A GNSS spoofing / multipath interference detection method and device

An adaptive method using SAPTL metric and CUSUM change point detection solves the problem of poor adaptability of GNSS interference detection in dynamic environments, achieves accurate identification of deception and multipath interference, and improves the robustness and reliability of the GNSS system.

CN120762055BActive Publication Date: 2026-02-10SHENZHEN KUANGWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511203316.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-27
Publication Date
2026-02-10
Estimated Expiration
2045-08-27

AI Technical Summary

Technical Problem

Existing GNSS interference detection methods are poorly adaptable to dynamic environments, making it difficult to accurately distinguish between spoofing attacks and multipath interference, leading to misjudgments and missed detections, which affect positioning accuracy and security.

Method used

An adaptive scheme based on SAPTL metric dynamic baseline and CUSUM change point detection is adopted. By calculating dynamic baselines by channel and fusing multi-satellite information, the detection threshold is adjusted in real time to distinguish between spoofing and multipath interference.

Benefits of technology

It significantly improves the robustness and reliability of GNSS interference detection, can accurately identify spoofing and multipath interference in dynamic environments, and improves the stability and security of the positioning system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120762055B_ABST
    Figure CN120762055B_ABST
Patent Text Reader

Abstract

The application discloses a GNSS spoofing / multipath interference detection method and device, relates to the field of signal detection, and calculates a dynamic baseline of a signal quality metric (SAPTL) of each satellite in real time and independently, that is, a dynamic mean value and a standard deviation changing with the environment. By normalizing and comparing the real-time metric with the dynamic baseline, the influence of baseline drift caused by scene switching (such as entering a city canyon) can be eliminated, so that a standardized deviation sequence which is not disturbed by the environment background can be obtained. Finally, the CUSUM change point detection algorithm which is extremely sensitive to small continuous changes is used to analyze the sequence, real signal abnormalities caused by spoofing or multipath can be accurately captured, and false fluctuations caused by environmental changes are not captured. In this way, the fundamental problem that a fixed threshold is poor in adaptability, easy to produce misjudgment and omissions in a dynamic environment is solved, and the robustness and reliability of detection are significantly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of signal detection, and more specifically, to a method and apparatus for detecting GNSS spoofing / multipath interference. Background Technology

[0002] Global Navigation Satellite Systems (GNSS), with their all-weather, global coverage, have become an indispensable infrastructure in both civilian and military fields, providing positioning, velocity measurement, and timing services. However, GNSS signals become extremely weak after long-distance transmission, and their structure is publicly known, making them vulnerable to spoofing attacks and multipath interference. Spoofing attacks can maliciously manipulate receiver positioning results by broadcasting false signals, posing a serious security threat; multipath interference causes propagation errors due to signal reflection, reducing positioning accuracy. Since both can cause signal quality anomalies, effectively detecting and accurately distinguishing them has become a key challenge in ensuring the security of GNSS spatiotemporal information.

[0003] To address this challenge, existing technologies have proposed several detection algorithms based on Signal Quality Monitoring (SQM). For example, the Delta and Ratio algorithms detect anomalies by analyzing the distortion of correlation peaks, but their performance degrades when both in-phase and quadrature components of the signal fluctuate. The ELP algorithm uses the phase difference between leading and lagging branches as a detection measure, but it fails under specific phase conditions. More importantly, these traditional SQM methods typically rely on a fixed detection threshold (e.g., a threshold for judging signal anomalies) to determine whether a signal is abnormal. The inherent assumption of this method is that the normal statistical characteristics of the signal are stationary; however, in practical applications, the operating environment of GNSS receivers is dynamically changing. For example, when a vehicle moves from an open area into a densely built-up urban canyon, multipath effects are significantly amplified, causing the baseline value of the signal quality monitoring measure itself to fluctuate drastically. In this case, a fixed threshold set for open areas will generate a large number of false alarms due to environmental changes; conversely, if an excessively high threshold is set to adapt to complex environments, it may miss concealed spoofing attacks. Therefore, existing detection methods using fixed thresholds have poor adaptability to dynamically changing environments, making it difficult to balance detection sensitivity and reliability. This is a core pain point that needs to be addressed before they can be applied to large-scale practical applications (such as autonomous driving and drone logistics). The root of the problem is that fixed thresholds cannot track and adapt to changes in the baseline of the normal signal state in real time.

[0004] To overcome this deficiency, there is an urgent need for a detection method that can dynamically adjust its judgment criteria, so that it can still accurately and robustly detect real anomalies caused by deception or multipath in various complex and dynamically changing scenarios, thereby improving the practicality and reliability of the detection system in all scenarios. Summary of the Invention

[0005] To address existing problems, according to one aspect of this application, a GNSS spoofing / multipath interference detection method is provided, comprising: acquiring SAPTL metric time series of M satellites; performing channel-specific dynamic baseline calculation on the SAPTL metric time series of the M satellites to obtain the dynamic mean and dynamic standard deviation of the M satellites; acquiring the real-time SAPTL metric of the i-th satellite; extracting the dynamic mean and dynamic standard deviation of the i-th satellite from the dynamic mean and dynamic standard deviation of the M satellites; normalizing the detection quantity of the real-time SAPTL metric of the i-th satellite based on the dynamic mean and dynamic standard deviation of the i-th satellite to obtain the normalized deviation of the i-th satellite; and performing CUSUM change point detection on the normalized deviation of the i-th satellite to obtain the anomaly marker of the i-th satellite.

[0006] According to another aspect of this application, a GNSS spoofing / multipath interference detection device is provided, comprising: a SAPTL metric time acquisition module for acquiring SAPTL metric time series of M satellites; a SAPTL metric time dynamic calculation module for performing channel-specific dynamic baseline calculation on the SAPTL metric time series of the M satellites to obtain the dynamic mean and dynamic standard deviation of the M satellites; a real-time SAPTL metric acquisition module for acquiring the real-time SAPTL metric of the i-th satellite; an i-th satellite feature extraction module for extracting the dynamic mean and dynamic standard deviation of the i-th satellite from the dynamic mean and dynamic standard deviation of the M satellites; a detection quantity normalization module for normalizing the real-time SAPTL metric of the i-th satellite based on the dynamic mean and dynamic standard deviation of the i-th satellite to obtain the normalized deviation of the i-th satellite; and an i-th satellite generation module for performing CUSUM change point detection on the normalized deviation of the i-th satellite to obtain the anomaly flag of the i-th satellite.

[0007] Compared with existing technologies, this application provides a GNSS spoofing / multipath interference detection method and apparatus. Addressing the technical problem that existing GNSS interference detection methods using fixed thresholds cannot adapt to dynamic environments, this application proposes an adaptive scheme based on dynamic baseline and change point detection. This scheme abandons the static, one-size-fits-all threshold and instead calculates a dynamic baseline for the Signal Quality Measure (SAPTL) of each satellite in real-time and independently, i.e., the dynamic mean and standard deviation that change with the environment. By normalizing and comparing the real-time metric with this dynamic baseline, the baseline drift caused by scene changes (such as entering an urban canyon) can be eliminated, resulting in a standardized deviation sequence unaffected by environmental background interference. Finally, the CUSUM change point detection algorithm, which is highly sensitive to small, continuous changes, is used to analyze this sequence, accurately capturing real signal anomalies caused by spoofing or multipath interference, rather than spurious fluctuations caused by environmental changes. This solves the fundamental problem of poor adaptability of fixed thresholds in dynamic environments, leading to misjudgments and missed detections, significantly improving the robustness and reliability of the detection. Attached Figure Description

[0008] The above and other objects, features, and advantages of this application will become more apparent from the more detailed description of the embodiments of this application in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of this application and form part of the specification. They are used together with the embodiments of this application to explain this application and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.

