered unknown inputs. To gain a deeper understanding of the relevant information about cyberattacks, it is crucial to isolate and reconstruct it. Summary of the Invention

[0003] To solve the problems of security state estimation, attack separation, and reconstruction in the presence of network attacks, a first aspect of the present invention provides a security estimation method based on attack separation and reconstruction of unknown inputs, comprising:

[0004] Building a system model based on the state variables and system matrix of the target system; determining an attack model and an unknown set of attacked actuators and sensors based on the system model and the data injection attack;

[0005] Based on the fully symmetric polytope method, the unknown set of attacked actuators and sensors are used to construct multiple unknown input observers.

[0006] Based on each unknown input observer, an attack separation and reconstruction method is determined.

[0007] In some embodiments of the present invention, determining the attack model and the unknown attacked actuator set and sensor set based on the system model and data injection attack includes: determining the attack model based on the injection attack on the input channel and the sensor output channel; and determining the unknown attacked actuator set and sensor set based on the number of attack channels of the input channel and the sensor output channel.

[0008] Furthermore, the support sets of the injection attacks on the input channel and the sensor output channel belong to the unknown attacked actuator set and sensor set, respectively.

[0009] In some embodiments of the present invention, the construction of multiple unknown input observers based on the fully symmetric polyhedron method, the unknown attacked actuator set and the unknown sensor set includes: determining the number of attack channels based on the unknown attacked actuator set and the unknown sensor set; determining the satisfaction conditions of the fully symmetric polyhedron according to the number of attack channels and the ranks of multiple system matrices in the attack model; and constructing multiple unknown input observers according to the satisfaction conditions.

[0010] Furthermore, constructing multiple unknown input observers according to the satisfied conditions includes: if the conditions are satisfied, constructing a first unknown input observer according to the satisfied conditions; otherwise, constructing a second unknown input observer based on the unknown attacked actuator set and sensor set.

[0011] In the above embodiment, determining the attack separation and reconstruction method based on each unknown input observer includes: reconstructing the attack based on each unknown input observer; determining a reconstruction error based on the reconstruction result, and determining the attack separation method according to the reconstruction error.

[0012] A second aspect of the present invention provides a security estimation system based on attack separation and reconstruction of unknown input, comprising:

[0013] A first determination module is configured to construct a system model based on the state variables and system matrix of the target system; and determine an attack model and an unknown set of attacked actuators and sensors based on the system model and the data injection attack;

[0014] A building module for constructing multiple unknown input observers based on the fully symmetric polytope method, an unknown set of attacked actuators, and a set of sensors;

[0015] The second determination module is used to determine the attack separation and reconstruction method based on each unknown input observer.

[0016] Furthermore, the first determination module includes: a first determination unit, used to determine the attack model based on the injection attack of the input channel and the sensor output channel; a second determination unit, used to determine the unknown attacked actuator set and sensor set based on the number of attack channels of the input channel and the sensor output channel.

[0017] The third aspect of the present invention provides an electronic device comprising: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the security estimation method based on attack separation and reconstruction based on unknown input provided in the first aspect of the present invention.

[0018] A fourth aspect of the present invention provides a computer-readable medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the security estimation method based on attack separation and reconstruction based on unknown input provided in the first aspect of the present invention is implemented.

[0019] The beneficial effects of the present invention are:

[0020] This paper addresses the security state estimation, attack isolation, and reconstruction problems in the presence of cyberattacks for linear discrete systems with unknown but bounded noise by designing an unknown input observer. It also proposes a design method for an unknown input observer based on fully symmetric polytopes, which solves the security estimation problem for systems with unknown but bounded noise and determines the impact of system interference and noise on attack isolation and reconstruction. This paper is suitable for applications requiring security state estimation and attack isolation for systems with unknown inputs and has high application value. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 Schematic diagram of a basic flow chart of a security estimation method based on attack separation and reconstruction of unknown input in some embodiments of the present invention;

[0022] Figure 2 Schematic diagram of the principle of a security estimation method based on attack separation and reconstruction of unknown input in some embodiments of the present invention;

[0023] Figure 3 Schematic diagram of the structure of a security estimation device based on attack separation and reconstruction of unknown input in some embodiments of the present invention;

[0024] Figure 4 Schematic diagram of the structure of an electronic device in some embodiments of the present invention. DETAILED DESCRIPTION

[0025] The principles and features of the present invention are described below with reference to the accompanying drawings. The examples given are only used to explain the present invention and are not used to limit the scope of the present invention.

