Hybrid attack resistant elastic output feedback model prediction control method

By designing a resilient output feedback model predictive control method resistant to hybrid attacks in cyber-physical systems, and utilizing state observers and primary-auxiliary controllers, the security control problem under unmeasurable system states is solved, and the robust asymptotic stability and attack mitigation effects of the system are achieved.

CN120602111APending Publication Date: 2025-09-05BEIJING INST OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510466360.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing technologies make it difficult to effectively respond to hybrid attacks in cyber-physical systems, especially when the system status is unpredictable and security control cannot be achieved.

Method used

A resilient output feedback model predictive control method resistant to hybrid attacks is designed. By establishing a resilient control framework, the system state is reconstructed using a state observer, the main controller and the auxiliary controller are combined, the MPC optimization problem is designed, and the abnormal behavior is detected by the attack detector to ensure the robust asymptotic stability of the system under different attack scenarios.

Benefits of technology

It achieves secure control of hybrid attacks in complex environments, ensures the robust asymptotic stability of the system and the security of control input, and can effectively mitigate the negative impact of attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602111A_ABST
    Figure CN120602111A_ABST
Patent Text Reader

Abstract

The invention discloses an anti-hybrid-attack elastic output feedback model predictive control method, relates to the technical field of electronic information, and can solve the problem of security control of a system suffering from hybrid attacks in a complex environment under the condition that the state is unmeasurable. A discrete time linear time-invariant system is used as a controlled object, and an elastic control framework is established. And constructing a mathematical model of the controlled object and a hybrid attack model with constrained duration. A state observer is designed to reconstruct the state of a controlled object, the boundary of an error dynamic trajectory between an estimation system and a nominal system is calculated, the constraint of an optimization problem and a corresponding cost function are designed, and MPC optimal control problems are constructed for a main controller and an auxiliary controller respectively. An attack detector is designed to evaluate the attacked condition of a communication medium, a main / auxiliary controller is selected by using an attack detection result, an MPC optimal control problem is solved, and an optimal control input sequence is obtained and acts on a controlled object.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of electronic information technology, and in particular to a predictive control method of an elastic output feedback model for resisting hybrid attacks. Background Art

[0002] Over the past decade, the concept of cyber-physical systems (CPSs) has been proposed and has attracted widespread attention in the control field. CPSs utilize advanced sensing, computing, communication, and control technologies to achieve a deep integration of physical and cyberspace. Typical application scenarios include intelligent transportation, power grids, and other fields. The architecture of a CPS typically consists of three layers: the perception and execution layer, the data transmission layer, and the application control layer. In the data transmission layer, the use of wireless networks makes physical devices open to access, making them vulnerable to cyber threats, which can lead to system performance degradation or even failure. Therefore, attack analysis, detection, and defense strategies are key issues in the design of modern control systems.

[0003] In addition to cyberattacks, cyber-physical systems also face various constraints. For example, actuator saturation can impose constraints on control inputs; for safety or environmental protection purposes, certain variables (such as temperature, pressure, and concentration) must not exceed thresholds, which can constrain states or outputs; and dynamic equations based on the laws of conservation of mass or energy effectively impose constraints on system dynamics. In the application control layer of cyber-physical systems, especially in controller design, simply ignoring these constraints can lead to poor control performance or even instability. As a powerful control method for handling constraints, model predictive control (MPC) is an advanced optimization-based control strategy that has been widely applied in cyber-physical systems, such as chemical processes, supply chains, aerospace engineering, and the automotive industry. Furthermore, MPC offers unique advantages in addressing cyberattacks. By solving a constrained optimization problem online, it obtains a sequence of optimal control inputs, which can replace failed control inputs affected by the attack.

[0004] In recent years, elastic model predictive control (MPC) methods have been proposed to address the control problems of constrained cyber-physical systems. These methods not only explicitly and proactively address constraints but also leverage the characteristics of MPC, such as rolling optimization and model-based prediction, to design elastic control laws to mitigate the negative impacts of attacks. Traditional MPC methods fail to account for sensor measurement noise and assume that the system state is directly accessible, an assumption that may not hold true in practice. Furthermore, traditional MPC methods can only handle a single type of attack and may fail when multiple attacks coexist.

[0005] Therefore, how to achieve security control for systems that are subject to hybrid attacks and whose system status is unpredictable is an urgent problem that needs to be solved. Summary of the Invention

[0006] In view of this, the present invention provides a predictive control method of an elastic output feedback model against hybrid attacks, which can solve the security control problem of a system subjected to hybrid attacks in a complex environment when its state is unpredictable.

[0007] To achieve the above objectives, the present invention provides a resilient output feedback model predictive control method for resisting hybrid attacks, comprising:

[0008] Taking the discrete-time linear time-invariant system as the controlled object, a flexible control framework is established, including sensors, targets, actuators, estimators and comparators installed locally, and auxiliary controllers, main controllers and detectors installed in the remote control center.

[0009] A mathematical model of the controlled object is constructed, and a hybrid attack model with a constrained duration is established. The hybrid attack model includes two methods: error data injection attack and DoS attack.