[0009] Figure 1 This is a flowchart of a GNSS spoofing / multipath interference detection method according to an embodiment of this application.

[0010] Figure 2 This is a schematic diagram of data flow in a GNSS spoofing / multipath interference detection method according to an embodiment of this application.

[0011] Figure 3 This is a schematic diagram of the multipath interference model in the GNSS spoofing / multipath interference detection method according to an embodiment of this application.

[0012] Figure 4 This is a schematic diagram illustrating the generation principle of generative deception in the GNSS deception / multipath interference detection method according to an embodiment of this application.

[0013] Figure 5 This is a flowchart of step S1 in the GNSS spoofing / multipath interference detection method according to an embodiment of this application.

[0014] Figure 6 This is a flowchart of step S6 in the GNSS spoofing / multipath interference detection method according to an embodiment of this application.

[0015] Figure 7 This is a block diagram of a GNSS spoofing / multipath interference detection device according to an embodiment of this application. Detailed Implementation

[0016] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0017] To address the issues mentioned in the background description, this application proposes a GNSS spoofing / multipath interference detection method. Figure 1 This is a flowchart of a GNSS spoofing / multipath interference detection method according to an embodiment of this application. Figure 2 This is a schematic diagram of the data flow in the GNSS spoofing / multipath interference detection method according to an embodiment of this application. Figure 1 and Figure 2 As shown, the GNSS spoofing / multipath interference detection method according to an embodiment of this application includes: Step S1, acquiring the SAPTL metric time series of M satellites; Step S2, performing channel-specific dynamic baseline calculation on the SAPTL metric time series of the M satellites to obtain the dynamic mean and dynamic standard deviation of the M satellites; Step S3, acquiring the real-time SAPTL metric of the i-th satellite; Step S4, extracting the dynamic mean and dynamic standard deviation of the i-th satellite from the dynamic mean and dynamic standard deviation of the M satellites; Step S5, performing detection quantity normalization on the real-time SAPTL metric of the i-th satellite based on the dynamic mean and dynamic standard deviation of the i-th satellite to obtain the normalized deviation of the i-th satellite; Step S6, performing CUSUM change point detection on the normalized deviation of the i-th satellite to obtain the anomaly flag of the i-th satellite.

[0018] It is worth noting that spoofing and multipath interference are two major forms of interference affecting the reliability of Global Navigation Satellite Systems (GNSS). Specifically, multipath interference is a phenomenon caused by the signal propagation environment. Figure 3 This is a schematic diagram of the multipath interference model in the GNSS spoofing / multipath interference detection method according to an embodiment of this application. Figure 3The multipath interference model shown illustrates that GNSS signals, during propagation, especially in complex environments such as urban canyons, are easily affected by obstacles such as buildings and mountains, resulting in reflections or diffractions and forming multiple reflection paths in addition to the direct path. Due to the longer reflection paths, these multipath signals experience time delays and attenuation relative to the direct signal. When these signals with different time delays and phases are superimposed at the receiver antenna, they cause interference and distortion to the synthesized signal. In a multipath environment, the received signal of the receiving antenna can be expressed as: In this context, the superscripts ad and m represent the true direct signal and the multipath signal, respectively. n ( t The noise is Gaussian white noise with zero mean, and this interference is one of the main sources of GNSS measurement errors and decreased positioning accuracy.

[0019] Unlike multipath interference, which forms naturally, deceptive interference is a deliberate and malicious attack. Figure 4 This is a schematic diagram illustrating the generation principle of generative deception in the GNSS deception / multipath interference detection method according to an embodiment of this application. Figure 4 As shown, attackers attempt to hijack the receiver's tracking loop by transmitting a forged satellite signal with higher power but containing false spatiotemporal information, causing it to output incorrect positioning, velocity, and time information, which is extremely dangerous. In a scenario considering only deception, the received signal can be represented as: ; where the superscript 's' indicates a deception signal.

[0020] Therefore, in a dynamic and complex scenario where multipath and spoofing coexist, the received signal contains the real signal, multipath signal, spoofing signal, and noise, and can be represented as: .

[0021] From the perspective of signal formation mechanism, whether it is a multipath signal, a real direct signal, or a deceptive signal, they all have similar signal structures, represented as: Among them, among them, For signal power, C It is a pseudo-random spreading code. For navigation data, For C / A code delay, For Doppler frequency shift, This is the carrier phase. It is precisely this high degree of structural similarity that makes it difficult for traditional detection methods that use fixed thresholds or single features to effectively distinguish between unintentional multipath interference and malicious deception attacks in dynamically changing environments, resulting in decreased detection performance and false positives and false negatives.

[0022] To address these challenges, this application employs a SAPTL-MA-MSC detection algorithm. The core idea of ​​this algorithm is a three-stage refined processing flow: First, it utilizes SAPTL (Three-Point Autocorrelation Power Sum) as the basic signal quality metric. This metric is highly sensitive to changes in the symmetry of the correlation peak, effectively reflecting signal distortion introduced by spoofing or multipath propagation. Next, using MA (Moving Average) technology, it performs dynamic baseline estimation on the SAPTL time series of each satellite, calculating the mean and standard deviation as the environment changes, thus solving the problem of poor adaptability of traditional fixed threshold methods in dynamic scenarios. Finally, using the MSC (Multi-Satellite Comparison) strategy, it comprehensively analyzes the detection results of all visible satellites, distinguishing between multipath interference affecting a few satellites and spoofing attacks attempting to affect all satellites based on the number and proportion of affected satellites. Therefore, this application first calculates the SAPTL metric time series, corresponding to SAPTL; then performs channel-specific dynamic baseline calculation to obtain the dynamic mean and standard deviation, corresponding to MA; and finally, it distinguishes between spoofing and multipath propagation by aggregating and analyzing the anomaly indicators of all satellites, corresponding to MSC. This approach overcomes the shortcomings of traditional fixed threshold methods in complex environments by using dynamic baselines, and solves the problem of single signal quality monitoring being unable to effectively distinguish between spoofing attacks and multipath interference by using multi-satellite information fusion. This significantly improves the robustness and accuracy of the detection system in dynamic and real-world scenarios.

[0023] In step S1, the SAPTL metric time series of M satellites is obtained. It should be understood that in GNSS signal processing, the shape of the correlation peak is a direct physical manifestation of signal quality. Ideally, the correlation peak is sharp and symmetrical, but under deception or multipath interference, the superposition of the real signal and the interfering signal can cause distortion of the correlation peak, such as broadening, skewness, or the appearance of sidelobes. This distortion is directly reflected in the output power of different branches of the correlator. Therefore, in order to build a detection basis that can sensitively capture such distortions, a metric that can quantify the overall shape change of the correlation peak is needed. To this end, this application obtains the SAPTL metric time series of M satellites to establish such a basis, providing raw, high-fidelity input data for subsequent dynamic baseline estimation and anomaly detection.