[0026] refer to Figure 1 and Figure 2 In a first aspect of the present invention, a security estimation method based on attack separation and reconstruction of unknown input is provided, comprising:

[0027] S100. Constructing a system model based on the state variables and system matrix of the target system; determining an attack model and an unknown set of attacked actuators and sensors based on the system model and the data injection attack;

[0028] S200. Construct multiple unknown input observers based on the fully symmetric polytope method, the unknown set of attacked actuators and the unknown set of sensors;

[0029] S300. Determine an attack separation and reconstruction method based on each unknown input observer.

[0030] As can be understood, an unknown input attack occurs when an attacker exploits vulnerabilities in wireless communication systems to send input signals that are not recognized or expected by the system, thereby interfering with or disrupting its normal operation. This type of attack is often difficult to detect because the input signals are not predefined or recognized by the system. The signals of unknown input attacks often resemble normal communication signals, making them difficult to detect using traditional detection methods. Attackers can generate unknown input signals in a variety of ways, including forged source IP addresses, abnormal packet sizes, and unusual request frequencies. The signals of unknown input attacks can also vary over time, making detection more challenging.

[0031] In step S100 of some embodiments of the present invention, determining the attack model and the unknown attacked actuator set and sensor set based on the system model and the data injection attack includes:

[0032] S101. Determine an attack model based on an injection attack on an input channel and a sensor output channel;

[0033] Specifically, the following discrete-time system model is first established:

[0034] (1)

[0035] (2)

[0036] in, is the system status, is the system control input, is the measurement output of the sensor, For system interference, is the noise of the sensor, A, B, C, D and F is a known system matrix; and satisfy and ,in and Indicates that the center is at the origin, and the generated matrix is Hω and Hv A fully symmetric polytope, and Hω and Hv is a given matrix; the initial value satisfies , p 0 and H 0 are the known center point and generator matrix respectively.

[0037] Considering that an attacker can launch a false data injection attack on the input channel and sensor output channel, the attack model is:

[0038] (3)

[0039] (4)

[0040] in, is the output of the controller, , , and is the number of corresponding attacked channels.

[0041] S102 . Determine an unknown attacked actuator set and sensor set based on the number of attack channels of the input channels and sensor output channels.

[0042] Specifically, define , ,but and Represent the unknown attacked actuators and sensor sets respectively. This paper assumes and is time-invariant and satisfies and , supp represents the support set, for example .

[0043] In step S200 of some embodiments of the present invention, constructing multiple unknown input observers based on the fully symmetric polytope method, the unknown set of attacked actuators, and the unknown set of sensors includes:

[0044] S201. Determine the number of attack channels based on the unknown set of attacked actuators and sensors;

[0045] S202. Determine the conditions for satisfying the fully symmetric polytope based on the number of attack channels and the ranks of multiple system matrices in the attack model;

[0046] Specifically, the present invention is based on whether the conditions are met , design two different unknown input observers. If ,So x For a n elements. For example, if , , then there is .

[0047] S203. Construct multiple unknown input observers according to the satisfied conditions.

[0048] Furthermore, constructing multiple unknown input observers according to the satisfied conditions includes: if the conditions are satisfied, constructing a first unknown input observer according to the satisfied conditions; otherwise, constructing a second unknown input observer based on the unknown attacked actuator set and sensor set.

[0049] The specific construction process of the first unknown input observer is:

[0050] If the conditions are met , consider a subset of the measurement output set , the corresponding unknown input observer can be designed as follows:

[0051] (5)

[0052] (6)

[0053] in, and are the estimated state and the observer state respectively, and the matrix and It can be obtained by the following algorithm:

[0054] (7)

[0055]

[0056] in, , , is an arbitrary matrix of appropriate dimension, and are the dimensions of the state and output vectors respectively. , we can solve the following inequality to get the matrix and , and then we get the matrix :

[0057] (8)

[0058] in, , , , , , .