[0010] A state observer is designed to reconstruct the state of the controlled object and calculate the boundary of the error dynamic trajectory between the estimated system and the nominal system.

[0011] According to the obtained boundary of the error dynamic trajectory, the constraints of the optimization problem and the corresponding cost function are designed, and the MPC optimal control problem is constructed for the main controller and the auxiliary controller respectively.

[0012] Considering that the time when hybrid attacks occur is random and unpredictable, an attack detector is designed to evaluate the attack situation of the communication medium and obtain attack detection results.

[0013] Using the attack detection results, the main controller or auxiliary controller is selected, and the MPC optimal control problem constructed for the selected controller is solved to obtain the optimal control input sequence acting on the controlled object.

[0014] Furthermore, the elastic control framework is specifically:

[0015] The local data sending port and the data receiving port of the remote control center are SC channels.

[0016] The local data receiving port and the data sending port of the remote control center are CA channels.

[0017] Wireless communication is used for data transmission between the SC channel and the CA channel, and the TCP protocol is used to control data transmission in the CA channel.

[0018] At each sampling moment, the estimator generates a state estimate using the control input signal acting on the target and the measurement output collected by the sensor. The local system sends the state estimate to the remote control center through the SC channel. The detector evaluates the received state estimate and, based on the evaluation result, selects one controller from the main controller and the auxiliary controller to generate a control sequence. The received state estimate and the generated control input sequence are then packaged and sent to the local system.

[0019] The actuator selects the appropriate control input to act on the target and drive the evolution of the target state. At the same time, the comparator is used to compare the difference between the locally received state estimate and the sent state estimate. At the same time, the local data receiving port determines whether the data has been successfully received; the data difference judgment result and the data reception situation judgment structure are generated locally, the two results are comprehensively considered, and the result is fed back to the remote control center through the response signal ACK.

[0020] Furthermore, in the elastic control framework, the sensor-controller channel is attacked by false data injection, the controller-actuator channel is attacked by DoS, and the number of times the hybrid attack occurs within a time interval of fixed length is upper bounded.

[0021] Furthermore, a hybrid attack model with a constrained duration is established. The hybrid attack model includes two methods: error data injection attack and DoS attack. Specifically:

[0022] Step 1.1: Build a discrete-time linear system model with additive perturbations:

[0023]

[0024] in, is the state of the controlled object, is the set of real numbers, is the control input, is an unknown state disturbance, is the measured output at time k, is the unknown output disturbance; the set and is a compact and convex set, and its interior contains the origin; represents the set of non-negative integers, Represents n-dimensional Euclidean space; A is an n-by-n coefficient matrix, B is an n-by-m coefficient matrix, and C is a p-by-n coefficient matrix, where n is the dimension of the state, m is the dimension of the control input, and p is the dimension of the measurement output.

[0025] Step 1.2: Establish the state constraints and control input constraints of the system as follows:

[0026]

[0027] Among them, the collection and It is a compact and convex set, and its interior contains the origin, which refers to the control target.

[0028] Step 1.3: The attacker launches a hybrid attack in the sensor-controller channel and the controller-actuator channel to destroy the integrity and availability of data. The hybrid attack launched by the attacker includes a false data injection attack in the sensor-controller channel and a DoS attack in the controller-actuator channel. The false data injection attack model is:

[0029]

[0030] in, represents the estimated value of the system state, γ 1,k = {0, 1} is a Bernoulli variable used to indicate the occurrence of an attack γ 1,k = 0 or not γ 1,k =1, Indicates the junk data injected by the attacker, Represents the state estimate actually received by the controller; the attacker launches a DoS attack with the intention of hindering the transmission of data in the controller-actuator channel, using the indicator variable γ 2,k Indicates whether the controller-actuator channel is under DoS attack: γ 2,k =1 means there is no DoS attack, otherwise it means there is a DoS attack; use the indicator variable γ k To indicate whether the entire system is attacked at time k, it is defined as: if γ 1,k =1 and γ 2,k =1, then γ k =1, otherwise γ k =0; In addition, the established hybrid attack model has a limited duration, that is, within the time interval Inside, there are:

[0031]

[0032] Established, where M represents the time interval The maximum number of mixed attacks, N represents the control time domain of the MPC optimization problem to be designed; k j represents the starting time of any j-th mixed attack.

[0033] Furthermore, a state observer is designed to reconstruct the state of the controlled object and calculate the boundary of the error dynamic trajectory between the estimated system and the nominal system. The specific steps are as follows:

[0034] Step 2.1: Construct an observer of the following form to reconstruct the state of the system:

[0035]

[0036] in, is the state of the observer at time k, is the observer gain matrix, Represents the set of all n×p dimensional matrices; the actual state x k+1 With estimated status The deviation between It means that it satisfies:

[0037]

[0038] Among them A L =A-LC, Defining a Collection for Then for all have The minimum robust positive invariant set of system (2) is

[0039] Step 2.2: Establish the nominal system:

[0040]

[0041] Constructing a control input sequence and Apply it to the observer and the nominal system (3) to get the error e k+1 , whose expression is:

[0042]

[0043] Among them A K =A+BK, KK is the gain matrix of mm times nn, Choose the matrix appropriately So that the matrix A K The spectral radius is less than 1; define the set for The minimum robust positive invariant set of error (4) is

[0044] Step 2.3: Establish the following error system:

[0045]

[0046] β k is a Bernoulli variable; for any In the time interval For all βk The possible values ​​of , according to the following iterative relationship, determine the set Is it an N-step robust positive invariant set of system (5):

[0047]

[0048] The set obtained by judgment Is it satisfied If this conclusion is satisfied, then the set is the N-step robust positive invariant set of system (5); otherwise, adjust the size of parameter N and repeat the test until the set is the N-step robust positive invariant set of system (5).

