Integrated learning high-sensitivity dynamic GNSS deception detection method
Through the combination of integrated learning and indirect Kalman filtering, the GNSS spoof detection indicators are dynamically selected, which solves the problem of identifying dynamic spoof signals in low carrier-to-noise environments, and improves the security and detection accuracy of the GNSS system.
Patent Information
- Application Number
- CN202510357639.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2045-03-25
AI Technical Summary
The existing GNSS spoof detection technology is difficult to effectively identify dynamically changing spoof signals in a low carrier-to-noise environment, and a single detection indicator cannot maintain reliable performance in the face of different spoof attack conditions, and the noise interference is severely affected.
The integrated learning method is adopted to smooth the multi-correlator SQM indicators through indirect Kalman filtering, and a variety of alternative spoof detection indicators are constructed, and machine learning models such as decision trees, random forests and K-nearest neighbors are used to dynamically select the best detection indicators, and combine the threshold to determine whether a spoof attack occurs.
It significantly improves the detection efficiency of spoofing attacks, improves the security and reliability of the GNSS system, and can promptly identify dynamically changing spoofing signals to reduce security risks.
Smart Images

Figure CN120507768A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of deception interference detection, and in particular to a high-sensitivity dynamic GNSS deception detection method based on integrated learning. Background Art
[0002] Global Navigation Satellite System (GNSS) signals are extremely weak and have an open signal format, making GNSS receivers highly susceptible to various interferences. Spoofing attacks, in particular, pose a serious threat to the security and reliability of GNSS applications. Spoofing attacks transmit forged GNSS signals, tricking receivers into outputting incorrect position or time information, thereby disrupting the normal operation of the entire system.
[0003] Existing spoofing detection technologies can be broadly categorized into signal space feature detection, measurement domain techniques, and baseband signal processing. Baseband signal processing technologies include power detection, navigation information detection, and signal quality monitoring (SQM). While these technologies offer advantages such as low cost and wide applicability, they exhibit significant limitations when faced with deceptive spoofing attacks. For example, power detection is only effective against high-power spoofing signals and is ineffective against deceptive spoofing attacks whose power is only slightly higher than that of the genuine signal. Navigation information detection primarily relies on the specific relationship between the Doppler frequency and bit rate of the genuine signal, but deceptive spoofing signals can also maintain this relationship to a certain extent, making detection more difficult. SQM technology detects spoofing by establishing detection indicators to identify anomalies in the signal correlation function. Its computational complexity is low and it does not require modifications to the receiver structure. However, this technology still has limitations in capturing dynamically changing spoofing signals, making it difficult to effectively address complex and changing spoofing scenarios.
[0004] The emergence of multi-correlator SQM technology has significantly improved the reliability and stability of traditional SQM spoofing detection. Indicators such as weighted dual ratio, orthogonal channel SQM, weighted second-order central moment, and sliding composite delta have been introduced, effectively improving detection accuracy by providing more robust signal integrity metrics. While multi-correlator SQM technology has made some progress in spoofing detection, it still faces significant challenges in the face of noise interference, which remains a key factor affecting detection performance. Furthermore, a single detection metric cannot provide robust detection against dynamically changing spoofing scenarios.
[0005] Existing multi-correlator SQM technology primarily focuses on detecting spoofing energy for spoofing detection. However, the vast majority of related work has overlooked the critical impact of noise on detection performance. Only a few studies have attempted to use mean filtering to smooth the original SQM metrics to reduce noise interference. However, mean filtering itself has inherent flaws that are difficult to overcome. For example, its noise reduction effectiveness is largely limited by the number of smoothing points. When the number of smoothing points is small, the noise reduction effect is poor. While increasing the number of smoothing points can improve noise reduction, it inevitably introduces latency issues and significantly reduces detection accuracy.
[0006] Furthermore, existing multi-correlator SQM technology overly relies on one or more static metrics when performing spoofing detection. However, because the performance of different SQM metrics is significantly affected by spoofing attack conditions, such as variations in spoofing signal strength, frequency, and latency, each of which can have varying degrees of impact on the detection effectiveness of each metric, no single metric can consistently and reliably detect all spoofing types. This makes accurately selecting the optimal SQM metric for specific spoofing attacks a challenging task in real-world applications. Summary of the Invention
[0007] This invention aims to address the challenge of effectively identifying dynamically changing spoofing signals in low carrier-to-noise ratio environments. To this end, it provides a highly sensitive dynamic GNSS spoofing detection method using ensemble learning. This method dynamically selects detection indicators to address diverse spoofing attack conditions, significantly improving detection efficiency and effectively enhancing the security and reliability of global navigation satellite systems.
