Attack detection and security state estimation method and system based on centrosymmetric multi-cell body
Through the nonlinear crew estimation method based on the central symmetric multicellular body, a nonlinear system and attack model of the information physical fusion system is established, and an attack detection strategy is designed, which solves the problem of unknown but bounded noise nonlinear system attacks, realizes the system's timely detection and safe state recovery, and improves the system's security and state estimation accuracy.
Patent Information
- Application Number
- CN202510308642.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-17
- Publication Date
- 2025-07-08
AI Technical Summary
The prior art cannot effectively detect and mitigate unknown but bounded noise nonlinear system attacks in information physical fusion systems, and cannot restore the system security state in a timely manner.
A nonlinear crew estimation method based on central symmetric multicellular bodies is adopted to establish a nonlinear system and attack model, design an attack detection strategy, obtain a state estimation set through the crew estimation method, and implement a security state estimation algorithm when an attack is detected, including directly removing the attacked sensor or correcting the sensor measurement value.
Timely attack detection and security status estimation of information physics fusion systems is realized, the system's security and state estimation accuracy is improved, and a variety of attack types can be dealt with, reducing the impact of attacks on estimation performance.
Smart Images

Figure CN120281508A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to an attack detection and security state estimation method and system based on a centrosymmetric polytope. Background Art
[0002] In recent years, Cyber-Physical Systems (CPSs) have been proposed to define physical systems equipped with communication and computing capabilities. Through intelligent perception and information interaction, they achieve a tight combination of information processing and physical operations to ensure the safe, reliable, efficient, and real-time monitoring and control of physical systems, and realize the autonomous operation and collaborative cooperation of the entire system. Due to the existence of communication networks, CPSs are vulnerable to attacks by malicious attackers. Various attacks in the cyberspace may lead to a reduction in control performance, cause economic losses, and even threaten the safety of personnel, posing a serious threat to national security and people's lives.
[0003] Therefore, it is very important to ensure the security of Cyber-Physical Systems. To protect CPSs, defenders need to detect attacks. It should be noted that timely and effective attack detection strategies can only detect or identify anomalies caused by attacks, but cannot quickly weaken or eliminate the impact of attacks. How to design corresponding defense mechanisms based on attack models and detection methods aims to mitigate or eliminate the impact of attacks on the estimation performance. In practical engineering applications, developing attack detection methods should consider the design of security state estimation simultaneously, which has great significance and practical value; to resist cyber attacks, two main solutions have been proposed. One is to protect important system components in advance, and the other is to identify false data injected by attackers afterwards. The first solution can be achieved by deploying redundant components or redundant communication paths. For example, in the power system, phasor measurement units that are immune to malicious attacks are deployed. On the other hand, the scope of defense usually includes physical and network security, so authentication, access control, and security guards can be used to defend against physical intrusion, and encryption algorithms and firewalls can be used to defend against network intrusion. However, this method cannot fully protect system security. The second solution is used to remove or effectively correct damaged data when an attack is detected. Summary of the Invention
[0004] In view of the above problems, the present invention is proposed.
[0005] Therefore, the technical problem solved by the present invention is: the attack detection and security state estimation problem for an unknown but bounded noise nonlinear system.
[0006] To solve the above technical problem, the present invention provides the following technical solutions: In a first aspect, an embodiment of the present invention provides an attack detection and security state estimation method based on a centrosymmetric polytope, including: Based on a non - linear discrete - time system and false data injection attacks, establish a system model and an attack model for the non - linear system; The establishment of the system model and the attack model for the non - linear system based on the non - linear discrete - time system and false data injection attacks includes: Establish a system model for the non - linear system, expressed as: , , where, is a twice - continuously differentiable function, is the system state, represents the measured state output, is a twice - continuously differentiable function, and represent the disturbance noise and the measurement noise respectively; Set the initial conditions and bounded noise, , and , where, , and are known convex sets, is the time instant.
[0007] Based on the system model and the attack model of the non - linear system, according to the set - membership estimation method, obtain the state estimation set of the non - linear system; Based on the state estimation set of the non - linear system, perform attack detection through an attack detection strategy; When an attack is detected, estimate the secure state through a secure state estimation algorithm.
