Network attack detection method based on non-fragile fuzzy cooperative interactive observer

By constructing a non-vulnerable fuzzy collaborative interactive observer, the problem of decreased detection performance caused by observer parameter offset is solved, and accurate detection and location diagnosis of false data injection attacks in nonlinear cyber-physical systems are achieved.

CN120934867APending Publication Date: 2025-11-11NORTHEAST DIANLI UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511199105.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing observers suffer from reduced detection performance in nonlinear cyber-physical systems due to parameter offsets, making them ineffective at detecting spoofing attacks.

Method used

A non-vulnerable fuzzy cooperative interactive observer is adopted. By establishing a Takagi-Sugeno senkaku fuzzy model, a virtual auxiliary system and a cooperative interactive structure observer are constructed. By utilizing the difference between trusted and untrusted sensor information, the attack signal is reconstructed and the attack location is detected.

Benefits of technology

It effectively eliminates the influence of observer uncertainty gain, accurately reconstructs attack signals and diagnoses attack locations, thus improving the accuracy and reliability of network attack detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934867A_ABST
    Figure CN120934867A_ABST
Patent Text Reader

Abstract

The invention discloses a network attack detection method based on a non-fragile fuzzy cooperative interactive observer, and belongs to the technical field of cyber-physical system attack detection. According to the method, a virtual auxiliary system containing attack estimation error information is established by means of input and output data of the system, the influence of uncertain gain of the observer on the performance of the observer is fully considered, and the non-fragile fuzzy cooperative interactive observer is constructed. According to the observer constructed by the method, the uncertain gain of the observer is effectively eliminated, and meanwhile, new and available antecedent variables can be constructed. Attack signals are accurately reconstructed through interactive attack estimation error information between new and available antecedent variables and an auxiliary system, and then attack detection is achieved. Meanwhile, the system can give an alarm when an actuator attack and / or a sensor attack occurs, and can diagnose whether the attack occurs in an actuator channel or a sensor channel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of cyber-physical system attack detection technology, and in particular relates to a Takagi-Sugeno (TS) fuzzy cyber-physical system attack detection method based on a non-vulnerable fuzzy cooperative interactive observer. Background Technology

[0002] Existing research has made significant progress in observer-based network attack detection. For example, some studies have reconstructed attack signals by constructing augmented systems and combining them with adjustable proportional-integral observers; others have designed separate state observers and attack estimators to simultaneously estimate the system state and identify attack signals. However, many current studies on detecting attack signals against nonlinear cyber-physical systems (CPS) rely on a hidden assumption: that the environment of the designed observer is ideal and its observer gain remains unchanged. In reality, however, complex factors such as aging circuit components and analog-to-digital conversion can cause parameter shifts in the designed observer during operation, leading to spoofed data injection attacks on nonlinear CPS. This can result in unwanted fluctuations in the designed observer gain during execution, potentially significantly jeopardizing detection performance.

[0003] Therefore, there is an urgent need for a new technical solution to address this problem. Summary of the Invention

[0004] The technical problem to be solved by this invention is to provide a network attack detection method based on a non-vulnerable fuzzy collaborative interactive observer to solve the technical problem that existing observers do not consider the possibility of encountering unexpected fluctuations, resulting in poor accuracy in network attack detection.

[0005] A network attack detection method based on a non-vulnerable fuzzy collaborative interactive observer includes the following steps, which are performed sequentially:

[0006] Step 1: Establish the Takagi-Sugeno fuzzy model based on set description, abbreviated as TS fuzzy model:

[0007] Step 2: Establish a fake data injection attack model;

[0008] Step 3: Establish a virtual auxiliary system that includes estimation error information:

[0009] Step 4: Obtain an attack detection scheme based on a collaborative interaction structure observer.

[0010] The process of establishing a TS fuzzy model based on set description is as follows:

[0011] Based on trusted sensors, the TS fuzzy model provides the following description of a nonlinear cyber-physical system (CPS):

[0012]

[0013] The CPS includes a controller and sensors, and the sensors include both sensors protected by the encrypted communication network and unprotected sensors.

[0014] In the formula, Let y1(t) represent the time derivative of x(t); x(t) is an n-dimensional vector representing the system state of the CPS at time t; u(t) is the l-dimensional controller input signal at time t; y1(t) is the mh... s A dimensional vector, representing the sensor output protected by the encrypted communication network at time t; y2(t) is a vector representing the output of the sensor at time t. s A dimensional vector, representing the output of the unprotected sensor at time t; i 1→o =i1i2...i o This indicates that there are o fuzzy antecedent variables and that the set indices of each fuzzy variable are combined in order so that they uniquely correspond to a combination of all fuzzy antecedent conditions. For the i-th 1→o Under a set of fuzzy rules, the state transition matrix describes the state of the CPS system; For the i-th 1→o Under a fuzzy rule, the control input matrix describes the influence of the controller input on the system state; For the i-th 1→o Under the fuzzy rules, the system state is mapped to the protected sensor observation matrix output by the sensors protected by the encrypted communication network; For the i-th 1→o Under the fuzzy rule, the system state is mapped to the unprotected sensor observation matrix output by the unprotected sensor;

[0015] The antecedent variable at time t is h g (t) represents the g-th fuzzy variable, where g = 1, ..., 0; using Indicates time t based on h g The fuzzy set of (t), i g =1,...,r g , indicating that the fuzzy set of the g-th fuzzy variable has r g Therefore, it can be represented as follows:

[0016]

[0017] use Represents the i-th fuzzy variable of the g-th fuzzy variable g There are fuzzy set membership functions, and the total number of fuzzy rules is .