[0008] The present invention provides a high-sensitivity dynamic GNSS spoofing detection method based on integrated learning, which adopts the following technical solution: Step 1: Obtain the output signal of the multi-correlator array and calculate the SQM index of the in-phase channel multi-correlator and the SQM index of the orthogonal channel multi-correlator; Step 2: Use indirect Kalman filtering to smooth the in-phase channel multi-correlator SQM index and the orthogonal channel multi-correlator SQM index respectively, and obtain the smoothed in-phase channel multi-correlator SQM index and the smoothed orthogonal channel multi-correlator SQM index, as well as the steady-state estimation error variance; Step 3: Constructing candidate spoofing detection indices based on the smoothed in-phase channel multi-correlator SQM index and the smoothed orthogonal channel multi-correlator SQM index, wherein the candidate spoofing detection indices include an in-phase channel index, an orthogonal channel index, a direct composite index, and an indirect composite index; Step 4: Input the smoothed in-phase channel multi-correlator SQM index, the smoothed orthogonal channel multi-correlator SQM index, and the steady-state estimation error variance into multiple machine learning models. Based on the output of the machine learning models, select one of the candidate spoofing detection indicators as the spoofing detection indicator. Step 5: Determine whether a deception attack has occurred based on the comparison result of the deception detection index and the corresponding threshold.
[0009] Furthermore, the same-phase channel multi-correlator SQM index and the SQM index of the orthogonal channel multi-correlator The expressions are: in, Indicates the spacing of the nth pair of correlators, where n ranges from 1, 2, ..., N, and N represents the number of logarithms of the multi-correlator array. Indicates the spacing is The in-phase channel advance correlator output of the correlator is Indicates the spacing is The in-phase channel lag correlator output of the correlator is Indicates the spacing is The orthogonal channel advance correlator output of the correlator, Indicates the spacing is The orthogonal channel lag correlator output of the correlator, represents the output of the in-phase channel instantaneous correlator, Represents The corresponding weighting coefficient.
[0010] Furthermore, in step 2, S21: Model construction of indirect Kalman filter. The state model and observation model of indirect Kalman filter are expressed as: in, Represents the SQM index of the same-phase multi-correlator at time k Or orthogonal channel multi-correlator SQM indicator status, Represents the SQM index of the k-1 time co-phase channel multi-correlator Or orthogonal channel multi-correlator SQM indicator status, represents the process noise, Represents the SQM index of the same-phase multi-correlator at time k Or orthogonal channel multi-correlator SQM indicator The measurement of represents the measurement noise; S22: Prediction and update of indirect Kalman filter. The prediction and update model of indirect Kalman filter is expressed as: in, Represents the SQM index of the same-phase channel multi-correlator from time k-1 to time k Or orthogonal channel multi-correlator SQM indicator A priori estimate of the state of Represents the SQM index of the k-1 time co-phase channel multi-correlator Or orthogonal channel multi-correlator SQM indicator The posterior estimate of the state of Represents the SQM index of the same-phase multi-correlator at time k Or orthogonal channel multi-correlator SQM indicator The posterior estimate of the state of represents the gain of the Kalman filter, The expression is: in, represents the measurement noise variance, It represents the variance of the prediction error, and its expression is: in, represents the variance of the state estimation error at time k-1, represents the variance of the state estimation error at time k, and q represents the variance of the process noise; S23: After the filter reaches steady state, the variance of the state estimation error remains unchanged, and the variance of the steady state estimation error The expression is: .
[0011] Further, The variance of , measurement noise variance The expression is: in, represents the carrier-to-noise ratio, represents the coherent integration time, Represents the spacing of the mth pair of correlators, where m ranges from 1, 2, ..., N. Represents The corresponding weighting coefficient is, Indicates that the GNSS signal autocorrelation function is The value of Indicates that the GNSS signal autocorrelation function is The value at .
[0012] Further, The variance of q is q, and the value of process noise variance q is: in, is the scaling factor.
[0013] Furthermore, the same faith channel indicator , orthogonal channel index , direct composite index and indirect composite indicators The expression is: in, It represents the SQM index of the smoothed in-phase channel multi-correlator. Represents the smoothed orthogonal channel multi-correlator SQM indicator.