[0008] As a preferred scheme of the attack detection and secure state estimation method based on the centrally symmetric polytope, where: The establishment of the system model and the attack model for the non - linear system based on the non - linear discrete - time system and false data injection attacks further includes: Establish an attack model. When it is a false data injection attack model, it is expressed as: , where, represents the measured output when under attack, represents the time instant, represents the attack.
[0009] As a preferred scheme of the attack detection and secure state estimation method based on the centrally symmetric polytope, where: The obtaining of the state estimation set of the non - linear system according to the set - membership estimation method based on the system model and the attack model of the non - linear system includes: Calculate the state prediction set , calculate the set of measurement states , calculate the intersection to obtain the set of state estimates .
[0010] As a preferred solution of the attack detection and security state estimation method based on the centrosymmetric polytope, wherein: The attack detection of the set of state estimates based on the nonlinear system by the attack detection strategy includes: Design the attack detection strategy as: , Perform an intersection operation on the set of state estimates of the nonlinear system and the measurement band. When the operation result is an empty set, it means an attack exists; otherwise, it means no attack is detected.
[0011] As a preferred solution of the attack detection and security state estimation method based on the centrosymmetric polytope, wherein: When an attack is detected, the estimation of the security state by the security state estimation algorithm includes: Design two security state estimation algorithms, namely Case 1: directly remove the attacked sensor and Case 2: perform corrective measures on the attacked sensor.
[0012] As a preferred solution of the attack detection and security state estimation method based on the centrosymmetric polytope, wherein: The direct removal of the attacked sensor includes: Detect the attacked measurement band After that, directly perform the removal operation, and take the intersection of the remaining complete measurement band and the state prediction set to obtain the set of state estimates .
[0013] As a preferred solution of the attack detection and security state estimation method based on the centrosymmetric polytope, wherein: The corrective measures for the attacked sensor include: Correct the sensor containing fraudulent information, and replace the measured value of the damaged sensor with .
[0014] In a second aspect, an embodiment of the present invention provides an attack detection and security state estimation system based on a centrosymmetric polytope, including: A modeling module for establishing a system model and an attack model of a nonlinear system based on a nonlinear discrete-time system and a false data injection attack; An estimation set acquisition module for obtaining a set of state estimates of the nonlinear system based on the system model and the attack model of the nonlinear system according to the set membership estimation method; An attack detection module, configured to perform attack detection based on a set of state estimates of a nonlinear system through an attack detection strategy; A state estimation module, configured to estimate a secure state through a secure state estimation algorithm when an attack is detected.
[0015] In a third aspect, an embodiment of the present invention provides a computing device, including: A memory and a processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the one or more programs are executed by the one or more processors, the one or more processors implement the method for attack detection and secure state estimation based on a centrosymmetric polytope as described in any embodiment of the present invention.
[0016] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by a processor, the method for attack detection and secure state estimation based on a centrosymmetric polytope as described above is implemented.
[0017] Advantages of the present invention: By designing a detection strategy for false data injection attacks, the present invention can timely identify and respond to potential attacks in the system, thereby improving the security of the cyber-physical fusion system; by using the nonlinear set membership estimation method of centrosymmetric polytopes, the uncertainty of the system state can be more accurately described, improving the accuracy and reliability of state estimation; the proposed attack detection strategy can simultaneously cope with various types of attacks, including replay attacks, denial-of-service attacks, and false data injection attacks, and has wide applicability; in the case of detecting an attack, by two secure state estimation algorithms (removing the attacked sensor and correcting the sensor measurement value), the impact of the attack on the estimation performance is effectively alleviated, ensuring that the system continues to operate under reasonable estimation. Description of the Drawings
[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0019] Figure 1 It is the overall flowchart of the method for attack detection and secure state estimation based on a centrosymmetric polytope described in the present invention; Figure 2It is a schematic diagram of non - linear state estimation based on a centrally symmetric polytope in the simulation method of the attack detection and security state estimation method based on a centrally symmetric polytope according to the present invention; Figure 3 It is a schematic diagram of the attack detection effect in the simulation method of the attack detection and security state estimation method based on a centrally symmetric polytope according to the present invention; Figure 4 It is a schematic diagram of the security state estimation of a non - linear system in Case 1 in the simulation method of the attack detection and security state estimation method based on a centrally symmetric polytope according to the present invention; Figure 5 It is a schematic diagram of the security state estimation of a non - linear system in Case 2 in the simulation method of the attack detection and security state estimation method based on a centrally symmetric polytope according to the present invention. Specific Embodiments
[0020] To make the above - mentioned objects, features, and advantages of the present invention more obvious and understandable, the following provides a detailed description of the specific embodiments of the present invention with reference to the accompanying drawings of the specification. Obviously, the described embodiments are a part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0021] In the following description, many specific details are set forth to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0022] Secondly, the so - called "one embodiment" or "embodiment" refers to a specific feature, structure, or characteristic that can be included in at least one implementation manner of the present invention. The appearances of "in one embodiment" in different places in this specification do not all refer to the same embodiment, nor are they separate or alternative embodiments that are mutually exclusive with other embodiments.