[0018] The Cartesian product of a set is defined as:

[0019]

[0020] Among them, S i ={1,...,r g},get:

[0021]

[0022] Where A(μ) and B(μ) are system matrices obtained by weighting according to fuzzy rules, respectively:

[0023]

[0024] In the formula, This represents the activation strength of the entire rule at time t. Let be the membership degree of a single fuzzy condition at time t;

[0025] The g-th fuzzy variable belongs to its i-th fuzzy variable g The normalized membership formula for a fuzzy set is shown below:

[0026] Where 1≤i g ≤r g ,and

[0027] The TS fuzzy model based on set description divides the fuzzy weight part into two parts: a measurable part and an unmeasurable part;

[0028] definition Then it can be represented as follows:

[0029]

[0030] The parameters of the TS fuzzy model based on set description satisfy the following conditions:

[0031] Condition 1: Matrix B has full column rank, matrix C1 has full row rank, and rank(C1B) = rank(B) = 1, where rank represents the rank of the matrix;

[0032] Condition 2: For any complex number s with a positive real part, its rank satisfies

[0033] The specific method for establishing the fake data injection attack model is as follows:

[0034] Since the controller input signal u(t) and the unprotected sensor output signal y2(t) transmitted over the network are susceptible to FDIA (Fake Data Injection) attacks, after the attack occurs, signals u(t) and y2(t) become:

[0035]

[0036] In the formula, f a (t) and f s Let (t) represent the controller attack signal and the sensor attack signal at time t, respectively. This indicates a spoofed data injection (FDIA) attack signal, and introduces the following attack model:

[0037]

[0038] Where: a(t) is an o1-dimensional vector, representing the state of the attack model. Let g(t, a(t), φ(t)) represent the derivative of a(t) with respect to time, and g(t, a(t), φ(t)) be a linear or nonlinear function; φ(t) and φ f (t) are all system input signals that are unknown but bounded, and the signal φ(t) is an o2-dimensional vector. It is a 3-dimensional vector; f(t) is l+h s 3D vector, C f For (l+h) s A 1×1 dimensional matrix, D f For (l+h) s A 3-dimensional matrix, C f and D f All are unknown matrices;

[0039] The state of the attack model is unknown, and it is locally Lipschitz with respect to (a(t), φ(t)), satisfying the following conditions:

[0040] a) If φ(t) = 0, then the attack model has an unknown but bounded equilibrium point a. e ;

[0041] b) Error at time t Dynamics of error It is an input-to-state stable model, meaning the attack model is stable. When dealing with unknown but bounded signals like φ(t), the defined error... It won't diverge without limit, but will remain within a set reasonable range, and can even be controlled by external input. It converges to the desired state.

[0042] The process of establishing the virtual auxiliary system containing estimation error information is as follows:

[0043] 1) An unprotected sensor output y2(t) will affect the sensor attack signal f. s Therefore, the following auxiliary filter is introduced to process the unprotected sensor output y2(t):

[0044]

[0045] Where, x f (t) is h s A dimensional vector representing the filter state at time t. x represents f (t) The derivative of A with respect to time f for h s ×h s A dimensional matrix and A f >0, is a filter matrix, v f (t) is h s A dimensional vector, representing the filter input at time t;

[0046] Using the information x from this auxiliary filter f (t) and v f (t) Proposed design of an observer;

[0047] make The following augmentation system is obtained:

[0048]

[0049] Where ξ(t) is n+h s A dimensional vector representing the augmented system state at time t; Let ξ denote the derivative of ξ with respect to time; y(t)ξ is an m-dimensional vector representing the augmented system output at time t; A ξ To augment the system state parameter matrix, A ξ For (n+h) s )×(n+h s A 3D matrix; B ξ To augment the system input matrix, B ξ For (n+h) s )×(l+h s A 3D matrix; C ξ To augment the system output matrix, C ξ For m×(n+h) s A 1+h dimensional matrix; U is l+h s A dimensional vector, representing the input of the augmented system at time t; these matrices are represented as follows:

[0050]

[0051] For the augmented system, in the dimension matrix P = PT >0 and In this case, The following conditions must be met:

[0052] He(PA χ,11 (μ)+MA χ,21 (μ))<0;

[0053] 2) Perform a linear transformation on the augmented system:

[0054] For C ξ Perform singular value decomposition to obtain C. ξ =S C V C D C Among them, V C =[X C [,0],X C S is a diagonal matrix. C and D C For a unitary matrix, there exists Make I represents the identity matrix, where:

[0055]

[0056] And T C B ξ =[B1,B2] T In the formula, T C To achieve C ξ The transformation matrices for block diagonalization, B1 and B2, are the input matrices of the augmented system. ξ The block submatrix after linear transformation;

[0057] Based on condition 1, we obtain rank(C) ξ B ξ ) = rank(B ξ )=l+h s And C ξ B ξ =B2, therefore B2 is full column rank, and there exists a transformation matrix. Make In the formula

[0058] V B =[B χ,2 ,0] T , It is a unitary matrix, and B χ,2 It is in full order;

[0059] Then there is the input transformation matrix:

[0060]

[0061] Let the transformation matrix T BC =T B T C The system parameters after linear transformation are:

[0062]

[0063] In the formula, A 11 (μ), A 11 (μ), A 11 (μ), A 11 (μ) is the transformed matrix T BC The state submatrix after linear transformation It is through the transformation matrix B ξ The control input submatrix after linear transformation It is through the transformation matrix C ξ The control input submatrix after linear transformation;

[0064] Based on the above transformation, the state transformation matrix is ​​obtained:

[0065]

[0066] and L is (n+h) s -m)×(mlh s A 1 / 2 dimensional matrix; then there exists a matrix T. χ =T A T BC The system parameters after linear transformation are:

[0067]

[0068] 3) The result of linear transformation of the augmented system is:

[0069] y ξ (t)=χ2(t); where, A χ,11 (μ) is the Herwitz matrix; the system state at time t after the linear transformation is χ(t), χ(t) = [χ1(t), χ2(t)] T =T χ ξ(t); χ1(t) is n+h s -m-dimensional vector χ1(t) is the derivative of χ1(t) with respect to time, and χ2(t) is an m-dimensional vector. It is the derivative of χ²(t) with respect to time, matrix A χ,11 (μ) is (n×h) s -m)×(n×h s -m) dimensional vector, A χ,12(μ) is (n×h) s A)×m dimensional vector χ,21 (μ) is m×(n×h) s -m) dimensional vector, A χ,22 (μ) is an m×m dimensional vector, B χ,2 For m×(l+h) s )-dimensional vector; T χ A is a linear transformation matrix; χ C is the system state matrix after linear transformation; χ This is the output matrix after linear transformation;

[0070] 4) Based on the impact of false data injection attacks on sensor measurements, the antecedent variables of the nonlinear cyber-physical system description performed by the TS fuzzy model are divided into the following four cases:

[0071] a) The antecedent variables do not contain any system state variables, meaning that the antecedent variables are independent of the system state and can be directly used;

[0072] b) The antecedent variables are constructed directly or indirectly from the system state variables and the state measurements come from reliable sensors. That is, the antecedent variables depend on the measurable and reliable system state and can be directly utilized.