[0014] Furthermore, each machine learning model outputs an alternative deception detection indicator, and the deception detection indicator is obtained by using the maximum vote method based on the alternative deception detection indicators output by multiple machine learning models.
[0015] Furthermore, the output of the machine learning model depends on the relative distance between the alternative deception detection indicator and the corresponding threshold, and the alternative deception detection indicator that deviates the most from the threshold is determined as the output.
[0016] Furthermore, if multiple alternative deception detection indicators receive the same number of votes, each machine learning model is assigned a corresponding weight based on its accuracy on the validation set, and the votes for each alternative deception detection indicator are weighted and scored. The alternative deception detection indicator with the highest score is selected as the deception detection indicator.
[0017] Furthermore, the machine learning model includes a decision tree model, a random forest model and a K-nearest neighbor model.
[0018] The above one or more technical solutions in the embodiments of the present invention have at least one of the following technical effects: The present invention is designed specifically for low carrier-to-noise ratio environments. Through the excellent tracking capability of indirect Kalman filtering for dynamic signals and the ability of integrated learning to analyze complex features, it can effectively identify dynamically changing deceptive signals, significantly improving detection reliability in complex environments and greatly enhancing the security of global navigation satellite systems in various scenarios.
[0019] This invention innovatively introduces indirect Kalman filtering technology. By constructing specific state and observation models, the state changes of the SQM indicators of the in-phase and quadrature channel multi-correlators are incorporated into the model. Furthermore, by properly setting the process noise variance, this method enables more accurate prediction and update of indicator states, effectively suppressing noise interference and improving the signal-to-noise ratio. This method far surpasses existing technologies in terms of the depth and effectiveness of noise processing.
[0020] This paper utilizes smoothed in-phase and orthogonal channel multi-correlator SQM indicators to construct multiple alternative spoofing detection metrics, including in-phase and orthogonal channel indicators, direct composite indicators, and indirect composite indicators. This construction method fully exploits the potential information of the multi-correlator SQM indicators, providing richer and more comprehensive data support for subsequent detection metric selection and spoofing detection, and is significantly different from existing indicator construction methods.
[0021] This invention uses an ensemble learning-based dynamic detection indicator selection mechanism. It uses the smoothed in-phase channel multi-correlator (SQM) and orthogonal channel multi-correlator (SQM) indicators, as well as the steady-state estimation error variance, as input features. Using independent machine learning modules consisting of decision trees (DTs), random forests (RFs), and K-nearest neighbors (KNNs), it makes a preliminary judgment based on the relative distance between the indicators and corresponding thresholds. Combined with a voting mechanism, it determines the optimal spoofing detection indicator from the prediction results of multiple models. This achieves dynamic and intelligent selection of detection indicators, in stark contrast to existing static, single-indicator selection methods.
[0022] This invention improves the signal-to-noise ratio through indirect Kalman filtering, providing a higher-quality data foundation for subsequent detection. Integrated learning dynamically selects indicators, leveraging the strengths of multiple models to enhance detection accuracy and reliability. Compared to existing technologies, this invention significantly improves detection sensitivity, accuracy, and reliability, enabling more timely and accurate detection of spoofing attacks and effectively reducing security risks.
[0023] Additional aspects and advantages of the present invention will be set forth in part in the description which follows and, in part, will be obvious from the description which follows, or may be learned by practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0025] Figure 1 It is a flow chart of the method provided by the present invention.
[0026] Figure 2 This is a cheating detection result diagram provided by the present invention. DETAILED DESCRIPTION
[0027] To make the purpose, technical solutions and advantages of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the present invention. Obviously, the embodiments described are part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention. The following embodiments are used to illustrate the present invention, but are not used to limit the scope of the present invention.
[0028] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the embodiment of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification and features of different embodiments or examples without contradiction.
[0029] The following combination Figure 1 and Figure 2 The present invention is further described in detail, which is an integrated learning high-sensitivity dynamic GNSS spoofing detection method of the present invention: In this embodiment, Figure 1 As shown, a high-sensitivity dynamic GNSS spoofing detection method using integrated learning is provided, comprising the following steps: Step 1: Use a high-sensitivity GNSS receiver to configure a multi-correlator array at equal intervals. Obtain the output signals of the multi-correlator array and calculate the SQM index of the in-phase and orthogonal channels.