[0023] Embodiment 1
[0024] Refer to Figure 1 , which is the first embodiment of the present invention. This embodiment provides an attack detection and security state estimation method based on a centrally symmetric polytope, including: S1: Based on a non - linear discrete - time system and false data injection attack, establish a system model and an attack model of the non - linear system; S2: Based on the system model and the attack model of the non - linear system, obtain the state estimation set of the non - linear system according to the set - membership estimation method; S3: Based on the state estimation set of the nonlinear system, perform attack detection through the attack detection strategy; S4: When an attack is detected, estimate the secure state through the secure state estimation algorithm.
[0025] It should be noted that through steps S1 - S4, set membership estimation is performed on the nonlinear system, and an attack detection strategy is designed using the central symmetric polyhedron set membership estimation method. It can simultaneously apply to the attack detection problems of replay attacks, denial - of - service attacks, and false data injection attacks, and has high application value.
[0026] In addition, through the attack detection results, when an attack is detected, two secure state estimation algorithms are studied. This method can reduce the impact of attacks on the estimation performance, enable the control system to operate within reasonable estimation performance, and avoid the operating mode deviating from the desired mode.
[0027] Embodiment 2
[0028] Refer to Figure 1 , which is an embodiment of the present invention. Based on the previous embodiment, an attack detection and secure state estimation method based on a central symmetric polyhedron is provided, including: In the embodiment of the present application, in step S1 above, based on the nonlinear discrete - time system and false data injection attack, establishing the system model and attack model of the nonlinear system includes: Establish the system model of the nonlinear system, expressed as: (1.1), (1.2), Among them, is a second - order continuously differentiable function, is the system state, represents the measured state output, is a second - order continuously differentiable function, and respectively represent the disturbance noise and the measurement noise; Set the initial conditions and bounded noise, , and , among which, , and are known convex sets, is the time instant.
[0029] Establish the attack model. When it is a false data injection attack model, it is expressed as: , Among them, represents the measured output when under attack, Indicates a moment, Indicates an attack.
[0030] In the embodiments of the present application, based on the system model and the attack model of the nonlinear system in the above step S2, according to the set membership estimation method, the state estimation set of the nonlinear system obtained includes: Calculate the state prediction set , calculate the measured state set , calculate the intersection to obtain the state estimation set .
[0031] Specifically, the state prediction set of the nonlinear system is expressed as: (1.3), Where: , According to formula (1.2), the measurement strip Satisfies the following conditions: (1.4), Where: , According to the central polytope set membership estimation method, the state estimation set of the nonlinear system is obtained, expressed as: (1.5), Where: , Where, Represents the state prediction set, , Are respectively the center point and the generation matrix representing the state prediction set; Represents Dimensional Euclidean space, Is Dimensional Euclidean space. 0 represents a zero matrix with appropriate dimensions, Represents element by element, And Respectively refer to the j-th column of the matrix and the i-th element of the vector b; The operator is defined as , where And , and Is an orthogonal unit vector; , assuming The state estimation set at time And , satisfy , , then the set The Cartesian product calculation satisfies: , where represents 's Hessian matrix; , Let the predicted state set at time k be and , satisfying , , then it satisfies: , where represents the state estimation set, , represents the center point and the generation matrix of the state estimation set.