[0049] Step 2.4: During each test, record and store the collection in When the N-step robust positive invariant set of system (5) is found through the test in the previous step, the set is calculated using the PolyUnion function provided by the MPT toolbox gather This is the bound on the error (4) in the attack scenario.

[0050] Furthermore, the MPC optimal control problem constructed for the main controller is:

[0051] Step 3.1: At time k, for i = 0, ..., N-1, the MPC optimization problem of the master controller is described as follows

[0052]

[0053] The constraints are as follows:

[0054]

[0055] in, is the predicted state at the initial step, is the predicted state at the i-th prediction step, and the optimized control input The definition of is the predictive control input for the i-th prediction step. is the set of state constraints imposed on the nominal state, which is defined as is the set of control constraints imposed on the nominal control input, which is defined as gather is a terminal constraint set that satisfies the following conditions: for all For system x k+1 =Ax k +Bu k, there exists a local control law u k =Kx k ,have as well as Established.

[0056] Constraint (6a): A constraint that represents the deviation between the initial predicted state and the state received by the controller.

[0057] Constraints (6b): represent constraints set on the evolution of the predicted state.

[0058] Constraints (6c): represent the constraints set on the predicted state.

[0059] Constraints (6d): represent the constraints set on the predictive control input.

[0060] Constraint (6e): represents the constraints on the terminal prediction state.

[0061] Step 3.2: Set up the cost function The expression is:

[0062]

[0063] in Adding a subscript f is the stage cost function, is the terminal cost function, and its expressions are:

[0064]

[0065] And for all The following inequality also holds:

[0066] V f ((A+BK)x k )+L(x k ,Kx k )≤V f (x k )

[0067] Matrices Q, R, and P are all positive definite matrices; the set satisfy σ≥1 is an adjustable parameter, which is properly selected so that is an N-step robust positive invariant set of system (5).

[0068] The optimal control input of the main controller is recorded as in, After the main controller solves the optimization problem, it constructs and sends the control input sequence

[0069]

[0070] to the actuator end.

[0071] Furthermore, the MPC optimal control problem constructed for the auxiliary controller is:

[0072] At time k, for i=0,...,N-1, the MPC optimization problem of the auxiliary controller is described as follows

[0073]

[0074] The constraints are as follows:

[0075]

[0076] Among them, the optimization variables The definition of is a virtual nominal state, and its expression is:

[0077]

[0078] The set Ξ(0,∞) is a time interval defined as:

[0079]

[0080] Symbol h0 represents the moment when the attack first occurs from the initial moment, h i Indicates that from k = h i-1 +N, the moment when the attack first occurs; the symbol s represents a timestamp. At the current moment k, if the communication medium is secure, then s=k; if the communication medium is insecure, then s represents the last sampling moment before the communication medium is evaluated as insecure. is the initial predicted state, is the state predicted at step i.

[0081] Constraint (7a): represents the equality constraint imposed on the initial predicted state.

[0082] Constraint (7b): represents the iterative relationship between the prediction states of two adjacent steps.

[0083] Constraints (7c): represent the constraints imposed on the predicted state.

[0084] Constraints (7d): represent the constraints imposed on the predictive control input.

[0085] Constraint (7e): represents the terminal constraints imposed on the predicted state.

[0086] Step 3.4: Cost Function The expression is:

[0087]

[0088] in and They are the stage cost function and the terminal cost function, and their expressions are:

[0089]

[0090] The optimal decision variable is denoted as After solving the optimization problem, the auxiliary controller constructs and sends the control input sequence;

[0091]

[0092] to the actuator end.

[0093] Furthermore, considering that the time when hybrid attacks occur is random and unpredictable, an attack detector is designed to evaluate the attack situation of the communication medium and obtain the attack detection results. The specific steps are as follows:

[0094] Step 4.1: Construct the following set

[0095]

[0096] The following conditions are used to preliminarily determine whether the sensor-controller channel has been attacked by false data injection:

[0097]

[0098] Step 4.2: Set the following conditions in the data comparator to more strictly determine whether an attack exists:

[0099]

[0100] Alarm signal β indicating whether the entire system is attacked by incorrect data injection k Determined by the following expression:

[0101]

[0102] If the evaluation result in (8) is that there is an attack, then the time index h i Will update in time interval Activate the auxiliary controller.