[0024] In one specific embodiment of this application, Figure 5 This is a flowchart of step S1 in the GNSS spoofing / multipath interference detection method according to an embodiment of this application. Figure 5As shown, step S1, obtaining the SAPTL metric time series of M satellites, includes: step S11, capturing and tracking the raw IQ sampling data output by the receiver RF front end at time t to obtain the quadrature and in-phase components of the leading branch, the quadrature and in-phase components of the instantaneous branch, and the quadrature and in-phase components of the lagging branch; step S12, performing power conversion on the quadrature and in-phase components of the leading branch, the quadrature and in-phase components of the instantaneous branch, and the quadrature and in-phase components of the lagging branch to obtain the power of the leading branch, the power of the instantaneous branch, and the power of the lagging branch; step S13, calculating the sum of the power of the leading branch, the power of the instantaneous branch, and the power of the lagging branch, and normalizing it to obtain the SAPTL value at time t as the SAPTL metric.

[0025] In the above embodiments, the specific process of step S1 is as follows: To illustrate the technical solution of the present invention in detail, a specific application scenario is used as an example below. For example, a vehicle-mounted device equipped with a GNSS receiver is driving from an open suburban road into a densely populated urban center. The receiver can currently stably track M=8 visible satellites. For any one of these satellites (e.g., PRN15 satellite), the SAPTL measurement acquisition process is as follows: First, step S11 is executed. In the front-end processing flow of the GNSS receiver, the weak radio frequency signal received by the antenna, which contains visible satellite signals, thermal noise, and potential interference signals, is first amplified by a low-noise amplifier, and then mixed with the signal generated by the local oscillator through a mixer, downconverting it from the high-frequency radio frequency band to a fixed intermediate frequency. Subsequently, the intermediate frequency analog signal is sampled and quantized by an analog-to-digital converter (ADC) to convert it into a digital signal. In order to completely preserve the amplitude and phase information of the signal, orthogonal sampling technology is used to decompose the digital intermediate frequency signal into two mutually orthogonal components: in-phase component (I) and quadrature component (Q). This sequence of digital values ​​generated at each sampling moment constitutes the raw IQ sampled data. This data stream is an undemodulated mixture containing all signal components and is the starting point of the signal processing flow. In practice, the signal processing module first performs signal acquisition on the input raw IQ sampled data for a satellite, such as PRN15. The essence of acquisition is searching for the target signal in a vast uncertainty space. This space consists of two dimensions: the Doppler shift caused by the relative motion between the satellite and the receiver, and the code phase caused by signal propagation delay. To perform the search, the signal processing module generates a local pseudo-random code copy that is completely identical to that of the PRN15 satellite. Subsequently, within a preset Doppler frequency search range, for example, in 500 Hz increments from -5 kHz to +5 kHz, the local code copy is cyclically correlated with the input raw IQ data at each frequency point. This process is equivalent to trying all possible code phase alignment methods at each frequency. When the calculated peak energy of a combination of a certain frequency and code phase significantly exceeds the acquisition threshold set based on the background noise level, the PRN15 satellite is successfully acquired. At this point, the frequency and code phase corresponding to this combination represent a rough estimate of the Doppler shift and code phase of the satellite signal. After successful acquisition, the processing flow switches to the tracking phase. The tracking loop, a precise closed-loop feedback control structure consisting of a code loop (delay-locked loop, DLL) and a carrier loop (Costas loop), takes over and locks the initial parameters obtained in the acquisition phase. The code loop achieves and maintains high-precision, dynamic synchronization between the locally generated pseudo-random code and the received satellite signal code phase. To this end, the numerically controlled oscillator (NCO) of the code loop generates three closely spaced local code copies based on the acquired code phase, corresponding to the leading, immediate, and lagging code phases, respectively.The interval between these three code phases is a pre-defined key parameter. For example, the lead and lag branches can be set to advance and lag by 0.5 chip widths relative to the instantaneous branch, respectively. At time t, these three local code copies are correlated and integrated in parallel with the input raw IQ sampled data stream. This process essentially projects the energy of the input signal onto these three specific code phase points.

[0026] To theoretically elucidate the impact of interference signals on the receiver correlator and provide a mathematical basis for the detection principle of this application, a general signal reception model is first established. The received signal in this model may simultaneously contain the real direct signal, multipath signals, spoofing signals, and noise. Under this theoretical model, the output of the correlator can represent the cross-correlation function R(t,τ) between the received signal and the local pseudocode, as shown in the following formula, which is the superposition of the cross-correlation results of the real direct signal, multipath signals, spoofing signals, noise, and the local code: Where τ is the delay between the local code and the received signal code. Since the structures of spoofing signals, multipath signals, and real direct signals are similar, their correlation functions can be expressed as the real signal correlation function under different time delays τ1 and τ2: .

[0027] Specifically, after integrating the local real-time code copy with the input data, the in-phase component of the output real-time branch is obtained. and orthogonal components Simultaneously, by integrating the local lookahead code copy with the input data, the in-phase component of the lookahead branch is obtained. and orthogonal components The in-phase component of the lagging branch is obtained by integrating the local hysteresis code copy with the input data. and orthogonal components These six values ​​represent the output for the PRN15 satellite at time t. Taking the instantaneous branch as an example, its in-phase and quadrature components are linear superpositions of the correlation results of each signal component, and are jointly affected by the signal power P, code phase error (τ-τ'), and carrier phase error (φ-φ'). , ;in, This represents the autocorrelation power of the spreading code.

[0028] Meanwhile, the code loop's discriminator uses the energy (or IQ components) of the leading and lagging branches to calculate the code phase error, and controls a numerically controlled oscillator (NCO) via a loop filter to dynamically adjust the generated phase of the local code, ensuring it remains locked to the code phase of the received signal. The carrier loop operates in a similar manner, using the IQ components of the instantaneous branch to track changes in the carrier's phase and frequency. This closed-loop feedback mechanism allows the receiver to continuously and stably output accurate IQ components for the leading, instantaneous, and lagging branches, even when the vehicle is moving.

[0029] Next, proceed to step S12. Power is a measure of signal energy, obtained by calculating the sum of the squares of the in-phase and quadrature components, i.e., the square of the amplitude. The specific calculation process for the amplitude is as follows: First, calculate the amplitude E of the leading branch, which is the square root of the sum of the squares of the in-phase and quadrature components of the leading branch; second, calculate the amplitude P of the instantaneous branch, which is the square root of the sum of the squares of the in-phase and quadrature components of the instantaneous branch; finally, calculate the amplitude L of the lagging branch, which is the square root of the sum of the squares of the in-phase and quadrature components of the lagging branch. The calculation process is as follows: ;in, E , P and L All follow a Rice distribution, with P For example, let W = P The probability density function is ;in, When there is no deception W The mean, For noise variance, This is a 0th-order modified Bezier function. When the signal-to-noise ratio is much greater than 1... E , P and L All of them approximately follow a normal distribution. Then, in the calculation... E , P and L The leading branch power Ec, the instantaneous branch power Pc, and the lagging branch power Lc are obtained by squaring them.