[0032] In the embodiments of the present application, the attack detection based on the state estimation set of the non-linear system in the above step S3 includes: It should be noted that since there may be attacks on the sensor measurement values in the non-linear system, the received data may be different from the actual measurement value , where i represents the i-th channel number. Therefore, a new attack detection strategy is designed.
[0033] Specifically, the designed attack detection strategy is expressed as: , Take the intersection of the state estimation set of the non-linear system and the measurement band. When the operation result is an empty set, it means an attack exists; otherwise, it means no attack is detected.
[0034] In the embodiments of the present application, when an attack is detected in the above step S4, the estimation of the safe state by the safe state estimation algorithm includes: Two safe state estimation algorithms are designed, namely Case 1: directly remove the attacked sensor and Case 2: take corrective measures on the attacked sensor. Both algorithms can, to a certain extent, alleviate the rapid decline of the estimation performance.
[0035] Specifically, directly removing the attacked sensor includes: After detecting the attacked measurement band , directly perform the removal operation. The remaining complete measurement band is intersected with the state prediction set to obtain the state estimation set ; Remove the sensor containing fraudulent information, and the following expression can be derived through (1.5): (1.6), where, represents the state estimation set obtained after removing the attacked measurement tape.
[0036] Suppose the first sensor is under a malicious attack, and a false data injection attack is detected in the first sensor, that is when: (1.7), (1.8), where: , , where, represents the center point of the safe state set, is the generation matrix for the safe state set.
[0037] The corrective measures for the attacked sensor include: correcting the sensor containing fraudulent information, and replacing the measured value of the damaged sensor with , and the corrected sensor measurement value is expressed as follows: (1.9), The algorithm for nonlinear set - membership estimation based on the centrosymmetric polytope is as follows: (1.10), where: (1.11), (1.12), It should be noted that when an attack is detected, two safe state estimation algorithms are studied, which can mitigate the impact of the attack on the estimation performance, enable the control system to operate within a reasonable estimation performance, and avoid the operation mode deviating from the desired mode.
[0038] Embodiment 3 The above is a schematic solution of the attack detection and safe state estimation method based on the centrosymmetric polytope in this embodiment. It should be noted that the technical solution of the attack detection and safe state estimation system based on the centrosymmetric polytope belongs to the same concept as the technical solution of the above - mentioned attack detection and safe state estimation method based on the centrosymmetric polytope. For the details not described in detail in the technical solution of the attack detection and safe state estimation system based on the centrosymmetric polytope in this embodiment, reference can be made to the description of the technical solution of the above - mentioned attack detection and safe state estimation method based on the centrosymmetric polytope.
[0039] This embodiment also provides a system for an attack detection and security state estimation method based on a centrosymmetric polytope, including: A modeling module, configured to establish a system model and an attack model of a nonlinear system based on a nonlinear discrete-time system and a false data injection attack; An estimation set acquisition module, configured to obtain a state estimation set of the nonlinear system based on the system model and the attack model of the nonlinear system according to a set membership estimation method; An attack detection module, configured to perform attack detection through an attack detection strategy based on the state estimation set of the nonlinear system; A state estimation module, configured to estimate the security state through a security state estimation algorithm when an attack is detected.
[0040] This embodiment also provides a computing device applicable to the case of an attack detection and security state estimation method based on a centrosymmetric polytope, including: A memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the attack detection and security state estimation method based on a centrosymmetric polytope as proposed in the above embodiment.
[0041] This embodiment also provides a storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the attack detection and security state estimation method based on a centrosymmetric polytope as proposed in the above embodiment.
[0042] The storage medium proposed in this embodiment and the attack detection and security state estimation method based on a centrosymmetric polytope proposed in the above embodiment belong to the same inventive concept. Technical details not described in detail in this embodiment can be referred to the above embodiment, and this embodiment has the same beneficial effects as the above embodiment.
[0043] Embodiment 4 Referring to Figures 2 - 5 , as an embodiment of the present invention, an attack detection and security state estimation method based on a centrosymmetric polytope is provided. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through simulation experiments.
[0044] As Figure 2 shown, it is the nonlinear state estimation based on a centrosymmetric polytope. Among them, the blue solid line represents the state prediction set , the green solid line represents the state estimation set , the red solid line represents the measurement state set , and the green asterisk represents the true state. The abscissa and ordinate respectively represent the lateral position and the longitudinal position of the unmanned vehicle.