[0073] c) The antecedent variable contains the system state and the state measurement of the variable comes from an untrusted sensor. That is, the antecedent variable depends on the measurable but questionable system state, which may be affected by sensor attacks and therefore cannot be used directly.

[0074] d) The antecedent variable is a system state that cannot be directly or indirectly measured, that is, the construction of the antecedent variable depends on the unmeasurable system state and cannot be utilized;

[0075] 5) To improve the non-fragility of the observer, a class of fuzzy cooperative interaction observers is constructed and utilizes antecedent variables. The structure of the observer is as follows:

[0076]

[0077] in It is a reliable antecedent variable obtained through the sensor output y1(t) protected by an encrypted communication network. Let represent the fuzzy set of reliable antecedent variables obtained at time t based on the sensor output protected by the encrypted communication network, where p represents the number of reliable antecedent variables obtained from the sensor output protected by the encrypted communication network, and 1 ≤ p ≤ 0. The preceding variable is an untrusted or unmeasurable variable obtained through the output y2(t) of an unprotected sensor and cannot be used. This is an estimate of f(t);

[0078] In the formula, It is an n+hs-m dimensional vector, which is an estimate of χ1; yes The derivative with respect to time; It is an m-dimensional vector, representing an estimate of χ²; yes The derivative with respect to time; Let y be an m-dimensional vector. ξ The estimate; in addition, For l+h s A dimensional vector is an estimate of the attack signal f; a matrix Let be an m×m dimensional matrix, representing the observer gain. The matrix is ​​m×m dimensional and represents the parameter drift of the observer gain during implementation. New antecedent variables constructed for the observer;

[0079] in, The formula is as follows:

[0080]

[0081] In the formula, and Both are l+h s The dimensional vector is the constructed virtual auxiliary system. yes The derivative with respect to time; ρ>0 is a constant; for Initial value; and All are (l+h) s )×(l+h s The 1 / 2 dimensional matrix represents the system parameters of the constructed virtual auxiliary system;

[0082] 6) Uncertainty gain of the observer The following constraints must be met:

[0083]

[0084] and Let be given symmetric matrices, and let there exist any positive scalar ε1 such that the given matrix ε1 ε2 ε3 ε4 ε5 ε6 ε7 ε8 ε9 ε1 ε9 ε1 ε2 ε1 ε2 ε3 ...4 ε5 ε6 ε7 ε8 and Under the condition t > 0, the following conditions are met:

[0085]

[0086] After that, The error system is as follows:

[0087]

[0088] Where e1 is χ1 and its estimate The error between them e1 is the derivative of e1 with respect to time, and e2 is the χ² and its estimate. The error between them It is the derivative of e² with respect to t, and and The formula for the deviation term of the error system is as follows:

[0089]

[0090] Let the error deviation vector Considering the error system, through integration and differentiation, we prove that the following equations are equivalent:

[0091]

[0092] Where yξ(0) is y ξ The initial value of (t), for Initial value;

[0093] This shows that the uncertainty of the observer gain during the construction process affects the observer performance, and the virtual auxiliary system... It includes error information about attack reconstruction, through the introduction of two virtual auxiliary systems. and The coordinated interaction with error e2 can utilize the reconstructed error information to improve the observation accuracy of the attack signal;

[0094] 7) When the linearly transformed system, observer, and attack model satisfy the relevant settings, for a given dimension matrix... and β>0 and The transpose of is equal to itself, in the case of a matrix. in The transpose of is equal to itself, and the positive scalar ε1, η1,η2,η3,η4η5,η6, and In the case of , the following linear matrix inequality is satisfied:

[0095]

[0096] in,

[0097]

[0098] Therefore, for the case where Ω = 0, the observer's estimation error converges to a compact set within a set threshold range near 0, and for the case where ρ > 0 and is sufficiently large, For the case where Ω ≠ 0, the observer estimation error system has a suppression performance of order γ against Ω; where γ = λ max (γ e ) / λ min (η e ),

[0099] And for matrices but For matrix but

[0100] The method for obtaining the attack detection scheme based on the cooperative interaction structure observer in step four is as follows:

[0101] The attack signal f(t) is set to be a signal. The refactored attack detection scheme based on the collaborative interaction structure observer is as follows: (The rest of the text appears to be a fragmented and nonsensical string of characters and symbols. A more accurate translation would require the original, coherent text.) Formula and Uncertainty Gain The observer under the constraint conditions generates the detector signal.

[0102] The detection logic is as follows:

[0103] The detector signal is If the detector does not trigger an alarm, the system is determined to be in normal operating condition.

[0104] If the detector detects fluctuations in the actuator channel output from the observer but no fluctuations in the sensor channel output from the observer, then the attack only occurred in the actuator channel, and the detector can reproduce the attack signal.

[0105] If the detector detects fluctuations in the sensor channel output from the observer but no fluctuations in the actuator channel output from the observer, then the attack only occurred in the sensor channel, and the detector can reproduce the attack signal.

[0106] If the detector detects fluctuations in both the actuator and sensor channels from the observer's output, then the attack occurred in both the actuator and sensor channels, and the detector can reproduce the attack signal.