[0103] Beneficial effects:

[0104] 1. This paper provides a resilient output-feedback model predictive control method resistant to hybrid attacks. Considering the unmeasurable state in practice, a state observer is designed to reconstruct the system state. A rational nominal trajectory is designed, and the impact of disturbances and estimation errors is fully analyzed. This method achieves indirect resilient control of the actual system by controlling the nominal trajectory. Furthermore, considering the coexistence of two random attacks, an attack detector is designed to detect the attacker's abnormal behavior. Tube MPC is employed to address the impact of state estimation errors, and primary and secondary controllers are designed to implement control during safe and unsafe moments, respectively. This ensures that the controlled object always has safe control inputs available, mitigating the negative impact of attacks while ensuring the robust asymptotic stability of the closed-loop system.

[0105] This paper provides a resilient output feedback model predictive control method for hybrid attacks. To achieve real-time and accurate detection of random and unknown attacks, appropriate evaluation conditions are designed. In response to an alarm signal from the attack detector, the system alternately switches between the primary and secondary controllers to provide a secure control input signal.

[0106] 3. This invention provides a resilient output feedback model predictive control method resistant to hybrid attacks, ensuring the iterative feasibility of the optimization problems solved by the primary and auxiliary controllers and the robust asymptotic stability of the closed-loop system. Compared with other currently available resilient model predictive control methods, the resilient output feedback model predictive control algorithm designed in this invention can achieve secure control under more complex attack scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0107] Figure 1 The present invention provides a flexible control framework for resisting hybrid attacks.

[0108] Figure 2 This is a supply chain structure diagram.

[0109] Figure 3 This is a timing diagram of a hybrid attack. DETAILED DESCRIPTION

[0110] The present invention is described in detail below with reference to the accompanying drawings and embodiments.

[0111] The present invention provides a resilient output feedback model predictive control method resistant to hybrid attacks. The basic concept is to establish a duration-constrained hybrid attack model, where the hybrid attack model includes two types: false data injection attacks and denial-of-service (DoS) attacks. The sensor-controller channel is attacked by false data injection, and the controller-actuator channel is attacked by DoS attacks. Furthermore, the number of hybrid attacks occurring within a fixed time interval is bounded. To address the challenge of unmeasurable states, a state observer is used to reconstruct the state of the system at each moment. The minimum robust positive invariant set to which the deviation between the estimated system and the nominal system belongs is calculated. By testing whether the minimum robust positive invariant set is a multi-step robust positive invariant set, an upper bound on the number of hybrid attacks occurring within a fixed time interval is obtained, and a tightened constraint set is designed. Furthermore, the MPC optimization problem for the main and auxiliary controllers is designed. An attack detector is designed to reveal the attacker's abnormal behavior, and a data comparator is introduced to eliminate the detector's false detections. Based on Lyapunov stability theory, the robust asymptotic stability of the closed-loop system is proven.

[0112] The present invention provides a method for predictive control of elastic output feedback model against hybrid attacks, such as Figure 1 As shown, the specific steps include:

[0113] Step 0: Taking the discrete-time linear time-invariant system as the controlled object, a flexible control framework is established, including sensors, targets, actuators, estimators, and comparators installed locally, and auxiliary controllers, main controllers, and detectors installed in the remote control center.

[0114] Wireless communication is used between the local data transmission port and the remote control center's data reception port (SC channel), as well as between the local data reception port and the remote control center's data transmission port (CA channel). The TCP protocol controls data transmission in the CA channel. At each sampling time, the estimator generates a state estimate using the control input signal applied to the target and the measured output collected by the sensor. The local state estimate is sent to the remote control center via the SC channel. The detector evaluates the received state estimate and, based on the evaluation result, selects one of the primary and secondary controllers to generate a control sequence. The received state estimate and the generated control input sequence are then packaged and sent to the local controller. The actuator selects the appropriate control input and applies it to the target, driving the target state evolution. Simultaneously, the comparator compares the difference between the received state estimate and the sent state estimate. The local data reception port determines whether the data has been successfully received. A data difference analysis result and a data reception status analysis structure are generated locally. These two results are considered and fed back to the remote control center via an acknowledgment signal (ACK).

[0115] Step 1: Construct a mathematical model of the controlled object, the state constraints and control input constraints of the system, and a hybrid attack model that includes two attack modes: denial of service (DoS) attack and error data injection attack. The specific steps include:

[0116] Step 1.1: Build a discrete-time linear system model with additive perturbations:

[0117]

[0118] in, is the state of the controlled object, is the set of real numbers, is the control input, is an unknown state disturbance, is the measured output at time k, is the unknown output disturbance; the set and is a compact and convex set, and its interior contains the origin; represents the set of non-negative integers, Represents n-dimensional Euclidean space; A is an n-by-n coefficient matrix, B is an n-by-m coefficient matrix, and C is a p-by-n coefficient matrix, where n is the dimension of the state, m is the dimension of the control input, and p is the dimension of the measurement output.

[0119] Step 1.2: Establish the state constraints and control input constraints of the system as follows:

[0120]

[0121] Among them, the collection and It is a compact and convex set, and its interior contains the origin, which refers to the control target.