[0045] As Figure 3As shown, for the attack detection effect, when the measuring tape is attacked, the state prediction set and the measurement state set have no intersection. Therefore, according to the attack detection strategy, the existence of malicious attacks can be detected.
[0046] As Figure 4 shown, for the security state estimation of the non-linear system in Case 1, when the damaged sensor is removed, the algorithm still has good estimation performance. The red asterisk represents the true state.
[0047] As Figure 5 shown, for the security state estimation of the non-linear system in Case 2, when the damaged sensor is corrected, the algorithm still has good estimation performance. The red asterisk represents the true state.
[0048] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
Claims
1. An attack detection and security status estimation method based on centrally symmetric polytopes, characterized in that Including: Based on a non-linear discrete-time system and false data injection attacks, establish a system model and an attack model for the non-linear system; The establishing of the system model and the attack model for the non-linear system based on the non-linear discrete-time system and false data injection attacks includes: Establish a system model for the non-linear system, expressed as: , , Among them, is a second-order continuously differentiable function, is the system state, represents the measurement state output, is a second-order continuously differentiable function, and represent the disturbance noise and the measurement noise respectively; set the initial conditions and bounded noise, , and , among which, , and are known convex sets, is the time; Based on the system model and the attack model of the non-linear system, obtain the state estimation set of the non-linear system according to the set membership estimation method; Based on the state estimation set of the non-linear system, perform attack detection through an attack detection strategy; When an attack is detected, estimate the secure state through a secure state estimation algorithm.
2. The attack detection and security state estimation method based on a centrosymmetric polytope according to claim 1, wherein, The establishing of the system model and the attack model for the non-linear system based on the non-linear discrete-time system and false data injection attacks further includes: Establish an attack model, which is expressed as when there is a false data injection attack model: , Among them, represents the measurement output when under attack, represents the time, represents the attack.
3. The attack detection and security status estimation method based on centrosymmetric polytopes according to claim 2, wherein, The obtaining of the state estimation set of the non-linear system according to the set membership estimation method based on the system model and the attack model of the non-linear system includes: Calculated state prediction set , calculate the measurement state set , calculate the intersection to obtain the state estimation set .
4. The attack detection and security state estimation method based on centrosymmetric polytopes according to claim 3, characterized in that The performing of attack detection through an attack detection strategy based on the state estimation set of the non-linear system includes: Design an attack detection strategy, expressed as: , Perform an intersection operation on the state estimation set of the non-linear system and the measurement band. When the operation result is an empty set, it represents that an attack exists; otherwise, it means that no attack is detected.
5. The attack detection and security state estimation method based on a centrally symmetric polytope according to claim 4, wherein The estimating of the secure state through a secure state estimation algorithm when an attack is detected includes: Design two secure state estimation algorithms, namely Case 1: directly remove the attacked sensor and Case 2: perform corrective measures on the attacked sensor.
6. The attack detection and security state estimation method based on centrosymmetric polytopes according to claim 5, wherein, The directly removing the attacked sensor includes: The attacked measuring tape is detected and then directly removed. The remaining complete measuring tape intersects with the state prediction set to obtain the state estimation set .
7. The attack detection and security state estimation method based on centrosymmetric polytopes according to claim 6, wherein The performing of corrective measures on the attacked sensor includes: Perform corrective processing on sensors containing fraudulent information and replace the measured values of damaged sensors with .
8. A system adopting the attack detection and security state estimation method based on a centrosymmetric polytope as described in any one of claims 1 to 7, characterized in that, Including: A modeling module, used to establish a system model and an attack model for the non-linear system based on the non-linear discrete-time system and false data injection attacks; An estimation set obtaining module, used to obtain the state estimation set of the non-linear system according to the set membership estimation method based on the system model and the attack model of the non-linear system; An attack detection module, used to perform attack detection through an attack detection strategy based on the state estimation set of the non-linear system; A state estimation module, used to estimate the secure state through a secure state estimation algorithm when an attack is detected.
9. A computing device, including: A memory and a processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the attack detection and secure state estimation method based on the centrosymmetric polytope according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by a processor, the steps of the attack detection and secure state estimation method based on the centrosymmetric polytope according to any one of claims 1 to 7 are implemented.