[0107] Through the above design scheme, the present invention can bring the following beneficial effects:

[0108] This invention utilizes system input / output data to establish a virtual auxiliary system incorporating attack estimation error information. It fully considers the impact of observer uncertainty gain on observer performance, constructing a class of non-vulnerable fuzzy cooperative interactive observers. The observer constructed in this invention effectively eliminates observer uncertainty gain while constructing new ones. By interacting with the auxiliary system using available antecedent variables and attack estimation error information, it accurately reconstructs the attack signal, thereby achieving attack detection. Simultaneously, it enables the system to issue alarms when actuator attacks and / or sensor attacks occur, and can diagnose whether the attack occurred in the actuator channel or the sensor channel. Attached Figure Description

[0109] The present invention will be further described below with reference to the accompanying drawings and specific embodiments:

[0110] Figure 1 This is a waveform diagram of the actuator channel being attacked in the simulation example of this invention;

[0111] Figure 2 This is a waveform diagram of the sensor channel being attacked in the simulation example of this invention.

[0112] Figure 3 This is a diagram of actuator channel fluctuation signals observed by a non-fragile fuzzy cooperative interactive observer in the simulation examples of this invention.

[0113] Figure 4 This is a diagram of sensor channel fluctuation signals observed by a non-fragile fuzzy cooperative interactive observer in the simulation examples of this invention.

[0114] Figure 5 This is a diagram of the actuator channel fluctuation signal when only the actuator fluctuates in the simulation example of this invention;

[0115] Figure 6 This is a simulation example of the sensor channel fluctuation signal when only the actuator fluctuates.

[0116] Figure 7 This is a diagram of the actuator channel fluctuation signal observed by a non-fragile fuzzy cooperative interactive observer, where only the actuator fluctuates in the simulation examples of this invention.

[0117] Figure 8 This is a diagram of sensor channel fluctuation signals observed by a non-fragile fuzzy cooperative interactive observer, where only the actuator fluctuates in the simulation examples of this invention.

[0118] Figure 9 This is a simulation example of the actuator channel fluctuation signal when only the sensor fluctuates.

[0119] Figure 10This is a simulation example of the sensor channel fluctuation signal when only the sensor fluctuates.

[0120] Figure 11 This is a simulation example of the present invention, showing the actuator channel fluctuation signal observed by a non-fragile fuzzy cooperative interactive observer where only the sensor fluctuates;

[0121] Figure 12 This is a diagram of sensor channel fluctuation signals observed by a non-fragile fuzzy cooperative interactive observer, where only sensor fluctuations occur in the simulation examples of this invention. Detailed Implementation

[0122] Network attack detection methods based on non-vulnerable fuzzy collaborative interactive observers specifically include:

[0123] S1: Establish a TS fuzzy model based on set description:

[0124] Based on reliable sensors, the TS fuzzy system model can describe nonlinear CPS as follows:

[0125]

[0126] In the formula, Let represent the time derivative of the system state at time t; x(t) is an n-dimensional vector representing the system state of the CPS at time t; u(t) is the l-dimensional controller input signal at time t; y1(t) is the mh... s A dimensional vector, representing the sensor output protected by the encrypted communication network at time t; y2(t) is a vector representing the output of the sensor at time t. s A dimensional vector, representing the output of the unprotected sensor at time t; i 1→o =i1i2...i o This indicates that there are o fuzzy antecedent variables and that the set indices of each fuzzy variable are combined in order so that they uniquely correspond to a combination of all fuzzy antecedent conditions. For the i-th 1→o Under a set of fuzzy rules, the state transition matrix describes the state of the CPS system; For the i-th 1→o Under a fuzzy rule, the control input matrix describes the influence of the controller input on the system state; For the i-th 1→o Under the fuzzy rules, the system state is mapped to the protected sensor observation matrix output by the sensors protected by the encrypted communication network; For the i-th 1→o Under the fuzzy rule, the system state is mapped to the unprotected sensor observation matrix output by the unprotected sensor;

[0127] h g(t) is the antecedent variable at time t, g = 1,...,0. Indicated based on h g The fuzzy set of (t), i g =1,...,r g The fuzzy set representing the g-th fuzzy variable is r. g indivual, Represents the i-th fuzzy variable of the g-th fuzzy variable g A fuzzy set membership function, fuzzy rule

[0128] The total number is

[0129] The Cartesian product of a set is defined as:

[0130] Where S i ={1,...,r g}, we can get:

[0131]

[0132] Where A(μ) and B(μ) are system matrices obtained by weighting according to fuzzy rules, respectively:

[0133]

[0134] The activation strength of the entire rule. For the membership degree of a single fuzzy condition, For the g-th fuzzy variable to belong to its i-th fuzzy variable g Normalized membership degree of a fuzzy set, 1≤i g ≤r g ,and For 1≤g≤o.

[0135] Set-based TS models make more effective use of the properties of product inference engines and have advantages that traditional fuzzy models do not have in some cases. First, they can divide the fuzzy weights into two parts: the measurable part and the unmeasurable part, which traditional TS fuzzy models cannot do. In addition, using set-based fuzzy models helps to reduce the conservatism problem in design.

[0136] Assumption The original system can then be represented as:

[0137]

[0138] The system parameters satisfy the following assumptions:

[0139] Assumption 1: Matrix B has full column rank, matrix C1 has full row rank, and rank(C1B) = rank(B) = 1, where rank represents the rank of the matrix;

[0140] Assumption 2: For any complex number s with a positive real part, its rank satisfies

[0141] S2: Establish a fake data injection attack model:

[0142] Since the control input u(t) transmitted over the network and the unprotected sensor measurement signal y2(t) are susceptible to False Data Injection Attack (FDIA), after an attack occurs, these attacked signals will become:

[0143]

[0144] In the formula, f a (t) and f s (t) represent actuator attacks and sensor attacks, respectively. Let This indicates a spoofed data injection (FDIA) attack signal, and introduces the following attack model:

[0145]

[0146] Where: a(t) is an o1-dimensional vector, representing the state of the attack model. Let g(t, a(t), φ(t)) represent the derivative of a(t) with respect to time, where g(t, a(t), φ(t)) is a linear or nonlinear function; the signal φ(t) is an o2-dimensional vector. Let φ(t) and φ be 3-dimensional vectors. f f(t) are all system inputs and are unknown but bounded; f(t) is l+h s 3D vector, C f For (l+h) s A 1×1 dimensional matrix, D f For (l+h) s A 3-dimensional matrix, C f and D f All are unknown matrices; the state of the attack model is unknown, and it is locally Lipschitz with respect to (a(t), φ(t)), satisfying the following conditions:

[0147] a) When φ=0, system (3) has an unknown but bounded equilibrium point a. e System (3) is represented by the system referred to in formula (3);

[0148] b) Error dynamics It is the input that makes the state stable;

[0149] S3: Establish a virtual auxiliary system that includes estimation error information:

[0150] As can be seen from equation (2), the sensor output y2(t) may affect the sensor attack f. s Therefore, the following auxiliary filter is introduced to process y2(t):

[0151]

[0152] Where, x f for h s A dimensional vector representing the filter state. x represents f The derivative with respect to time, A f for h s ×h s A dimensional matrix and A f >0, is a filter matrix, v f for h s A dimensional vector represents the filter input; for ease of description, the time-dependent function t is omitted in some cases; since the introduced auxiliary filter is located at the control center, the proposed observer can utilize the information x from the auxiliary filter within the considered framework. f and v f .