[0122] Step 1.3: The attacker launches a hybrid attack in the sensor-controller channel and the controller-actuator channel to destroy the integrity and availability of data. The hybrid attack launched by the attacker includes a false data injection attack in the sensor-controller channel and a DoS attack in the controller-actuator channel. The model of the false data injection attack is

[0123]

[0124] in, represents the estimated value of the system state, γ 1,k = {0, 1} is a Bernoulli variable used to indicate the occurrence of an attack (γ 1,k =0) or not (γ 1,k =1), Indicates the junk data injected by the attacker, The attacker launches a DoS attack with the intention of hindering the transmission of data in the controller-actuator channel, using the indicator variable γ 2,k Indicates whether the controller-actuator channel is under DoS attack: γ 2,k =1 indicates that there is no DoS attack, otherwise it indicates that there is a DoS attack.

[0125] With indicator variable γ k To indicate whether the entire system is attacked at time k, it is defined as: if γ 1,k =1 and γ 2,k =1, then γ k =1, otherwise γ k = 0. In addition, the established hybrid attack model has a limited duration, that is, within the time interval Inside, there

[0126]

[0127] Established, where M represents the time interval k represents the maximum number of hybrid attacks, and N represents the control horizon of the MPC optimization problem to be designed. j Indicates the starting time of any jj-th mixed attack.

[0128] Step 2: Considering the unpredictable nature of the system state, a state observer is designed to reconstruct the state of the controlled object. A nominal model is established to analyze the propagation characteristics of the errors between the actual system and the estimated system, as well as between the estimated system and the nominal system. The boundaries of the dynamic trajectory of the errors between the estimated system and the nominal system under hybrid attacks are obtained. This includes the following steps:

[0129] Step 2.1: Construct an observer of the following form to reconstruct the state of the system:

[0130]

[0131] in, is the state of the observer at time k, is the observer gain matrix, represents the set of all n×p dimensional matrices. The actual state x k+1 With estimated status The deviation between It means that it satisfies:

[0132]

[0133] Among them A L=A-LC, Defining a Collection for Then for all have The minimum robust positive invariant set of system (2) is

[0134] Step 2.2: Establishing the Nominal System

[0135]

[0136] Constructing a control input sequence and Apply it to the observer and the nominal system (3) to get the error e k+1 , whose expression is:

[0137]

[0138] Among them A K =A+BK, K is the gain matrix of m times n, Choose the matrix appropriately So that the matrix A K The spectral radius is less than 1. Define the set for The minimum robust positive invariant set of error (4) is

[0139] Step 2.3: Establish the following error system:

[0140]

[0141] β k is a Bernoulli variable; for any In the time interval For all β k The possible values ​​of , according to the following iterative relationship, determine the set Is it an N-step robust positive invariant set of system (5):

[0142]

[0143] The set obtained by judgment Is it satisfied If this conclusion is satisfied, then the set is the N-step robust positive invariant set of system (5). Otherwise, adjust the size of parameter N and repeat the test until the set is the N-step robust positive invariant set of system (5).

[0144] Step 2.4: During each test, record and store the collection in When the N-step robust positive invariant set of system (5) is found through the test in the previous step, the set is calculated using the PolyUnion function provided by the MPT toolbox gather This is the bound on the error (4) in the attack scenario.

[0145] Step 3: Based on the obtained error dynamic trajectory boundary, design the optimization problem constraints and the corresponding cost function, and construct the MPC optimal control problem. Specifically, it includes the following steps:

[0146] Step 3.1: At time k, for i = 0, ..., N-1, the MPC optimization problem of the master controller is described as follows

[0147]

[0148] The constraints are as follows:

[0149]

[0150] in, is the predicted state at the initial step, is the predicted state of the i-th prediction step, is the predictive control input for the i-th prediction step. The optimized control input The definition of is the predictive control input for the i-th prediction step. is the set of state constraints imposed on the nominal state, which is defined as is the set of control constraints imposed on the nominal control input, which is defined as gather is a terminal constraint set that satisfies the following conditions: for all For system x k+1 =Ax k +Bu k , there exists a local control law u k =Kx k ,have as well as Established.

[0151] Constraint (6a) represents the constraint on the deviation between the initial predicted state and the state received by the controller;

[0152] Constraint (6b) represents the constraints set on the evolution of the predicted state;

[0153] Constraints (6c) represent constraints set on the predicted state;

[0154] Constraint (6d) represents the constraints set on the predictive control input;

[0155] Constraint (6e) represents the constraint on the terminal prediction state.

[0156] Step 3.2: Set up the cost function The expression is:

[0157]

[0158] in is the stage cost function, is the terminal cost function, and its expressions are:

[0159]

[0160] And for all The following inequality also holds:

[0161] V f ((A+BK)x k )+L(x k ,Kx k )≤V f (x k )

[0162] The matrices Q, R, and P are all positive definite matrices. satisfy σ≥1 is an adjustable parameter, which is properly selected so that is an N-step robust positive invariant set of system (5). The expression is gather The expression is gather is a terminal constraint set that satisfies the following conditions: for all For system x k+1 =Ax k +Bu k , there exists a local control law u k =Kx k ,have as well as In addition, the following inequality also holds:

[0163] V f ((A+BK)x k )+L(x k , kx k )≤V f (x k )

[0164] The optimal control input of the main controller is recorded as in, After the main controller solves the optimization problem, it constructs and sends the control input sequence

[0165]

[0166] to the actuator end.