[0030] Next, step S13 is executed. This step first adds the three power values ​​Ec, Pc, and Lc to obtain a total power sum. Then, to ensure this metric has consistent dimensions and facilitates subsequent processing, the total power sum needs to be normalized. Normalization is accomplished by dividing by an adjustment factor. This adjustment factor can be preset; a reasonable setting is to take the expected value or long-term average value of the instantaneous branch power P when the receiver stably tracks the signal in an interference-free, open environment. For example, if the stable average value of the instantaneous branch power measured in the calibration environment is 10,000 units, the adjustment factor can be set to 10,000. Finally, the SAPTL value at time t is calculated as (Ec + Pc + Lc) divided by the adjustment factor.

[0031] At the latest time t, by executing steps S11 to S13 above, the SAPTL value (i.e., SAPTL metric) of PRN15 satellite at that instant can be calculated. This latest metric is then appended to the end of the satellite's existing historical data sequence, thereby updating and constructing a SAPTL metric time series containing information about the current time. This process is applied in parallel to all eight visible satellites, ultimately resulting in a set of SAPTL metric time series M equal to the eight satellites.

[0032] In step S2, channel-specific dynamic baseline calculations are performed on the SAPTL metric time series of the M satellites to obtain the dynamic mean and dynamic standard deviation of the M satellites. Correspondingly, in practical GNSS applications, the electromagnetic environment in which the receiver operates is not static. When a vehicle moves from an open area into a densely populated urban canyon, or passes through tunnels or overpasses, signal obstruction and reflection change drastically, leading to a significant increase or decrease in multipath effects. This dynamic change in the environment causes the normal level (i.e., the baseline) of the SAPTL metric, which serves as a signal quality indicator, to drift and fluctuate. If a fixed threshold is used for anomaly detection, a large number of false alarms or missed alarms will occur during environmental transitions. Therefore, in order to enable the detection method to overcome the limitations of static thresholds and to perceive and adapt to environmental changes in real time, providing a normal reference standard that adapts to the environment for subsequent normalization processing and anomaly detection, channel-specific dynamic baseline calculations are required on the SAPTL metric time series.

[0033] In a specific embodiment of this application, step S2 is as follows: This step involves establishing and maintaining an independent sliding window for each satellite (i.e., each channel) to dynamically track the statistical characteristics of recent signals. The sliding window moves along the time axis and performs statistical calculations only on the data within the window. First, the length W of the sliding window needs to be set. The selection of this length requires a trade-off between response speed and estimation stability. A shorter window can more sensitively capture instantaneous environmental changes, but its calculation results are more susceptible to random noise and therefore less stable; conversely, a longer window can provide smoother and more reliable statistical estimates, but its response to sudden environmental changes is relatively slow. In this embodiment, if the receiver's SAPTL metric update rate is 10 Hz, a sliding window with a length of W equal to 1000 epochs can be set, corresponding to the data of the past 100 seconds. This allows for an effective response to minute-level environmental changes while ensuring statistical stability.

[0034] At each new time epoch t, ​​when the latest SAPTL value for a satellite, such as PRN15, is generated, its corresponding sliding window moves forward one epoch. At this point, the window contains 1000 of the latest SAPTL values ​​for that satellite from time t-W+1 to time t. Next, standard statistical calculations are performed on these 1000 data points: First, all SAPTL values ​​within the window are summed and divided by the window length W (1000) to obtain the dynamic mean of the satellite at time t. Then, the difference between each SAPTL value within the window and this dynamic mean is calculated, and these differences are squared. All squared differences are then summed and divided by W. Finally, the square root of the result is taken to obtain the dynamic standard deviation of the satellite at time t.

[0035] This calculation process is applied in parallel to all M tracked satellites. Specifically, an independent sliding window of length 1000 is maintained for each of the eight satellites, and at each epoch t, ​​their respective dynamic mean and dynamic standard deviation are calculated. This results in a set of dynamic baselines that reflect the normal fluctuation range of the signal environment in which each satellite is currently located, thus yielding M sets of dynamic mean time series and M sets of dynamic standard deviation time series.

[0036] In step S3, the real-time SAPTL metric for the i-th satellite is obtained. Understandably, after completing the dynamic baseline calculation of historical data, the focus of the detection process naturally shifts to the current moment. Historical data analysis provides a dynamic, environment-adaptive definition of normal signal status, but this definition itself cannot directly determine whether there is an anomaly. The essence of anomaly detection lies in accurately comparing the current observation value with this dynamically defined normal range. Therefore, in order to apply the dynamically established normal baseline to real-time anomaly judgment, it is necessary to obtain the latest signal quality status for each satellite for subsequent detailed analysis and processing.

[0037] In a specific embodiment of this application, the specific process of step S3 is as follows: Here, index i represents any satellite pointed to by the current processing flow, such as the aforementioned PRN15 satellite, or any other one of the 8 visible satellites (M equals 8). This process is implemented through a precise data extraction operation. Specifically, from the SAPTL metric time series set generated in parallel for all M satellites in step S1, based on the index i of the current target satellite, the latest time t of the SAPTL metric time series corresponding to that satellite is directly located and extracted. This value is the real-time SAPTL metric of the i-th satellite.

[0038] In step S4, the dynamic mean and dynamic standard deviation of the i-th satellite are extracted from the dynamic mean and dynamic standard deviation of the M satellites. It should be understood that in the detection process, the dynamic baselines of all M visible satellites have been calculated and maintained in parallel, forming a set containing the dynamic mean and standard deviation of each satellite. Simultaneously, the real-time SAPTL metric of the i-th satellite at the current moment is also obtained. At this point, in order to meaningfully evaluate the real-time metric of this specific satellite, a universal baseline shared by all satellites cannot be used, because the signal strength, elevation angle, and multipath environment experienced by each satellite are different, resulting in a unique normal baseline. Therefore, to ensure that the subsequent normalization processing is performed on the signal characteristics of the satellite itself, thereby obtaining a standardized deviation that accurately reflects its deviation from its normal state, it is necessary to perform the step of extracting the dynamic mean and dynamic standard deviation specific to the i-th satellite from the dynamic baseline set of the M satellites.

[0039] In one specific embodiment of this application, the specific process of step S4 is as follows: The corresponding value of the i-th satellite is extracted from the dynamic mean and dynamic standard deviation of the M satellites in a similar manner. First, the dynamic mean time series set generated for all satellites in step S2 is located. Using the same target satellite index i, the element value of the latest time t of the dynamic mean time series of that satellite is directly extracted; this value is the dynamic mean of the i-th satellite at the current time. Subsequently, in the same manner, the dynamic standard deviation time series set is accessed, and the element value of the latest time t of the corresponding sequence is extracted according to index i; this value is the dynamic standard deviation of that satellite at the current time.

[0040] In step S5, based on the dynamic mean and dynamic standard deviation of the i-th satellite, the real-time SAPTL metric of the i-th satellite is normalized to obtain the normalized deviation of the i-th satellite. Correspondingly, in the signal detection process, although the real-time SAPTL metric value of a specific satellite and its unique dynamic baseline (mean and standard deviation) have been obtained, these raw values ​​are not suitable for direct anomaly judgment. The magnitude of the real-time SAPTL value varies drastically with factors such as the signal environment and satellite elevation angle, and its absolute value itself does not have universal significance. A high value considered abnormal in an open area may be completely normal in an urban canyon. Therefore, in order to eliminate this baseline drift effect caused by environmental changes and to give the detection quantity a uniform scale and statistical meaning, thereby enabling the application of a standardized judgment criterion that does not change with the environment, it is necessary to normalize the real-time SAPTL metric.