[0153] make Then, the following augmentation system was obtained:

[0154]

[0155] Where ξ is n+h s A dimensional vector representing the state of the augmented system. Let y be the derivative of ξ with respect to time. ξ Let A be an m-dimensional vector representing the output of the augmented system. ξ For (n+h) s )×(n+h s A 3D matrix, B ξ For (n+h) s )×(l+h s A 3D matrix, C ξ For m×(n+h) s A 3D matrix, A ξ To augment the system state parameter matrix, B ξ To augment the system input matrix, C ξ To augment the system output matrix, U is l+h s Dimensional vectors, representing the inputs to the augmented system, are shown below:

[0156]

[0157]

[0158] If there exists a matrix of appropriate dimension P = P T >0 and The following conditions must be met:

[0159]

[0160] As can be seen from the known proof, formula (5) can be linearly transformed.

[0161] For C ξ Singular value decomposition yields C ξ =S C V C D C Among them, V C =[X C [,0],X C S is a diagonal matrix. C and D C It is a unitary matrix. There exists... Make in:

[0162]

[0163] And T C B ξ =[B1,B2] T .

[0164] Based on the assumption, we can obtain rank(C). ξ B ξ ) = rank(B ξ )=l+h s And C ξ B ξ =B2, therefore B2 is column full rank, and exists Make In the formula It is a unitary matrix, and B χ,2 It is fully ranked. Then:

[0165]

[0166] Let T BC =T B T C The system parameters after linear transformation are:

[0167]

[0168] Based on the above transformation, we can obtain:

[0169]

[0170] in, L is (n+h) s -m)×(mlh s A 3D matrix. Then there exists a matrix T. χ =T A T BC The system parameters after linear transformation are:

[0171]

[0172] The obtained linear transformation result is:

[0173]

[0174] In the formula, A χ,11 (μ) is the Herwitz matrix, χ = [χ1, χ2] T =T χ ξ represents the system state after linear transformation, and χ1 represents n+h. s -m-dimensional vector χ1 is the derivative of χ1 with respect to time, and χ2 is an m-dimensional vector. It is the derivative of χ² with respect to time, matrix A χ,11 (μ) is (n×h) s -m)×(n×h s -m) dimensional vector, A χ,12 (μ) is (n×h) s A)×m dimensional vector χ,21 (μ) is m×(n×h) s -m) dimensional vector, A χ,22 (μ) is an m×m dimensional vector, B χ,2 For m×(l+h) s )-dimensional vector.

[0175] Based on the impact of false data injection attacks on sensor measurements, the antecedent variables of the fuzzy system (1) can be divided into the following four cases:

[0176] a) Independent of the system state, it can be directly utilized.

[0177] b) It depends on a measurable and reliable system state that can be directly utilized.

[0178] c) It relies on measurable, questionable system states, which may be susceptible to sensor attacks and therefore cannot be directly exploited.

[0179] d) It depends on an unmeasurable system state and cannot be utilized.

[0180] Subsequently, to improve the non-fragility of the observer, a class of fuzzy cooperative interaction observers is constructed to build trustworthy and exploitable antecedent variables. The structure of the observer is as follows:

[0181]

[0182] in It is reliable. It is untrustworthy or immeasurable and cannot be exploited. For n+h s -m-dimensional vector, is an estimate of χ1. yes The derivative with respect to time; Let be an m-dimensional vector, representing an estimate of χ². yes The derivative with respect to time; Let y be an m-dimensional vector. ξ The estimate; in addition, For l+h s The dimensional vector is an estimate of the attack signal f. A s Let m×m be the observer gain matrix. Let be an m×m dimensional matrix, representing the observer gain. The matrix is ​​m×m dimensional and represents the parameter drift of the observer gain during implementation. New predecessor variables are constructed for the observer.

[0183]

[0184] in, and Both are l+h s The dimensional vector is the constructed virtual auxiliary system. yes The derivative with respect to time; ρ>0 is a constant; for The initial value of . and All are (l+h) s )×(l+h s The 1 / 2-dimensional matrix represents the system parameters of the constructed virtual auxiliary system, which will be determined later.

[0185] Uncertainty gain of the observer The following constraints must be met:

[0186]

[0187] There exists any positive scalar ε1 such that the matrix in the hypothesis... and When t > 0, the following condition is met:

[0188]

[0189] After that, The error system is as follows:

[0190]

[0191] Where e1 is χ1 and its estimate The error between them e1 is the derivative of e1 with respect to time, and e2 is the χ² and its estimate. The error between them It is the derivative of e² with respect to t.

[0192]

[0193] make Considering the error system, through integration and differentiation, we prove that the following equations are equivalent:

[0194]

[0195] Among them, y ξ (0) is y ξ The initial value of (t), for The initial value of .

[0196] This shows that the impact of the uncertainty of the observer gain on the observer performance during the actual construction process has been fully considered. On the other hand, the virtual auxiliary system... It includes error information about attack reconstruction, through the introduction of two virtual auxiliary systems. and The coordinated interaction with system e2 can make full use of reconstruction error information, thereby improving the observation accuracy of attack signals.