[0167] Step 3.3: At time k, for i=0,...,N-1, the MPC optimization problem of the auxiliary controller is described as follows

[0168]

[0169] The constraints are as follows:

[0170]

[0171] Among them, the optimization variables The definition of is a virtual nominal state, and its expression is:

[0172]

[0173] The set Ξ(0,∞) is a time interval defined as:

[0174]

[0175] Symbol h0 represents the moment when the attack first occurs from the initial moment, h i Indicates that from k = h i-1 +N, the moment when the attack first occurs. The symbol s represents a timestamp. At the current time k, if the communication medium is secure, then s = k. If the communication medium is insecure, then s represents the last sampling time before the communication medium is evaluated as insecure. is the initial predicted state, is the state predicted at step i. Constraint (7a) represents the equality constraint imposed on the initial predicted state; constraint (7b) represents the iterative relationship between the predicted states of two adjacent steps; constraint (7c) represents the constraint imposed on the predicted state; constraint (7d) represents the constraint imposed on the predictive control input; and constraint (7e) represents the terminal constraint imposed on the predicted state.

[0176] Step 3.4: Cost Function The expression is:

[0177]

[0178] in and They are the stage cost function and the terminal cost function, and their expressions are:

[0179]

[0180] The optimal decision variable is denoted as After the auxiliary controller solves the optimization problem, it constructs and sends the control input sequence

[0181]

[0182] to the actuator end.

[0183] Step 4: Considering that the time when hybrid attacks occur is random and unpredictable, an attack detector is designed to assess the attack situation of the communication medium and issue an alarm signal. The specific steps include:

[0184] Step 4.1: Construct the following set

[0185]

[0186] The following conditions are used to preliminarily determine whether the sensor-controller channel has been attacked by false data injection:

[0187]

[0188] Step 4.2: Set the following conditions in the data comparator to more strictly determine whether an attack exists:

[0189]

[0190] Alarm signal β indicating whether the entire system is attacked by incorrect data injection k Determined by the following expression:

[0191]

[0192] If the evaluation result in (8) is that there is an attack, then the time index h i Will update in time interval Activate the auxiliary controller.

[0193] Step 5: Solve the constructed MPC optimal control problem and obtain the optimal control input sequence. According to the detection results of the attack detector, the real-time control input or the historically stored control input is applied to the controlled object to reduce the negative impact of the attack while ensuring the stability of the system. In summary, the process of an economical model predictive control algorithm for autonomous electric vehicles can be described as follows:

[0194] Algorithm 1: Elastic Output Feedback Model Predictive Control Algorithm

[0195]

[0196]

[0197] The YALMIP toolbox and GUROBI solver were used to conduct simulation experiments on MATLAB to verify the effectiveness and feasibility of the algorithm.

[0198] Simulation parameter selection: A supply chain model including suppliers, manufacturers and distributors is used to verify the effectiveness of the algorithm. The structure diagram of the supply chain is as follows: Figure 2 As shown. At each sampling time k, u k units of unprocessed raw materials are delivered to the manufacturer by the supplier. Of these, w 1,k units of raw materials are delivered to other manufacturers, the remaining raw materials and the original remaining x 1,k units of raw materials are stored at the manufacturer. Among the raw materials stored at the manufacturer, there are αx 1,k units of raw materials are converted into products and passed to the company that already has x 2,k The distributor of a unit of product will 2,k units of product are delivered to customers. The parameter α = 0.5 is known, and the parameter w 1,k and w 2,k At the sampling time k is unknown, but has known bounds. Due to the constraints on supply rate, storage capacity and demand, the following input constraints are obtained: 0≤u k ≤8, (0, 0) ≤ x k ≤(10, 10), (1.45, 2.45) ≤ w k ≤(1.55, 2.55), where x k =(x 1,k ,x 2,k ) is the state, u k is the control input, w k =(w 1,k , w 2,k ) is the disturbance term. And the centroid w of the disturbance set 0 =(1.5, 2.5) The corresponding state and control input equilibrium points are u 0 =4,x 0 =(5,5). The system model uses the transformed variable x δ =xx 0 ,u δ =uu 0 and w δ =ww 0 It is expressed as follows:

[0199]

[0200] where the transformed variables are constrained The measurement equation of the sensor is

[0201]

[0202] The disturbance Constrained The matrices K and L are selected as K = [-0.8853 -0.7765], L = [0.118 0.118] respectively. The weighting matrix in the cost function is Q = I, R = 0.01, The initial values ​​of the actual system, estimated system and nominal system are When a hybrid attack occurs Figure 3 shown.