[0041] In a specific embodiment of this application, the specific process of step S5 is as follows: Step S5, based on the dynamic mean and dynamic standard deviation of the i-th satellite, normalize the detection quantity of the real-time SAPTL metric of the i-th satellite to obtain the normalized deviation of the i-th satellite, including: based on the dynamic mean and dynamic standard deviation of the i-th satellite, normalize the detection quantity of the real-time SAPTL metric of the i-th satellite using the following formula, wherein the formula is: ;in, For the real-time SAPTL metric of the i-th satellite, Let be the dynamic mean of the i-th satellite. Let be the dynamic standard deviation of the i-th satellite. Let be the normalized bias of the i-th satellite. First, the numerator calculates the difference between the real-time SAPTL metric and its dynamic mean. This difference represents the degree of deviation of the current observation from its recent normal center. In the absence of anomalies, this difference should fluctuate slightly around zero. Second, this difference is divided by the dynamic standard deviation. The standard deviation is a measure of the magnitude of fluctuation of data around its mean, representing the amplitude of normal fluctuations in that environment. Dividing the bias by the standard deviation essentially converts the original degree of deviation into a relative deviation in terms of standard deviations; this is a standard Z-score transformation. For example, at the latest time t, for the 5th satellite, if the real-time SAPTL metric of this satellite (PRN15) is 1.6, and its dynamic mean calculated through a sliding window is 1.2 with a dynamic standard deviation of 0.2, then the normalized bias of this satellite is calculated as (1.6 - 1.2) / 0.2 = 2. This result of 2 means that the current SAPTL value is 2 standard deviations higher than its recent normal mean. This normalized deviation value eliminates the influence of the original metric's dimensions and absolute size.

[0042] In step S6, CUSUM change point detection is performed on the normalized deviation of the i-th satellite to obtain the anomaly marker of the i-th satellite. It is understood that after normalizing the real-time observations, a standardized deviation value is obtained. However, spoofing or multipath interference events are often not isolated instantaneous pulses, but rather manifest as a persistent shift in the signal's statistical characteristics over a period of time. If only a simple instantaneous threshold judgment is performed on each normalized deviation value, it is easily affected by random noise at a single data point, resulting in insufficient sensitivity and reliability of detection, making it difficult to effectively identify those weak but persistent minor anomalies. Therefore, in order to accumulate evidence of weak but persistent anomalous signals, amplify small changes in the signal mean, and maintain robustness against transient random noise, thereby achieving rapid and reliable detection of the starting point of anomaly events, it is necessary to perform CUSUM change point detection on the normalized deviation.

[0043] In one specific embodiment of this application, Figure 6 This is a flowchart of step S6 in the GNSS spoofing / multipath interference detection method according to an embodiment of this application. Figure 6 As shown, step S6, which involves performing CUSUM change point detection on the normalized deviation of the i-th satellite to obtain the anomaly flag of the i-th satellite, includes: step S61, iteratively updating the previous epoch cumulative value of the i-th satellite based on the normalized deviation of the i-th satellite to obtain the current epoch cumulative value of the i-th satellite; step S62, generating the anomaly flag of the i-th satellite based on the comparison between the decision threshold and the current epoch cumulative value of the i-th satellite.

[0044] In the above embodiments, the specific process of step S1 is as follows: First, step S61 is executed. In a specific embodiment of this application, step S61, based on the normalized deviation of the i-th satellite, iteratively updates the previous epoch cumulative value of the i-th satellite to obtain the current epoch cumulative value of the i-th satellite, including: step S611, adding the normalized deviation of the i-th satellite to the previous epoch cumulative value of the i-th satellite and subtracting the slack amount to obtain an intermediate sum; step S612, taking the larger value between the intermediate sum and zero to obtain the current epoch cumulative value of the i-th satellite.

[0045] Specifically, this process maintains an independent cumulative value variable, denoted as S_i, for each satellite. Before processing begins, this cumulative value S_i(0) is initialized to zero. At each new time epoch t, ​​this cumulative value is updated according to the following iterative formula: This update process is specifically broken down into two sub-steps. The first step, S611, calculates an intermediate sum. The normalized bias at the current time is then calculated. Cumulative value from the previous moment Add them together, then subtract a preset relaxation amount. Relaxation amount This is a key adjustment parameter, set according to the minimum deviation to be detected, typically half the deviation of the mean value to be detected, to strike a balance between detection sensitivity and robustness to noise. It represents the range within which the normalization deviation is allowed to fluctuate normally without triggering accumulation, and is typically set to a small positive number, such as 0.5. The effect of this value is that only when the normalization deviation is consistently significantly greater than... The cumulative value will only increase when the deviation is less than a certain value. The accumulated value will decrease, thus filtering out small, meaningless random fluctuations. The second step, S612, is to take the larger value between this intermediate sum and zero to obtain the accumulated value for the current epoch. This operation ensures that the accumulated value will never be negative. If a series of small deviations causes the intermediate sum to become negative, it will be reset to zero. This means that the CUSUM algorithm has the property of memory reset: once the signal returns to normal, the accumulated evidence of anomalies is quickly cleared, and the algorithm is ready to detect the next anomaly.

[0046] Next, step S62 is executed. In a specific embodiment of this application, step S62, based on the comparison between a decision threshold and the current epoch cumulative value of the i-th satellite, generates an anomaly flag for the i-th satellite, including: step S621, in response to the current epoch cumulative value of the i-th satellite being greater than the decision threshold, determining that the anomaly flag of the i-th satellite is true; step S622, in response to the current epoch cumulative value of the i-th satellite being less than or equal to the decision threshold, determining that the anomaly flag of the i-th satellite is false.

[0047] Specifically, a decision threshold H is first set. This threshold H represents the strength of the accumulated evidence required to determine if an anomaly has occurred. The setting of H needs to strike a balance between detection sensitivity and false alarm rate. A lower H value can detect anomalies faster, but may increase false alarms due to noise accumulation; a higher H value can provide more reliable detection, but will sacrifice some detection speed. In this embodiment, the decision threshold H can be set to 5. The comparison process is specifically divided into two mutually exclusive conditions. The first is step S621, which determines the accumulated value of the current epoch. Is it greater than the decision threshold H? If so... If the normalization bias is consistently and significantly deviating from the normal level, the accumulated evidence is sufficient. At this point, the anomaly flag Flag_i(t) for the i-th satellite is determined to be true, indicating that a spoofing or multipath interference event has been detected. The next step is step S622, if... If the cumulative value is less than or equal to the decision threshold h, then in response to this condition, the anomaly flag Flag_i(t) of the i-th satellite is determined to be false. This indicates that, so far, the accumulated evidence is insufficient to determine the occurrence of an anomaly, and the signal state is considered normal. For a concrete example, for the 5th satellite, if this satellite is PRN15, its cumulative value... The relaxation amount is 3.8. Set the value to 0.5, and the decision threshold h to 5. At the current time t, its normalized bias... It is 2.0. First, update the cumulative value: Then, a decision comparison is made: because 5.3 is greater than the threshold 5, the satellite's anomaly flag Flag_5(t) is set to true. This flag can be directly used to trigger receiver alarms or data loss responses.