[0030] In-phase channel multi-correlator SQM index and the SQM index of the orthogonal channel multi-correlator The expressions are: in, Indicates the spacing of the nth pair of correlators, where n ranges from 1, 2, ..., N, and N represents the number of logarithms of the multi-correlator array. Indicates the spacing is The in-phase channel advance correlator output of the correlator is Indicates the spacing is The in-phase channel lag correlator output of the correlator is Indicates the spacing is The orthogonal channel advance correlator output of the correlator, Indicates the spacing is The orthogonal channel lag correlator output of the correlator, represents the output of the in-phase channel instantaneous correlator, Represents The corresponding weighting coefficient.
[0031] Step 2: Use indirect Kalman filtering to smooth the in-phase channel multi-correlator SQM index and the orthogonal channel multi-correlator SQM index respectively to obtain the smoothed in-phase channel multi-correlator SQM index and the smoothed orthogonal channel multi-correlator SQM index, as well as the steady-state estimation error variance.
[0032] The specific process is: S21: Model construction of indirect Kalman filter. The state model and observation model of indirect Kalman filter are expressed as: in, Represents the SQM index of the same-phase multi-correlator at time k Or orthogonal channel multi-correlator SQM indicator status, Represents the SQM index of the k-1 time co-phase channel multi-correlator Or orthogonal channel multi-correlator SQM indicator status, represents the process noise, The variance of is q, Represents the SQM index of the same-phase multi-correlator at time k Or orthogonal channel multi-correlator SQM indicator The measurement of represents the measurement noise, The variance of .
[0033] Measurement noise variance The expression is: in, represents the carrier-to-noise ratio, represents the coherent integration time, Represents the spacing of the mth pair of correlators, where m ranges from 1, 2, ..., N. Represents The corresponding weighting coefficient is, Indicates that the GNSS signal autocorrelation function is The value of Indicates that the GNSS signal autocorrelation function is The value at .
[0034] The value of process noise variance q is: in, is the scaling factor, which should be greater than 1000.
[0035] S22: Prediction and update of indirect Kalman filter. The prediction and update model of indirect Kalman filter is expressed as: in, Represents the SQM index of the same-phase channel multi-correlator from time k-1 to time k Or orthogonal channel multi-correlator SQM indicator A priori estimate of the state of Represents the SQM index of the k-1 time co-phase channel multi-correlator Or orthogonal channel multi-correlator SQM indicator The posterior estimate of the state of Represents the SQM index of the same-phase multi-correlator at time k Or orthogonal channel multi-correlator SQM indicator The posterior estimate of the state of represents the gain of the Kalman filter.
[0036] The expression is: in, It represents the variance of the prediction error, and its expression is: in, represents the variance of the state estimation error at time k-1, represents the variance of the state estimation error at time k.
[0037] S23: After the filter reaches steady state, the variance of the state estimation error remains unchanged, and the variance of the steady state estimation error The expression is: .
[0038] Step 3: Construct alternative deception detection indices based on the smoothed in-phase channel multi-correlator SQM index and the smoothed orthogonal channel multi-correlator SQM index, wherein the alternative deception detection indices include an in-phase channel index, an orthogonal channel index, a direct composite index, and an indirect composite index.
[0039] Conviction Indicator , orthogonal channel index , direct composite index and indirect composite indicators The expression is: in, It represents the SQM index of the smoothed in-phase channel multi-correlator. Represents the smoothed orthogonal channel multi-correlator SQM indicator.
[0040] Step 4: Input the smoothed in-phase channel multi-correlator SQM indicator, the smoothed orthogonal channel multi-correlator SQM indicator, and the steady-state estimation error variance into multiple machine learning models respectively. Based on the outputs of the multiple machine learning models, select one of the alternative deception detection indicators as the deception detection indicator.
[0041] The output of the machine learning model depends on the relative distance between the alternative deception detection indicator and the corresponding threshold. The alternative deception detection indicator that deviates the most from the threshold is determined as the output.
[0042] Multiple machine learning models constitute an independent machine learning module. In this embodiment, the independent machine learning module includes three machine learning models, namely a decision tree (DT) model, a random forest (RF) model, and a K-nearest neighbor (KNN) model.