[0197] The system after linear transformation, the observer, and the attack model satisfy the relevant assumptions. For a given matrix of appropriate dimension... and β>0 and The transpose of is equal to itself if a matrix of suitable dimension exists. in The transpose of is equal to itself, and the positive scalar ε1, η1,η2,η3,η4η5,η6, and Then the following linear matrix inequalities are satisfied.

[0198] in,

[0199]

[0200] Therefore, when Ω = 0, the observer's estimation error converges to a compact set near 0, and when ρ > 0 and is sufficiently large,

[0201] When Ω ≠ 0, the observer estimation error system has a suppression performance of order γ against Ω; where

[0202] γ=λ max (γ e ) / λ min (η e ),

[0203] And for the appropriate For the appropriate

[0204] S4: Attack Detection Scheme Based on Cooperative Interaction Structure Observer

[0205] because This means that the attack signal f can be generated by the signal Therefore, for the purpose of attack detection, this invention uses the reconstructed attack signal as a detector signal to monitor system anomalies, assuming that the attack signal f(t) has already been converted from the signal... Reconstruction. The attack detection scheme based on the proposed observer can be summarized as follows:

[0206] a) The observer in formulas (9)-(10) generates detector signals.

[0207] b) The detection logic is as follows:

[0208] When the detector signal is When the detector does not trigger an alarm, it means that the system is in normal operating condition.

[0209] When the detector receives the waveform signal output by the observer, it reproduces the attack signal, triggers an alarm, and determines that the system has been attacked.

[0210] S5: Simulation Examples

[0211] To verify the effectiveness and superiority of the proposed control strategy, a numerical simulation example is introduced and validated using MATLAB software. The nonlinear CPS model is described using the TS fuzzy model as follows:

[0212]

[0213] Where z(t) = [z1(t), z2(t), z3(t), z4(t)] T ,

[0214] μ1=(sin(z3) / z3+0.2172) / 1.2172, μ2=1-μ1, considering their parameters as follows:

[0215]

[0216] C2 = [0 1 0 0].

[0217] As can be seen, the system state z3(t) related to the antecedent variables is not measured by the sensor, and therefore cannot be used in a fuzzy observer. To solve this problem, an observer is used to estimate the system state. New antecedent variables are constructed based on the estimated system state for use in the observer design.

[0218] Introducing A f An auxiliary filter with a value of 1 is used to process the output signal of the attacked sensor. Then, an augmented system can be obtained. Then, assume the matrix related to the observer's uncertainty gain is:

[0219]

[0220] By using the LMI toolbox in MATLAB to solve formulas (13), (14), and (15), the parameters of the fuzzy observer can be obtained as follows:

[0221] ρ = 200,

[0222]

[0223] Furthermore, the possibility of spoofed data injection attacks on the system's actuators and sensors was also considered. for:

[0224] a) When t∈[0,15)s, there is no attack:

[0225] b) When t∈[15,30)s, attack 1 occurs:

[0226]

[0227] c) When t∈[30,45)s, attack 2 occurs:

[0228]

[0229] When t∈[45,60)s, attack 3 occurs:

[0230]

[0231] Then, under the above-mentioned attacks, the two attack signals were observed, and the results are as follows: Figures 1 to 12 As shown. From Figures 1 to 4 As can be seen, no attack occurred between 0 and 15 seconds, and the attack signal was [3sin(4t), 2cos(4t)] between 15 and 30 seconds. T The observer successfully detected the attack signal at this time. Between 30s and 45s, the attack signal changed to [4+sin(0.5t),-2+cos(0.4t)], and the waveform observed by the observer also changed accordingly, accurately observing the actual waveform signal. Finally, between 45s and 60s, the attack signal became a more complex signal 4a(t)+4×[cos(3t),-sin(3t)cos(0.3t)], which the observer of the present invention could still accurately observe. Therefore, it can be seen that the non-fragile fuzzy cooperative interaction observer designed in this invention can accurately observe the false data injection attack signal received by the system, including the waveform of the system being attacked, the time of the attack, and the size of the attack, and can issue an alarm based on the detected attack signal.

[0232] from Figures 5 to 12 As can be seen, when only actuator attacks or sensor attacks occur, the attack detection method of this invention also only reproduces the attack signal in the channel where the attack occurred and triggers the alarm mechanism of that channel. This indicates that the observer can accurately diagnose the channel where the attack signal occurs and trigger an alarm for that channel. Therefore, the attack signal detection method based on a non-fragile fuzzy cooperative interaction observer designed in this invention not only eliminates the influence of the observer's uncertain gain, but also accurately detects the channel where the attack signal occurs and triggers an alarm when an attack occurs in that channel.

Claims

1. A network attack detection method based on a non-vulnerable fuzzy collaborative interactive observer, characterized in that: Includes the following steps, And the following steps are performed in sequence: Step 1: Establish the Takagi-Sugeno fuzzy model based on set description, abbreviated as TS fuzzy model: Step 2: Establish a fake data injection attack model; Step 3: Establish a virtual auxiliary system that includes estimation error information: Step 4: Obtain an attack detection scheme based on a collaborative interaction structure observer.