[0059] Defining the estimation error ,if , then we can get by calculation ,in:

[0060] (9)

[0061] (10)

[0062] in, .

[0063] For each set , with potential , recorded as .definition and The maximum deviation between them is:

[0064] ;

[0065] definition , we can get the estimated state of the output of the fully symmetric polytope observer, that is, .

[0066] The specific construction process of the second unknown input observer is:

[0067] If the conditions are not met , the system after the attack is rewritten as follows:

[0068] (11)

[0069] (12)

[0070] in, , In this case, As an unknown input. The unknown input observer is designed as follows:

[0071] (13)

[0072] (14)

[0073] in, is the observer state, is the estimated state; definition , then the matrix 、 and The matrix needs to be is stable, and , .matrix 、 The calculation is done as follows:

[0074] (15)

[0075] (16)

[0076] in, , , is an arbitrary matrix of appropriate dimension, , By selecting , we can solve the following inequality to get the matrix and , and then we get the matrix ,

[0077] (17)

[0078] in, , , , , , , .

[0079] Defining the estimation error ,if , then we can get ,in

[0080] (18)

[0081] (19)

[0082] in, .

[0083] Assume the most q Actuators and q The sensors are attacked, i.e. , , so at least The sensor is not attacked.

[0084] (20)

[0085] in, , , , Therefore, the output of the fully symmetric polytope observer can be determined as follows:

[0086] (twenty one)

[0087] Right now , .

[0088] In step S300 of the above embodiment, determining the attack separation and reconstruction method based on each unknown input observer includes:

[0089] S301. Reconstruct the attack based on each unknown input observer;

[0090] Specifically, if Figure 2 The input of attack separation and reconstruction is the observer output , the center point of the observer error set. The attack reconstruction results are as follows:

[0091] , (twenty two)

[0092] in, .

[0093] S302. Determine a reconstruction error based on the reconstruction result, and determine an attack separation method according to the reconstruction error.

[0094] Specifically, the attack reconstruction error satisfies the following conditions:

[0095] , (twenty three)

[0096] in, ,

[0097] .

[0098] Based on this, the attack separation algorithm is as follows:

[0099] (twenty four)

[0100] Among them, if ,but ,otherwise ;if ,but ,otherwise . and are the sets of separated attacked actuators and sensors respectively.

[0101] Example 2

[0102] refer to Figure 3 In a second aspect of the present invention, a security estimation system 1 based on attack separation and reconstruction of unknown input is provided, comprising:

[0103] A first determination module 11 is configured to construct a system model based on the state variables and system matrix of the target system; and determine an attack model and an unknown set of attacked actuators and sensors based on the system model and the data injection attack.

[0104] A construction module 12 is used to construct multiple unknown input observers based on a fully symmetric polytope method, an unknown set of attacked actuators, and a set of sensors;

[0105] The second determining module 13 is configured to determine an attack separation and reconstruction method based on each unknown input observer.

[0106] Furthermore, the first determination module 11 includes: a first determination unit, used to determine the attack model based on the injection attack of the input channel and the sensor output channel; a second determination unit, used to determine the unknown attacked actuator set and sensor set based on the number of attack channels of the input channel and the sensor output channel.

[0107] Example 3

[0108] refer to Figure 4 According to a third aspect of the present invention, an electronic device is provided, comprising: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the security estimation method based on attack separation and reconstruction based on unknown input in the first aspect of the present invention.

[0109] The electronic device 500 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage device 508 into a random access memory (RAM) 503. Various programs and data required for the operation of the electronic device 500 are also stored in the RAM 503. The processing device 501, the ROM 502, and the RAM 503 are connected to each other via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0110] Typically, the following devices may be connected to the I / O interface 505: an input device 506 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 507 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 508 including, for example, a hard disk, etc.; and a communication device 509. The communication device 509 may allow the electronic device 500 to communicate with other devices wirelessly or by wire to exchange data. Figure 4The electronic device 500 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead. Figure 4 Each block shown in the figure may represent one device, or may represent multiple devices as needed.