[0048] In particular, in the application of the CUSUM change point detection algorithm, relaxation and decision threshold are two core parameters that determine its detection performance. If these two parameters are set to fixed values, although they can work effectively when the signal environment (such as signal-to-noise ratio and multipath intensity) is stable, their performance will significantly deteriorate in dynamically changing real-world scenarios. For example, when the receiver enters an area with severe multipath effects, the baseline fluctuation of signal quality metrics will naturally increase. At this time, a fixed, low relaxation will incorrectly accumulate these normal baseline fluctuations, causing the accumulated values ​​to easily exceed the decision threshold, thus generating a large number of false alarms. Conversely, if the relaxation and decision threshold are preset too high to avoid false alarms, the detector will become too insensitive when the signal environment returns to cleanliness, unable to effectively detect covert spoofing attacks with energy equivalent to normal noise, leading to missed detections. Therefore, in order to enable the detection device to maintain a balance between high sensitivity and low false alarm rate in various complex signal environments, this application adopts a noise-aware dual adaptive CUSUM threshold mechanism to achieve intelligent and dynamic adjustment of detection parameters.

[0049] Based on this, in a preferred embodiment of this application, the relaxation amount and the decision threshold are determined by a noise-aware dual-loop adaptive CUSUM threshold mechanism, including: constructing an approximate formula between the relaxation amount and the decision threshold, namely: ;in, It is the relaxation amount. It is the decision threshold. This refers to the average runtime without anomalies. It's understandable that to achieve high consistency and predictability of detector performance under different environments, a quantitative performance constraint model with clear physical meaning must first be established. In CUSUM's statistical theory, relaxation and decision threshold together determine two key performance indicators: the average runtime without anomalies. (Characterizing false alarm rate) and average run length when anomalies occur (Characterizing detection speed). If only adjustments are made when adapting to environmental changes... Instead of adjusting accordingly , and This will get out of control, leading to unpredictable detection performance. For example, As the value increases, the accumulation rate slows down. constant, It will become extremely large (with an extremely low false alarm rate), but It will also become extremely large (detection becomes extremely insensitive). Therefore, this step introduces a method based on... The approximate formula will and A strong mathematical correlation is established. In practice, a desired false alarm performance target is first set, for example, the false alarm probability is set. , If it is one ten-thousandth, then the corresponding That is, ten thousand. Subsequently, based on... The approximate formula then constructs a system based on... For a constant objective, As the independent variable, This establishes a functional relationship between the dependent and dependent variables, laying a solid theoretical foundation for subsequent adaptive adjustments and ensuring that regardless of... How can we always calculate a matching value based on environmental changes? This ensures that the false alarm probability of the system is always locked at the preset expected level.

[0050] The relaxation quantity is obtained by performing a noise-sensitive sigmoid relaxation mapping on the state standard deviation and the fundamental relaxation quantity, i.e.: ;in, and Is The adaptive relaxation and dynamic standard deviation at time intervals. It is the basic relaxation amount, representing the amount under ideal conditions (e.g., ...). The minimum tolerance can be set, for example, to 0.5, to ensure that the system has basic noise immunity even in ideal environments. Used to set the adjustment range, i.e. The magnitude of the upward fluctuation of the value, to prevent In extreme environments, the values ​​are set unreasonably high to ensure the robustness of the algorithm. It is a reference fluctuation threshold, used as a class The inflection point of the function represents the critical point between normal and noisy environments; for example, it can be set to the standard deviation level of 1.0, representing a good signal environment. For control classes The function curve is The steepness of the surrounding terrain is used to adjust the sensitivity, that is, The larger, The faster the transition, the more drastic the system's response to environmental changes. The smaller the value, the smoother the transition and the stronger the adaptability; for example, it can be set to 2.0. Furthermore, the abstract environmental noise level needs to be transformed into a concrete relaxation amount that the CUSUM algorithm can directly use. The physical meaning of the relaxation amount is the normal fluctuation amplitude that the system is allowed to tolerate, without accounting for abnormal accumulation. The most direct representation of this amplitude is the dynamic standard deviation of the signal quality metric time series. However, the simple linear relationship between the two has drawbacks: it is overly sensitive to small changes in the standard deviation and may cause the k value to increase indefinitely under extreme noise conditions, rendering the detector completely ineffective. Therefore, this step employs a sigmoid-like function to provide a smooth, bounded, and non-linear mapping. In practice, the above formula is used for calculation; that is, the relaxation amount is achieved through this non-linear mapping. Intelligent sensing of environmental noise: In low-noise environments, Smoothly approaching This keeps the detector highly alert; in high-noise environments, The smooth approach to the upper limit makes the detector more tolerant, thus avoiding abrupt changes and runaway parameters, and greatly enhancing the robustness of the algorithm. In particular, the preset parameter values ​​in the above formulas were finally determined based on a large amount of prior experimental data, simulation analysis, and a trade-off and optimization of the performance requirements (such as the desired false alarm rate and detection sensitivity) for the target application scenarios (such as automotive and aviation).

[0051] The decision threshold is obtained by inversely solving the approximate formula and the relaxation amount. In other words, after obtaining the adaptive relaxation amount that reflects environmental changes in real time, a matching decision threshold must be calculated immediately to complete the dual adaptive closed loop, a crucial execution step to ensure the constant performance of the detector. In specific implementation, the real-time relaxation amount calculated in the previous step is... That is, in relaxation amount at time and the performance targets set in the first step. For example, let's substitute 10,000 into the approximation formula. Because... and All numbers are known; the formula then becomes a formula about... The transcendental equation is solved by numerical methods (such as Newton's iteration method or the bisection method) to obtain the unique decision threshold at the current moment. This achieves precise nonlinear compensation of the relaxation amount for the decision threshold. As environmental noise increases, the relaxation amount increases accordingly, and the calculated decision threshold also increases nonlinearly, thus ensuring that the decision boundary and tolerance of the cumulative sum are adjusted synchronously. Ultimately, this ensures that the false alarm probability of the detector remains at a preset level of one ten-thousandth in any signal environment, from clean to noisy, achieving a high degree of consistency in detection performance.

[0052] By performing steps 3-6 for each satellite, anomaly flags for M satellites were obtained. However, while generating anomaly flags independently for each satellite allows for assessment of signal quality and triggering of corresponding countermeasures, this only achieves anomaly detection, not anomaly identification. In complex GNSS application scenarios, different types of interference sources (such as multipath and spoofing) have fundamentally different impact patterns on satellite constellations: multipath interference is localized, affecting only a few satellites on specific paths; while spoofing attacks are often global, aiming to hijack the entire receiver and simultaneously affecting most or all satellites within the field of view. Therefore, to understand the nature of interference events from a higher perspective, distinguish between localized multipath interference and global spoofing attacks, and thus be able to initiate more targeted and higher-level countermeasures, a comprehensive analysis of the anomaly flags for all M satellites is necessary.

[0053] In one specific embodiment of this application, the process is as follows: The previous stage involves generating a set of anomaly flags {Flag_1(t), Flag_2(t), ..., Flag_8(t)} in parallel for all M equal to 8 satellites at the latest time t. This implementation process mainly includes three stages: anomaly information aggregation, anomaly satellite counting, and judgment based on classification rules.