[0043] Each machine learning model outputs a candidate spoofing detection metric. Specifically, each machine learning model outputs one of the following: an in-phase channel metric, an orthogonal channel metric, a direct composite metric, and an indirect composite metric. A majority vote method is then used to determine the spoofing detection metric based on the candidate spoofing detection metrics output by multiple machine learning models.
[0044] For example, the outputs of the decision tree model, random forest model, and K-nearest neighbor model are the same-belief channel index, the same-belief channel index, and the indirect composite index, respectively. The number of votes for the same-belief channel index is 2, the number of votes for the indirect composite index is 1, and the number of votes for the orthogonal channel index and the direct composite index is 0. The same-belief channel index is used as a deception detection indicator.
[0045] If multiple alternative deception detection indicators receive the same number of votes, each machine learning model will be assigned a corresponding weight based on its accuracy on the validation set. The higher the accuracy, the greater the weight. The votes for each alternative deception detection indicator will be weighted and scored, and the alternative deception detection indicator with the highest score will be the deception detection indicator.
[0046] For example, the outputs of the decision tree model, random forest model, and K-nearest neighbor model are the same-belief channel index, orthogonal channel index, and direct composite index, respectively. The votes for the same-belief channel index, orthogonal channel index, and direct composite index are all 1, while the vote for the indirect composite index is 0. If the K-nearest neighbor model has the highest accuracy on the validation set, its corresponding weight is the largest, and the direct composite index has the highest score. The direct composite index is then used as the spoofing detection metric.
[0047] Step 5: Determine whether a spoofing attack has occurred based on the comparison of the spoofing detection index with the corresponding threshold. If the spoofing detection index exceeds the threshold, a spoofing attack is considered to have occurred; otherwise, no spoofing attack has occurred. This threshold is the same as the threshold used in the machine learning model output calculation in Step 4.
[0048] This embodiment also verifies the effectiveness of this method through the following experiments.
[0049] (1) Hardware environment: Multi-correlator array: 10 pairs of correlators are configured with a spacing range of 0-1 code chip, and a long coherent integration time (20ms) is used to suppress multipath interference.
[0050] Data Storage: A 1TB solid-state drive (SSD) is used to store collected GNSS signal data, intermediate data during processing, and final test results. The SSD's fast data read and write speeds ensure rapid data storage and retrieval, improving system efficiency.
[0051] (2) Application examples: Scenario setting: In an urban canyon environment, a vehicle driving scenario is simulated. The vehicle travels at a speed of 50 km / h and is subjected to multiple types of deception attacks, including induced deception attacks and high-power deception attacks.
[0052] (3) Technical parameters and data During the multi-correlator array construction and index generation phase, the array's correlator spacing was set to 0.1 chip, and the coherent integration time was set to 20 ms. The generated SQM indicators for the in-phase and quadrature-channel multi-correlators, before indirect Kalman filtering, exhibited significant noise, with a signal-to-noise ratio of approximately 1 dB.
[0053] After indirect Kalman filtering for noise reduction, the signal-to-noise ratio (SNR) of the multi-correlator SQM indicator for both the in-phase and quadrature channels increased to 10dB. The constructed alternative spoofing detection metric exhibited significant changes in the face of spoofing attacks. For example, during a induced spoofing attack, the in-phase channel metric deviated from its normal range by 20% within three seconds of the attack.
[0054] Deception detection indicators are dynamically determined through decision tree models, random forest models, and K-nearest neighbor models. Figure 2 As shown in the figure, the dynamic detection index used in this method is significantly better than the fixed detection index (in-phase channel index, orthogonal channel index, direct composite index and indirect composite index).
[0055] During the entire testing process, this method achieved a correct detection rate of up to 100% for various types of deception attacks, effectively avoiding vehicle positioning errors caused by deception attacks and ensuring the safety of vehicle navigation.
[0056] Experiments show that this method can effectively operate in an actual hardware environment. Through the coordinated work of various steps, it significantly improves the detection capability of GNSS spoofing signals, providing a strong guarantee for the safe application of global navigation satellite systems.
[0057] This method utilizes a highly sensitive GNSS receiver with an array of equally spaced multi-correlators and employs a long coherent integration time to suppress multipath interference. This method generates SQM metrics for both the in-phase and quadrature channels. This step provides fundamental data for subsequent noise processing and spoofing detection. The long coherent integration time effectively reduces the impact of multipath interference on the signal, improving signal quality. This allows the generated SQM metrics for both the in-phase and quadrature channels to more accurately reflect the characteristics of the GNSS signal, providing a more reliable data source for subsequent steps.