[0111] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 509, or installed from the storage device 508, or installed from the ROM 502. When the computer program is executed by the processing device 501, the above-mentioned functions defined in the method of the embodiment of the present disclosure are executed. It should be noted that the computer-readable medium described in the embodiment of the present disclosure can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In embodiments of the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In embodiments of the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including, but not limited to, an electromagnetic signal, an optical signal, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device. Program code embodied on a computer readable medium may be transmitted using any appropriate medium, including but not limited to wire, optical cable, RF (radio frequency), etc., or any suitable combination thereof.

[0112] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device. The computer-readable medium carries one or more computer programs, which, when executed by the electronic device, cause the electronic device to:

[0113] Computer program code for performing the operations of embodiments of the present disclosure may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, Python, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0114] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0115] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A security estimation method based on attack separation and reconstruction of unknown input, characterized in that: include: Construct a system model based on the state variables and system matrix of the target system; Based on the system model and the data injection attack, determining an attack model and an unknown set of attacked actuators and sensors; Based on the fully symmetric polytope method, the unknown set of attacked actuators and sensors, multiple unknown input observers are constructed. The conditions for satisfying the fully symmetric polytope are determined based on the number of attack channels and the ranks of multiple system matrices in the attack model. Constructing a plurality of unknown input observers according to the satisfied conditions; wherein constructing a plurality of unknown input observers according to the satisfied conditions includes, if the conditions are satisfied, constructing a first unknown input observer according to the satisfied conditions; otherwise, constructing a second unknown input observer based on the unknown attacked actuator set and sensor set; Based on each unknown input observer, an attack separation and reconstruction method is determined.

2. The security estimation method based on attack separation and reconstruction of unknown input according to claim 1 is characterized in that: The determining of the attack model and the unknown attacked actuator set and sensor set based on the system model and the data injection attack includes: Determine the attack model based on the injection attack of the input channel and the sensor output channel; Based on the number of attack channels of input channels and sensor output channels, the unknown attacked actuator set and sensor set are determined.

3. The security estimation method based on attack separation and reconstruction of unknown input according to claim 2 is characterized in that: The support sets of the injection attacks on the input channel and the sensor output channel belong to the unknown attacked actuator set and sensor set respectively.

4. The security estimation method based on attack separation and reconstruction of unknown input according to claim 1 is characterized in that: The method of determining the attack separation and reconstruction based on each unknown input observer includes: Reconstruct the attack based on each unknown input observer; A reconstruction error is determined based on the reconstruction result, and an attack separation method is determined according to the reconstruction error.

5. A security estimation system based on attack separation and reconstruction of unknown input, characterized in that: include: A first determination module is used to construct a system model based on the state variables and system matrix of the target system; Based on the system model and the data injection attack, determining an attack model and an unknown set of attacked actuators and sensors; A construction module is used to construct multiple unknown input observers based on the fully symmetric polytope method, the unknown set of attacked actuators and the unknown set of sensors. The fully symmetric polytope satisfying conditions are determined according to the number of attack channels and the ranks of multiple system matrices in the attack model. Constructing a plurality of unknown input observers according to the satisfied conditions; wherein constructing a plurality of unknown input observers according to the satisfied conditions includes, if the conditions are satisfied, constructing a first unknown input observer according to the satisfied conditions; otherwise, constructing a second unknown input observer based on the unknown attacked actuator set and sensor set; The second determination module is used to determine the attack separation and reconstruction method based on each unknown input observer.

6. An electronic device comprising: one or more processors; A storage device for storing one or more programs, which, when executed by the one or more processors, enables the one or more processors to implement the security estimation method based on attack separation and reconstruction based on unknown input as described in any one of claims 1 to 4.

7. A computer-readable medium having a computer program stored thereon, wherein: When the computer program is executed by a processor, the security estimation method based on attack separation and reconstruction based on unknown input is implemented.

Citation Information

Patent Citations

  • Liquid level safety control method based on unknown input observer

    CN119165894A