2. The network attack detection method based on a non-vulnerable fuzzy cooperative interactive observer according to claim 1, characterized in that: The process of establishing a TS fuzzy model based on set description is as follows: Based on trusted sensors, the TS fuzzy model provides the following description of a nonlinear cyber-physical system (CPS): The CPS includes a controller and sensors, and the sensors include both sensors protected by the encrypted communication network and unprotected sensors. In the formula, Let y1(t) represent the time derivative of x(t); x(t) is an n-dimensional vector representing the system state of the CPS at time t; u(t) is the l-dimensional controller input signal at time t; y1(t) is the mh... s A dimensional vector, representing the sensor output protected by the encrypted communication network at time t; y2(t) is a vector representing the output of the sensor at time t. s A dimensional vector, representing the output of the unprotected sensor at time t; i 1→o =i1i2...i o This indicates that there are o fuzzy antecedent variables and that the set indices of each fuzzy variable are combined in order so that they uniquely correspond to a combination of all fuzzy antecedent conditions. For the i-th 1→o Under a set of fuzzy rules, the state transition matrix describes the state of the CPS system; For the i-th 1→o Under a fuzzy rule, the control input matrix describes the influence of the controller input on the system state; For the i-th 1→o Under the fuzzy rules, the system state is mapped to the protected sensor observation matrix output by the sensors protected by the encrypted communication network; For the i-th 1→o Under the fuzzy rule, the system state is mapped to the unprotected sensor observation matrix output by the unprotected sensor; The antecedent variable at time t is h g (t) represents the g-th fuzzy variable, where g = 1, ..., 0; using Indicates time t based on h g The fuzzy set of (t), i g =1,...,r g , indicating that the fuzzy set of the g-th fuzzy variable has r g Therefore, it can be represented as follows: use Represents the i-th fuzzy variable of the g-th fuzzy variable g There are fuzzy set membership functions, and the total number of fuzzy rules is . The Cartesian product of a set is defined as: Among them, S i ={1,...,r g },get: Where A(μ) and B(μ) are system matrices obtained by weighting according to fuzzy rules, respectively: In the formula, This represents the activation strength of the entire rule at time t. Let be the membership degree of a single fuzzy condition at time t; The g-th fuzzy variable belongs to its i-th fuzzy variable g The normalized membership formula for a fuzzy set is shown below: Where 1≤i g ≤r g ,and The TS fuzzy model based on set description divides the fuzzy weight component into two parts: a measurable part and an unmeasurable part; definition Then it can be represented as follows: The parameters of the TS fuzzy model based on set description satisfy the following conditions: Condition 1: Matrix B has full column rank, matrix C1 has full row rank, and rank(C1B) = rank(B) = 1, where rank represents the rank of the matrix; Condition 2: For any complex number s with a positive real part, its rank satisfies 3. The network attack detection method based on a non-vulnerable fuzzy cooperative interactive observer according to claim 1, characterized in that: The specific method for establishing the fake data injection attack model is as follows: Since the controller input signal u(t) and the unprotected sensor output signal y2(t) transmitted over the network are susceptible to FDIA (Fake Data Injection) attacks, after the attack occurs, signals u(t) and y2(t) become: In the formula, f a (t) and f s Let (t) represent the controller attack signal and the sensor attack signal at time t, respectively. This indicates a spoofed data injection (FDIA) attack signal, and introduces the following attack model: Where: a(t) is an o1-dimensional vector, representing the state of the attack model. Let g(t, a(t), φ(t)) represent the derivative of a(t) with respect to time, and g(t, a(t), φ(t)) be a linear or nonlinear function; φ(t) and φ f (t) are all system input signals that are unknown but bounded, and the signal φ(t) is an o2-dimensional vector. It is a 3-dimensional vector; f(t) is l+h s 3D vector, C f For (l+h) s A 1×1 dimensional matrix, D f For (l+h) s A 3-dimensional matrix, C f and D f All are unknown matrices; The state of the attack model is unknown, and it is locally Lipschitz with respect to (a(t), φ(t)), satisfying the following conditions: a) If φ(t) = 0, then the attack model has an unknown but bounded equilibrium point ae; b) Error at time t Dynamics of error It is an input-to-state stable model, meaning the attack model is stable. When dealing with unknown but bounded signals like φ(t), the defined error... It won't diverge without limit, but will remain within a set reasonable range, and can even be controlled by external input. It converges to the desired state.