[0058] Based on the constructed state and observation models, this method uses the SQM indicators for the in-phase and quadrature channels as inputs and employs an indirect Kalman filter algorithm to remove noise. Through a prediction and update process, the indicator states are estimated and corrected to reduce noise interference. After indirect Kalman filtering, the noise in the SQM indicators for the in-phase and quadrature channels is effectively suppressed, significantly improving the signal-to-noise ratio.
[0059] This method utilizes the in-phase channel multi-correlator (SQM) and orthogonal channel multi-correlator (SQM) metrics, smoothed by indirect Kalman filtering, to construct multiple alternative spoofing detection metrics, including the in-phase channel metric, the orthogonal channel metric, the direct composite metric, and the indirect composite metric. These metrics comprehensively reflect GNSS signal characteristics from different perspectives, providing multi-dimensional data support for spoofing detection. These multiple alternative spoofing detection metrics can more comprehensively capture anomalies in GNSS signals and are more sensitive to spoofing signals than a single metric. For example, in a simulated spoofing attack scenario, the detection method based on these alternative metrics was able to detect spoofing signals earlier, by 20 seconds.
[0060] This method uses the smoothed SQM metrics of the in-phase and orthogonal channel multi-correlators, as well as the steady-state estimation error variance, as input features for the machine learning model. These input features contain rich signal information and related information after noise processing, providing a comprehensive data foundation for the independent machine learning module. By generating comprehensive and targeted input features, the independent machine learning module can better learn and analyze the relationship between signal characteristics and spoofing signals, improving the accuracy of subsequent detection metric selection and spoofing detection.
[0061] This method's independent machine learning modules are composed of three machine learning algorithms: decision tree (DT), random forest (RF), and k-nearest neighbor (KNN). They make preliminary judgments based on the relative distance between candidate deception detection metrics and corresponding thresholds. A voting mechanism aggregates the predictions of each model and determines the optimal deception detection metric from among the multiple model predictions. The collaborative work of multiple machine learning algorithms and the voting mechanism effectively combine the strengths of different algorithms and avoid the limitations of a single algorithm.
[0062] This method compares the optimal spoofing detection metric determined by an independent machine learning module with its corresponding detection threshold. Based on the comparison results, it determines whether a spoofing attack has occurred. If the metric exceeds the threshold, a spoofing event is detected and a corresponding alert is output. This method can accurately and rapidly detect spoofing attacks, providing timely security protection for global navigation satellite systems.
[0063] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A high-sensitivity dynamic GNSS spoofing detection method based on ensemble learning, characterized by: The following steps are involved: Step 1: Obtain the output signal of the multi-correlator array and calculate the SQM index of the in-phase channel multi-correlator and the SQM index of the orthogonal channel multi-correlator; Step 2: Use indirect Kalman filtering to smooth the in-phase channel multi-correlator SQM index and the orthogonal channel multi-correlator SQM index respectively, and obtain the smoothed in-phase channel multi-correlator SQM index and the smoothed orthogonal channel multi-correlator SQM index, as well as the steady-state estimation error variance; Step 3: Constructing candidate spoofing detection indices based on the smoothed in-phase channel multi-correlator SQM index and the smoothed orthogonal channel multi-correlator SQM index, wherein the candidate spoofing detection indices include an in-phase channel index, an orthogonal channel index, a direct composite index, and an indirect composite index; Step 4: Input the smoothed in-phase channel multi-correlator SQM index, the smoothed orthogonal channel multi-correlator SQM index, and the steady-state estimation error variance into multiple machine learning models. Based on the output of the machine learning models, select one of the candidate spoofing detection indicators as the spoofing detection indicator. Step 5: Determine whether a deception attack has occurred based on the comparison result of the deception detection index and the corresponding threshold.
2. The high-sensitivity dynamic GNSS spoofing detection method of integrated learning according to claim 1, characterized in that: In-phase channel multi-correlator SQM index and the SQM index of the orthogonal channel multi-correlator The expressions are: in, Indicates the spacing of the nth pair of correlators, where n ranges from 1, 2, ..., N, and N represents the number of logarithms of the multi-correlator array. Indicates the spacing is The in-phase channel advance correlator output of the correlator is Indicates the spacing is The in-phase channel lag correlator output of the correlator is Indicates the spacing is The orthogonal channel advance correlator output of the correlator, Indicates the spacing is The orthogonal channel lag correlator output of the correlator, represents the output of the in-phase channel instantaneous correlator, Represents The corresponding weighting coefficient.