[0054] First, at each latest time t, anomalous satellite information aggregation is performed. This stage collects the anomaly flags of all M equal to 8 satellites, forming a Boolean array of anomaly flags. For example, at time t, if the anomaly flags of the 2nd, 3rd, 5th, 6th, and 7th satellites are true, and the rest are false, then the aggregated anomaly flag array is {false, true, true, false, true, true, true, false}. This array comprehensively reflects the impact status of the entire visible satellite constellation at the current time.

[0055] Next, anomaly satellite counting is performed. To increase the stability of the decision and avoid misjudgments due to single-point noise, the anomaly flags within a short decision window (e.g., the most recent 10 epochs) can be smoothed. One method is to calculate the number of times each satellite's anomaly flag is true within that window and then perform the statistical analysis. This embodiment uses an instantaneous counting method, that is, directly counting the number of elements with true values ​​in the anomaly flag array at the current epoch t. In the example above, the anomaly flag array {false, true, true, false, true, true, true, false} contains 5 true values, therefore the anomaly satellite count at the current moment is 5.

[0056] Finally, a pre-defined classification rule is applied to determine the current state. This rule is based on a comparison between the count of abnormal satellites and the total number of visible satellites, using thresholds to divide different state intervals. This step requires pre-setting two key thresholds: a low count threshold T_low and a high proportion threshold P_high. T_low distinguishes between interference-free and interference-affected states and can be set to 1, meaning that interference is considered to exist as long as at least one satellite is abnormal. P_high distinguishes between multipath interference and spoofing attacks, representing the proportion of affected satellites out of the total. Considering the global nature of spoofing attacks, P_high can be set to 0.5, meaning that a spoofing attack is determined when the number of affected satellites reaches or exceeds half of the total.

[0057] Based on these preset values, the classification rules are as follows: First, determine whether the abnormal satellite count is less than the low count threshold T_low. If the abnormal satellite count is 0, i.e., less than 1, the final decision is no interference. Second, if the above condition is not met, determine whether the ratio of the abnormal satellite count to the total number of visible satellites is greater than or equal to the high ratio threshold P_high. In this embodiment, the total number of visible satellites is 8, and P_high is 0.5. Therefore, the judgment condition is abnormal satellite count / 8>=0.5, i.e., whether the abnormal satellite count is greater than or equal to 4. If this condition is met, the final decision is a deception attack. Third, if neither of the above two conditions is met, i.e., the abnormal satellite count is between 1, 2, or 3 (i.e., greater than or equal to T_low but less than M*P_high), the final decision is multipath interference.

[0058] Taking the aforementioned example, the abnormal satellite count is 5. This value is not less than 1, but greater than or equal to 4 (i.e., 8 * 0.5), thus satisfying the second judgment condition. The final decision output is a spoofing attack. This final decision result provides the receiver with a clear insight into the nature of the current interference environment, enabling it to initiate more complex response strategies such as switching to a backup positioning technology or issuing a high-level security alert to the user.

[0059] Specifically, this application illustrates its detection process using a scenario where a vehicle equipped with a GNSS receiver is driving from an open suburban road into a densely populated urban center, and the receiver is currently able to stably track M=8 visible satellites: During the initial suburban driving phase, signal quality is excellent. The SAPTL values ​​of all satellites remain stable around 1.0 with minimal fluctuations. Therefore, the dynamic mean and dynamic standard deviation calculated using a long sliding window also remain stable at approximately 1.0 and 0.1, respectively. Based on this dynamic baseline, the normalized deviation of each satellite fluctuates slightly and randomly around zero, far from sufficient to increase the CUSUM accumulation value to the decision threshold of 5. Therefore, the anomaly flags for all satellites remain false. At this point, the anomaly satellite count is zero, and the final decision correctly determines that there is no interference. When the vehicle enters the urban area, the low-elevation PRN4 and PRN7 satellites begin to experience significant multipath interference, causing their SAPTL values ​​to fluctuate dramatically and rise to approximately 1.5. The dynamic baseline adjustment mechanism of this invention comes into play. The long sliding window captures this change, causing the dynamic mean and standard deviation of the two satellites to gradually and adaptively climb to reflect the new, more complex signal environment. During this baseline adjustment process, the normalized bias may briefly spike, but since multipath interference usually only affects a few satellites, the anomalous satellite count may briefly become 1 or 2. This count is greater than or equal to the low threshold of 1, but less than the product of the total number of satellites (8) and the high proportion threshold of 0.5 (i.e., 4), so the final decision is updated to multipath interference, accurately identifying the current environmental characteristics. Subsequently, in the city center area, a spoofing source suddenly activates, broadcasting a spoofing signal to all 8 satellites. At the moment of the attack, the SAPTL values ​​of all satellites jump sharply from their respective current baselines (some of which have been raised due to multipath). However, due to the inertia of the long sliding window, the dynamic mean and standard deviation cannot immediately respond to this abrupt change and remain near their pre-attack values. This results in a huge positive spike in the normalized bias of all satellites instantaneously. For example, the normalization bias of the PRN1 satellite could be as high as 9.33. These huge bias values ​​cause the cumulative CUSUM of all satellites to accumulate rapidly within a very short time (several epochs) and exceed the decision threshold of 5, resulting in the anomaly flags of all 8 satellites being set to true almost simultaneously. Therefore, the anomaly satellite count instantly becomes 8. The ratio of this count to the total number of satellites is 1.0, which is much greater than the high proportion threshold of 0.5. The final decision is immediately and decisively updated to a deception attack, achieving rapid and accurate identification of this global threat.

[0060] In summary, the GNSS spoofing / multipath interference detection method based on the embodiments of this application has been clarified. Addressing the technical problem that existing GNSS interference detection methods using fixed thresholds cannot adapt to dynamic environments, an adaptive scheme based on dynamic baseline and change point detection is proposed. This scheme abandons the static, one-size-fits-all threshold and instead calculates a dynamic baseline for the Signal Quality Measure (SAPTL) of each satellite in real time and independently, i.e., the dynamic mean and standard deviation that change with the environment. By normalizing and comparing the real-time metric with this dynamic baseline, the baseline drift caused by scene switching (such as entering an urban canyon) can be eliminated, resulting in a standardized deviation sequence unaffected by environmental background interference. Finally, the CUSUM change point detection algorithm, which is highly sensitive to small, continuous changes, is used to analyze this sequence, accurately capturing real signal anomalies caused by spoofing or multipath interference, rather than false fluctuations caused by environmental changes. This solves the fundamental problem of the poor adaptability of fixed thresholds in dynamic environments, which easily leads to false positives and false negatives, significantly improving the robustness and reliability of the detection.