[0203] Simulation results show that the proposed resilient output feedback model predictive control algorithm can mitigate the impact of hybrid attacks while ensuring robust constraint satisfaction and robust asymptotic stability of the closed-loop system.

[0204] In summary, the above are only preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A resilient output feedback model predictive control method against hybrid attacks, characterized in that: include: Taking the discrete-time linear time-invariant system as the controlled object, a flexible control framework is established, including sensors, targets, actuators, estimators and comparators installed locally, and auxiliary controllers, main controllers and detectors installed in a remote control center; Constructing a mathematical model of the controlled object and establishing a hybrid attack model with a constrained duration, wherein the hybrid attack model includes two modes: an error data injection attack and a DoS attack; Design a state observer to reconstruct the state of the controlled object and calculate the boundary of the error dynamic trajectory between the estimated system and the nominal system; According to the obtained error dynamic trajectory boundary, the optimization problem constraints and the corresponding cost function are designed, and the MPC optimal control problem is constructed for the main controller and the auxiliary controller respectively; Considering that the time when hybrid attacks occur is random and unpredictable, an attack detector is designed to evaluate the attack situation of the communication medium and obtain attack detection results; Using the attack detection result, a main controller or an auxiliary controller is selected, and an MPC optimal control problem constructed for the selected controller is solved to obtain an optimal control input sequence to act on the controlled object.

2. The method for predictive control of a resilient output feedback model against hybrid attacks according to claim 1, characterized in that: The elastic control framework is specifically: The local data sending port and the data receiving port of the remote control center are SC channels; The local data receiving port and the data sending port of the remote control center are CA channels; Wireless communication is used for data transmission between the SC channel and the CA channel, and TCP protocol is used to control data transmission in the CA channel. At each sampling moment, the estimator generates a state estimate using the control input signal acting on the target and the measurement output collected by the sensor. The local controller sends the state estimate to the remote control center through the SC channel. The detector evaluates the received state estimate and, based on the evaluation result, selects one controller from the main controller and the auxiliary controller to generate a control sequence. The received state estimate and the generated control input sequence are then packaged and sent to the local controller. The actuator selects the appropriate control input to act on the target and drive the evolution of the target state. At the same time, the comparator is used to compare the difference between the locally received state estimate and the sent state estimate. At the same time, the local data receiving port determines whether the data has been successfully received; the data difference judgment result and the data reception situation judgment structure are generated locally, the two results are comprehensively considered, and the result is fed back to the remote control center through the response signal ACK.

3. The method for predictive control of a flexible output feedback model against hybrid attacks according to claim 1, wherein: In the elastic control framework, the sensor-controller channel is attacked by false data injection, the controller-actuator channel is attacked by DoS, and the number of times the hybrid attack occurs within a time interval of a fixed length is upper bounded.

4. The method for predictive control of a flexible output feedback model against hybrid attacks according to claim 2, wherein: The hybrid attack model with a constrained duration is established, and the hybrid attack model includes two modes: error data injection attack and DoS attack, specifically: Step 1.1: Build a discrete-time linear system model with additive perturbations: in, is the state of the controlled object, is the set of real numbers, is the control input, is an unknown state disturbance, is the measured output at time k, is the unknown output disturbance; the set and is a compact and convex set, and its interior contains the origin; represents the set of non-negative integers, represents n-dimensional Euclidean space; A is an n-by-n coefficient matrix, B is an n-by-m coefficient matrix, and C is a p-by-n coefficient matrix, where n is the dimension of the state, m is the dimension of the control input, and p is the dimension of the measurement output; Step 1.2: Establish the state constraints and control input constraints of the system as follows: Among them, the collection and It is a compact and convex set, and its interior contains the origin, which refers to the control target; Step 1.3: The attacker launches a hybrid attack in the sensor-controller channel and the controller-actuator channel to destroy the integrity and availability of data. The hybrid attack launched by the attacker includes a false data injection attack in the sensor-controller channel and a DoS attack in the controller-actuator channel. The false data injection attack model is: in, represents the estimated value of the system state, γ 1,k = {0, 1} is a Bernoulli variable used to indicate the occurrence of an attack γ 1,k = 0 or not γ 1,k =1, Indicates the junk data injected by the attacker, Represents the state estimate actually received by the controller; the attacker launches a DoS attack with the intention of hindering the transmission of data in the controller-actuator channel, using the indicator variable γ 2,k Indicates whether the controller-actuator channel is under DoS attack: γ 2,k =1 means there is no DoS attack, otherwise it means there is a DoS attack; use the indicator variable γ k To indicate whether the entire system is attacked at time k, it is defined as: if γ 1,k =1 and γ 2,k =1, then γ k =1, otherwise γ k =0; In addition, the established hybrid attack model has a limited duration, that is, within the time interval Inside, there are: Established, where M represents the time interval The maximum number of mixed attacks, N represents the control time domain of the MPC optimization problem to be designed; k j represents the starting time of any j-th mixed attack.