4. The network attack detection method based on a non-vulnerable fuzzy cooperative interactive observer according to claim 2, characterized in that: The process of establishing the virtual auxiliary system containing estimation error information is as follows: 1) An unprotected sensor output y2(t) will affect the sensor attack signal f. s Therefore, the following auxiliary filter is introduced to process the unprotected sensor output y2(t): Where, x f (t) is h s A dimensional vector representing the filter state at time t. x represents f (t) The derivative of A with respect to time f for h s ×h s A dimensional matrix and A f >0, is a filter matrix, v f (t) is h s A dimensional vector, representing the filter input at time t; Using the information x from this auxiliary filter f (t) and v f (t) Proposed design of an observer; make The following augmentation system is obtained: Where ξ(t) is n+h s A dimensional vector representing the augmented system state at time t; Let ξ denote the derivative of ξ with respect to time; y(t)ξ is an m-dimensional vector representing the augmented system output at time t; A ξ To augment the system state parameter matrix, A ξ For (n+h) s )×(n+h s A 3D matrix; B ξ To augment the system input matrix, B ξ For (n+h) s )×(l+h s A 3D matrix; C ξ To augment the system output matrix, C ξ For m×(n+h) s A 1+h dimensional matrix; U is l+h s A dimensional vector, representing the input of the augmented system at time t; these matrices are represented as follows: For the augmented system, in the dimension matrix P = P T >0 and In this case, The following conditions must be met: A (PA χ,11 (μ)+MA χ,21 (μ))<0; 2) Perform a linear transformation on the augmented system: For C ξ Perform singular value decomposition to obtain C. ξ =S C V C D C Among them, V C =[X C [,0],X C S is a diagonal matrix. C and D C For a unitary matrix, there exists Make I represents the identity matrix, where: And T C B ξ =[B1,B2] T In the formula, T C To achieve C ξ The transformation matrices for block diagonalization, B1 and B2, are the input matrices of the augmented system. ξ The block submatrix after linear transformation; Based on condition 1, we obtain rank(C) ξ B ξ ) = rank(B ξ )=l+h s And C ξ B ξ =B2, therefore B2 is full column rank, and there exists a transformation matrix. Make In the formula V B =[B χ,2 ,0] T , It is a unitary matrix, and B χ,2 It is in full order; Then there is the input transformation matrix: Let the transformation matrix T BC =T B T C The system parameters after linear transformation are: In the formula, A 11 (μ), A 11 (μ), A 11 (μ), A 11 (μ) is the transformed matrix T BC The state submatrix after linear transformation It is through the transformation matrix B ξ The control input submatrix after linear transformation It is through the transformation matrix C ξ The control input submatrix after linear transformation; Based on the above transformation, the state transformation matrix is ​​obtained: and L is (n+h) s -m)×(mlh s A 1 / 2 dimensional matrix; then there exists a matrix T. χ =T A T BC The system parameters after linear transformation are: 3) The result of linear transformation of the augmented system is: y ξ (t)=χ2(t); where, A χ,11 (μ) is the Herwitz matrix; the system state at time t after the linear transformation is χ(t), χ(t) = [χ1(t), χ2(t)] T =T χ ξ(t); χ1(t) is n+h s -m-dimensional vector χ1(t) is the derivative of χ1(t) with respect to time, and χ2(t) is an m-dimensional vector. It is the derivative of χ²(t) with respect to time, matrix A χ,11 (μ) is (n×h) s -m)×(n×h s -m) dimensional vector, A χ,12 (μ) is (n×h) s -m)×m dimensional vector, A χ,21 (μ) is m×(n×h) s -m) dimensional vector, A χ,22 (μ) is an m×m dimensional vector, B χ,2 For m×(l+h) s )-dimensional vector; T χ A is a linear transformation matrix; χ C is the system state matrix after linear transformation; χ This is the output matrix after linear transformation; 4) Based on the impact of false data injection attacks on sensor measurements, the antecedent variables of the nonlinear cyber-physical system description performed by the TS fuzzy model are divided into the following four cases: a) The antecedent variables do not contain any system state variables, meaning that the antecedent variables are independent of the system state and can be directly used; b) The antecedent variables are constructed directly or indirectly from the system state variables and the state measurements come from reliable sensors. That is, the antecedent variables depend on the measurable and reliable system state and can be directly utilized. c) The antecedent variable contains the system state and the state measurement of the variable comes from an untrusted sensor. That is, the antecedent variable depends on the measurable but questionable system state, which may be affected by sensor attacks and therefore cannot be used directly. d) The antecedent variable is a system state that cannot be directly or indirectly measured, that is, the construction of the antecedent variable depends on the unmeasurable system state and cannot be utilized; 5) To improve the non-fragility of the observer, a class of fuzzy cooperative interaction observers is constructed and antecedent variables are utilized. The structure of the observer is as follows: in It is a reliable antecedent variable obtained through the sensor output y1(t) protected by an encrypted communication network. Let represent the fuzzy set of reliable antecedent variables obtained at time t based on the sensor output protected by the encrypted communication network, where p represents the number of reliable antecedent variables obtained from the sensor output protected by the encrypted communication network, and 1 ≤ p ≤ 0. The preceding variable is an untrusted or unmeasurable variable obtained through the output y2(t) of an unprotected sensor and cannot be used. This is an estimate of f(t); In the formula, For n+h s -m-dimensional vector, is an estimate of χ1; yes The derivative with respect to time; It is an m-dimensional vector, representing an estimate of χ²; yes The derivative with respect to time; Let y be an m-dimensional vector. ξ The estimate; in addition, For l+h s A dimensional vector is an estimate of the attack signal f; a matrix Let be an m×m dimensional matrix, representing the observer gain. The matrix is ​​m×m dimensional and represents the parameter drift of the observer gain during implementation. New antecedent variables constructed for the observer; in, The formula is as follows: In the formula, and Both are l+h s The dimensional vector is the constructed virtual auxiliary system. yes The derivative with respect to time; ρ>0 is a constant; for Initial value; and All are (l+h) s )×(l+h s The 1 / 2 dimensional matrix represents the system parameters of the constructed virtual auxiliary system; 6) Uncertainty gain of the observer The following constraints must be met: and Let be given symmetric matrices, and let there exist any positive scalar ε1 such that the given matrix ε1 ε2 ε3 ε4 ε5 ε6 ε7 ε8 ε9 ε1 ε9 ε1 ε2 ε1 ε2 ε3 ...4 ε5 ε6 ε7 ε8 and Under the condition t > 0, the following is satisfied: After that, The error system is as follows: Where e1 is χ1 and its estimate The error between them e1 is the derivative of e1 with respect to time, and e2 is the χ² and its estimate. The error between them It is the derivative of e² with respect to t, and and The formula for the deviation term of the error system is as follows: Let the error deviation vector Considering the error system, through integration and differentiation, we prove that the following equations are equivalent: Among them, y ξ (0) is y ξ The initial value of (t), for Initial value; This shows that the uncertainty of the observer gain during the construction process affects the observer performance, and the virtual auxiliary system... It includes error information about attack reconstruction, through the introduction of two virtual auxiliary systems. and The coordinated interaction with error e2 can utilize the reconstructed error information to improve the observation accuracy of the attack signal; 7) When the linearly transformed system, observer, and attack model satisfy the relevant settings, for a given dimension matrix... and β>0 and The transpose of is equal to itself, in the case of a matrix. in The transpose of is equal to itself, and the positive scalar ε1, η1,η2,η3,η4η5,η6, and In the case of , the following linear matrix inequality is satisfied: in, Therefore, for the case where Ω = 0, the observer's estimation error converges to the set compact set near 0, and for the case where ρ > 0 and is sufficiently large, For the case where Ω ≠ 0, the observer estimation error system has a suppression performance of order γ against Ω; where γ = λ max (γ e ) / λ min (η e ), And for matrices but For matrix but 5. The network attack detection method based on a non-vulnerable fuzzy cooperative interactive observer according to claim 4, characterized in that: The method for obtaining the attack detection scheme based on the cooperative interaction structure observer in step four is as follows: The attack signal f(t) is set to be a signal. The refactored attack detection scheme based on the collaborative interaction structure observer is as follows: (The rest of the text appears to be a fragmented and nonsensical string of characters and symbols. A more accurate translation would require the original, coherent text.) Formula and Uncertainty Gain The observer under the constraint conditions generates the detector signal. The detection logic is as follows: The detector signal is If the detector does not trigger an alarm, the system is considered to be in normal operating condition. If the detector detects fluctuations in the actuator channel output from the observer but no fluctuations in the sensor channel output from the observer, then the attack only occurred in the actuator channel, and the detector can reproduce the attack signal. If the detector detects fluctuations in the sensor channel output from the observer but no fluctuations in the actuator channel output from the observer, then the attack only occurred in the sensor channel, and the detector can reproduce the attack signal. If the detector detects fluctuations in both the actuator and sensor channels of the observer output, then the attack occurred in both the actuator and sensor channels, and the detector can reproduce the attack signal.