[0061] Figure 7 This is a block diagram of a GNSS spoofing / multipath interference detection device according to an embodiment of this application. Figure 7 As shown, the GNSS spoofing / multipath interference detection device 100 according to an embodiment of this application includes: a SAPTL metric time acquisition module 110, used to acquire SAPTL metric time series of M satellites; a SAPTL metric time dynamic calculation module 120, used to perform channel-specific dynamic baseline calculation on the SAPTL metric time series of the M satellites to obtain the dynamic mean and dynamic standard deviation of the M satellites; and a real-time SAPTL metric acquisition module 130, used to acquire the real-time SAPTL metric of the i-th satellite; the i-th satellite... The satellite feature extraction module 140 is used to extract the dynamic mean and dynamic standard deviation of the i-th satellite from the dynamic mean and dynamic standard deviation of the M satellites; the detection quantity normalization module 150 is used to normalize the detection quantity of the real-time SAPTL metric of the i-th satellite based on the dynamic mean and dynamic standard deviation of the i-th satellite to obtain the normalized deviation of the i-th satellite; the i-th satellite generation module 160 is used to perform CUSUM change point detection on the normalized deviation of the i-th satellite to obtain the anomaly flag of the i-th satellite.

[0062] As described above, the GNSS spoofing / multipath interference detection device 100 according to the embodiments of this application can be implemented in various wireless terminals, such as servers with GNSS spoofing / multipath interference detection algorithms. In one possible implementation, the GNSS spoofing / multipath interference detection device 100 according to the embodiments of this application can be integrated into the wireless terminal as a software module and / or a hardware module. For example, the GNSS spoofing / multipath interference detection device 100 can be a software module in the operating system of the wireless terminal, or it can be an application developed for the wireless terminal; of course, the GNSS spoofing / multipath interference detection device 100 can also be one of many hardware modules of the wireless terminal.

[0063] Alternatively, in another example, the GNSS spoofing / multipath interference detection device 100 and the wireless terminal can also be separate devices, and the GNSS spoofing / multipath interference detection device 100 can be connected to the wireless terminal via wired and / or wireless networks, and transmit interactive information in accordance with an agreed data format.

[0064] Here, those skilled in the art will understand that the specific operation of each step in the above-described GNSS spoofing / multipath interference detection device has been referenced above. Figures 1 to 6 The method for detecting GNSS spoofing / multipath interference is described in detail here, and therefore its repeated description will be omitted.

Claims

1. A method for detecting GNSS spoofing / multipath interference, characterized in that, include: Obtain the SAPTL metric time series of M satellites; The dynamic baseline of the SAPTL metric time series of the M satellites is calculated by channel to obtain the dynamic mean and dynamic standard deviation of the M satellites. Obtain the real-time SAPTL metric for the i-th satellite; Extract the dynamic mean and dynamic standard deviation of the i-th satellite from the dynamic mean and dynamic standard deviation of the M satellites; Based on the dynamic mean and dynamic standard deviation of the i-th satellite, the real-time SAPTL metric of the i-th satellite is normalized by the detection quantity to obtain the normalized deviation of the i-th satellite. The normalized deviation of the i-th satellite is subjected to CUSUM change point detection to obtain the anomaly flag of the i-th satellite; The process of obtaining the SAPTL metric time series for M satellites includes: The original IQ sampling data output by the receiver RF front end at time t is captured and tracked to obtain the quadrature and in-phase components of the leading branch, the quadrature and in-phase components of the instantaneous branch, and the quadrature and in-phase components of the lagging branch. Power conversion is performed on the quadrature and in-phase components of the leading branch, the instantaneous branch, and the lagging branch to obtain the power of the leading branch, the instantaneous branch, and the lagging branch. Calculate the sum of the leading branch power, the instantaneous branch power, and the lagging branch power, and normalize it to obtain the SAPTL value at time t as the SAPTL metric.

2. The GNSS spoofing / multipath interference detection method according to claim 1, characterized in that, Based on the dynamic mean and dynamic standard deviation of the i-th satellite, the real-time SAPTL metric of the i-th satellite is normalized to obtain the normalized bias of the i-th satellite, including: Based on the dynamic mean and dynamic standard deviation of the i-th satellite, the real-time SAPTL metric of the i-th satellite is normalized using the following formula: in, For the real-time SAPTL metric of the i-th satellite, Let be the dynamic mean of the i-th satellite. Let be the dynamic standard deviation of the i-th satellite. Let be the normalized bias of the i-th satellite.

3. The GNSS spoofing / multipath interference detection method according to claim 1, characterized in that, The normalized bias of the i-th satellite is subjected to CUSUM change point detection to obtain the anomaly markers of the i-th satellite, including: Based on the normalized bias of the i-th satellite, the cumulative value of the i-th satellite in the previous epoch is iteratively updated to obtain the cumulative value of the i-th satellite in the current epoch. An anomaly flag for the i-th satellite is generated based on a comparison between a decision threshold and the current epoch cumulative value of the i-th satellite.

4. The GNSS spoofing / multipath interference detection method according to claim 3, characterized in that, Based on the normalized bias of the i-th satellite, the cumulative value of the i-th satellite in the previous epoch is iteratively updated to obtain the cumulative value of the i-th satellite in the current epoch, including: The normalized bias of the i-th satellite is added to the cumulative value of the i-th satellite in the previous epoch, and then the relaxation amount is subtracted to obtain the intermediate sum; The larger of the intermediate sum and zero is taken to obtain the current epoch cumulative value of the i-th satellite.

5. The GNSS spoofing / multipath interference detection method according to claim 4, characterized in that, An anomaly flag for the i-th satellite is generated based on a comparison between a decision threshold and the current epoch cumulative value of the i-th satellite, including: If the current epoch cumulative value of the i-th satellite is greater than the decision threshold, then the anomaly flag of the i-th satellite is determined to be true; If the current epoch cumulative value of the i-th satellite is less than or equal to the decision threshold, then the anomaly flag of the i-th satellite is determined to be false.

6. A GNSS spoofing / multipath interference detection device, characterized in that, include: The SAPTL measurement time acquisition module is used to acquire the SAPTL measurement time series of M satellites, including: capturing and tracking the raw IQ sampling data output by the receiver RF front end at time t to obtain the quadrature and in-phase components of the leading branch, the quadrature and in-phase components of the instantaneous branch, and the quadrature and in-phase components of the lagging branch; performing power conversion on the quadrature and in-phase components of the leading branch, the quadrature and in-phase components of the instantaneous branch, and the quadrature and in-phase components of the lagging branch to obtain the power of the leading branch, the power of the instantaneous branch, and the power of the lagging branch; calculating the sum of the power of the leading branch, the power of the instantaneous branch, and the power of the lagging branch, and normalizing it to obtain the SAPTL value at time t as the SAPTL measurement; The SAPTL metric time dynamic calculation module is used to perform channel-by-channel dynamic baseline calculation on the SAPTL metric time series of the M satellites to obtain the dynamic mean and dynamic standard deviation of the M satellites. The real-time SAPTL metric acquisition module is used to acquire the real-time SAPTL metric of the i-th satellite. The feature extraction module for the i-th satellite is used to extract the dynamic mean and dynamic standard deviation of the i-th satellite from the dynamic mean and dynamic standard deviation of the M satellites. The detection quantity normalization module is used to normalize the real-time SAPTL metric of the i-th satellite based on the dynamic mean and dynamic standard deviation of the i-th satellite to obtain the normalized deviation of the i-th satellite. The i-th satellite generation module is used to perform CUSUM change point detection on the normalized deviation of the i-th satellite to obtain the anomaly flag of the i-th satellite.

Citation Information

Patent Citations

  • GNSS deception jamming detection method based on combined SQM square

    CN115236701A

  • Adaptive estimation of GNSS satellite bias

    CN117083540A