5. The method for elastic output feedback model predictive control against hybrid attacks according to any one of claims 1 to 4, characterized in that: The designed state observer reconstructs the state of the controlled object and calculates the boundary of the error dynamic trajectory between the estimated system and the nominal system. The specific steps are: Step 2.1: Construct an observer of the following form to reconstruct the state of the system: in, is the state of the observer at time k, is the observer gain matrix, Represents the set of all n×p dimensional matrices; the actual state x k+1 With estimated status The deviation between It means that it satisfies: Among them A L =A-LC, Defining a Collection for Then for all have The minimum robust positive invariant set of system (2) is Step 2.2: Establish the nominal system: Constructing a control input sequence and Apply it to the observer and the nominal system (3) to get the error e k+1 , whose expression is: Among them A K =A+BK, KK is the gain matrix of mm times nn, Choose the matrix appropriately So that the matrix A K The spectral radius is less than 1; define the set for The minimum robust positive invariant set of error (4) is Step 2.3: Establish the following error system: β k is a Bernoulli variable; for any In the time interval For all β k The possible values ​​of , according to the following iterative relationship, determine the set Is it an N-step robust positive invariant set of system (5): The set obtained by judgment Is it satisfied If this conclusion is satisfied, then the set is the N-step robust positive invariant set of system (5); otherwise, adjust the size of parameter N and repeat the test until the set is the N-step robust positive invariant set of system (5); Step 2.4: During each test, record and store the collection in When the N-step robust positive invariant set of system (5) is found through the test in the previous step, the set is calculated using the PolyUnion function provided by the MPT toolbox gather This is the bound on the error (4) in the attack scenario.

6. The method for predictive control of a flexible output feedback model against hybrid attacks according to claim 5, characterized in that: The MPC optimal control problem constructed for the main controller is: Step 3.1: At time k, for i=0,...,N-1, the MPC optimization problem of the master controller is described as follows The constraints are as follows: in, is the predicted state at the initial step, is the predicted state at the i-th prediction step, and the optimized control input The definition of is the predictive control input for the i-th prediction step. is the set of state constraints imposed on the nominal state, which is defined as is the set of control constraints imposed on the nominal control input, which is defined as gather is a terminal constraint set that satisfies the following conditions: for all For system x k+1 =Ax k +Bu k , there exists a local control law u k =Kx k ,have as well as Established; Constraint (6a): A constraint representing the deviation between the initial predicted state and the state received by the controller; Constraints (6b): represent the constraints set on the evolution of the predicted state; Constraints (6c): represent the constraints set on the predicted state; Constraints (6d): represent the constraints set on the predictive control input; Constraint (6e): represents the constraints on the terminal prediction state. Step 3.2: Set up the cost function The expression is: in Adding a subscript f is the stage cost function, is the terminal cost function, and its expressions are: And for all The following inequality also holds: V f ((A+BK)x k )+L(x k ,Kx k )≤V f (x k ) Matrices Q, R, and P are all positive definite matrices; the set satisfy σ≥1 is an adjustable parameter, which is properly selected so that is an N-step robust positive invariant set of system (5). The optimal control input of the main controller is recorded as in, After the main controller solves the optimization problem, it constructs and sends the control input sequence to the actuator end.

7. The method for predictive control of a flexible output feedback model against hybrid attacks according to claim 6, characterized in that: The MPC optimal control problem constructed for the auxiliary controller is: At time k, for i=0,...,N-1, the MPC optimization problem of the auxiliary controller is described as follows The constraints are as follows: Among them, the optimization variables The definition of is a virtual nominal state, and its expression is: The set Ξ(0,∞) is a time interval defined as: Symbol h0 represents the moment when the attack first occurs from the initial moment, h i Indicates that from k = h i-1 +N, the moment when the attack first occurs; the symbol s represents a timestamp. At the current moment k, if the communication medium is secure, then s=k; if the communication medium is insecure, then s represents the last sampling moment before the communication medium is evaluated as insecure. is the initial predicted state, is the state predicted at step i; Constraint (7a): represents the equality constraint imposed on the initial predicted state; Constraint (7b): represents the iterative relationship between two adjacent prediction states; Constraints (7c): represent the constraints imposed on the predicted state; Constraint (7d): represents the constraints imposed on the predictive control input; Constraint (7e): represents the terminal constraints imposed on the predicted state. Step 3.4: Cost Function The expression is: in and They are the stage cost function and the terminal cost function, and their expressions are: The optimal decision variable is denoted as After solving the optimization problem, the auxiliary controller constructs and sends the control input sequence; to the actuator end.

8. The method for predictive control of a resilient output feedback model against hybrid attacks according to claim 6, wherein: Considering that the time when hybrid attacks occur is random and unpredictable, an attack detector is designed to evaluate the attack situation of the communication medium and obtain the attack detection results. The specific steps are as follows: Step 4.1: Construct the following set The following conditions are used to preliminarily determine whether the sensor-controller channel has been attacked by false data injection: Step 4.2: Set the following conditions in the data comparator to more strictly determine whether an attack exists: Alarm signal β indicating whether the entire system is attacked by incorrect data injection k Determined by the following expression: If the evaluation result in (8) is that there is an attack, then the time index h i Will update in time interval Activate the auxiliary controller.