3. The high-sensitivity dynamic GNSS spoofing detection method of integrated learning according to claim 2, characterized in that: In step 2, S21: Model construction of indirect Kalman filter. The state model and observation model of indirect Kalman filter are expressed as: in, Represents the SQM index of the same-phase multi-correlator at time k Or orthogonal channel multi-correlator SQM indicator status, Represents the SQM index of the k-1 time co-phase channel multi-correlator Or orthogonal channel multi-correlator SQM indicator status, represents the process noise, Represents the SQM index of the same-phase multi-channel correlator at time k Or orthogonal channel multi-correlator SQM indicator The measurement of represents the measurement noise; S22: Prediction and update of indirect Kalman filter. The prediction and update model of indirect Kalman filter is expressed as: in, Represents the SQM index of the same-phase channel multi-correlator from time k-1 to time k Or orthogonal channel multi-correlator SQM indicator A priori estimate of the state of Represents the SQM index of the k-1 time co-phase channel multi-correlator Or orthogonal channel multi-correlator SQM indicator The posterior estimate of the state of Represents the SQM index of the same-phase multi-channel correlator at time k Or orthogonal channel multi-correlator SQM indicator The posterior estimate of the state of represents the gain of the Kalman filter, The expression is: in, represents the measurement noise variance, It represents the variance of the prediction error, and its expression is: in, represents the variance of the state estimation error at time k-1, represents the variance of the state estimation error at time k, and q represents the process noise variance; S23: After the filter reaches steady state, the variance of the state estimation error remains unchanged, and the variance of the steady state estimation error The expression is: 。 4. The high-sensitivity dynamic GNSS spoofing detection method of integrated learning according to claim 3, characterized in that: The variance of , measurement noise variance The expression is: in, represents the carrier-to-noise ratio, represents the coherent integration time, Represents the spacing of the mth pair of correlators, where m ranges from 1, 2, ..., N. Represents The corresponding weighting coefficient is, Indicates that the GNSS signal autocorrelation function is The value of Indicates that the GNSS signal autocorrelation function is The value at .
5. The high-sensitivity dynamic GNSS spoofing detection method of integrated learning as claimed in claim 3, characterized in that: The variance of q is q, and the value of process noise variance q is: in, is the scaling factor.
6. The high-sensitivity dynamic GNSS spoofing detection method of integrated learning according to claim 1, characterized in that: Conviction Indicator , orthogonal channel index , direct composite index and indirect composite indicators The expression is: in, It represents the SQM index of the smoothed in-phase channel multi-correlator. Represents the smoothed orthogonal channel multi-correlator SQM indicator.
7. The high-sensitivity dynamic GNSS spoofing detection method of integrated learning according to claim 1, characterized in that: Each machine learning model outputs an alternative deception detection indicator. Based on the alternative deception detection indicators output by multiple machine learning models, the deception detection indicator is obtained by using the maximum vote method.
8. The high-sensitivity dynamic GNSS spoofing detection method of integrated learning according to claim 7, characterized in that: The output of the machine learning model depends on the relative distance between the alternative deception detection indicator and the corresponding threshold. The alternative deception detection indicator that deviates the most from the threshold is determined as the output.
9. The high-sensitivity dynamic GNSS spoofing detection method of integrated learning according to claim 7, characterized in that: If multiple alternative deception detection indicators receive the same number of votes, each machine learning model will be assigned a corresponding weight based on its accuracy on the validation set, and the votes for each alternative deception detection indicator will be weighted and scored. The alternative deception detection indicator with the highest score will be selected as the deception detection indicator.
10. The high-sensitivity dynamic GNSS spoofing detection method of integrated learning according to claim 1, characterized in that: The machine learning models include decision tree models, random forest models and K-nearest neighbor models.
Citation Information
Patent Citations
Weighted moving average deviation correction method for GNSS anti-spoofing detection index
CN118330684A
Improved signal deception detection method and system based on PCS algorithm and Ratio algorithm
CN119105046A
Self-adaptive generalized accumulation and GPS spoofing attack detection method
WO2022262780A1
Cited By
Unmanned aerial vehicle GPS deception detection method based on dynamic threshold generation
CN120742356A