Service-oriented unmanned equipment intelligent behavior conceptual model construction method

By combining multispectral data acquisition and deep learning models, the system monitors video stream transmission information in real time, extracts potential attack features, and makes intelligent predictions. This solves the problem of identifying video data attacks by unmanned equipment in battlefield environments, achieving efficient and accurate target identification and attack prediction, and enhancing the autonomous reconnaissance and response capabilities of unmanned equipment.

CN120953891AActive Publication Date: 2025-11-14JOINT WARFARE COLLEGE NAT DEFENSE UNIV OF THE CHINESE PEOPLES LIBERATION ARMY
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511212828.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-28
Publication Date
2025-11-14
Estimated Expiration
2045-08-28

AI Technical Summary

Technical Problem

Existing technologies struggle to intelligently predict and identify enemy attacks that tamper with or falsify video data in real-time video streams, leading to errors and misfires in battlefield situation assessment by unmanned equipment, which affects the accuracy and security of tactical deployments.

Method used

By employing multispectral data acquisition technology, combined with edge computing and deep learning models, the system monitors video stream transmission information in real time, extracts potential attack features, and uses feature vectors to input into a pre-trained model for intelligent prediction. The system dynamically adjusts detection strategies to enhance the detection capability against transient and covert attacks.

Benefits of technology

It improves the target recognition accuracy and tactical execution accuracy of unmanned equipment in complex environments, reduces the risk of misjudgment and missed detection, optimizes the utilization efficiency of combat resources, and ensures the timeliness and reliability of tactical execution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120953891A_ABST
    Figure CN120953891A_ABST
Patent Text Reader

Abstract

The invention discloses a service-oriented unmanned equipment intelligent behavior conceptual model construction method, and relates to the technical field of military, and the method comprises the following steps: carrying optical, infrared and multispectral camera equipment when unmanned equipment executes reconnaissance and attack tasks, continuously collecting battlefield real-time videos, and carrying out multi-spectral data collection to obtain an intelligent behavior conceptual model of the unmanned equipment; and high-efficiency target identification and tracking capability can be maintained in various complex battlefield environments. The target identification precision is improved through multispectral data acquisition, the video stream is monitored in real time to extract the potential attack features, the attack hidden danger is efficiently identified by means of a deep learning model, the detection strategy is adaptively adjusted in a high-risk environment, the response capability to the hidden attack is enhanced, the tactical execution precision and instantaneity are ensured, and the method is suitable for popularization and application. Therefore, the identification efficiency is optimized, the misjudgment and leak detection risks are reduced, the utilization rate of combat resources is improved, and an efficient, accurate and self-adaptive solution is provided for intelligent application of unmanned equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of military technology, specifically to a method for constructing a service-oriented intelligent behavior conceptual model for unmanned equipment. Background Technology

[0002] The concept model for intelligent behavior of service-oriented unmanned equipment refers to the design and construction of an intelligent behavior system for unmanned equipment based on the Service-Oriented Architecture (SOA) principle in the military field, designed to meet diverse operational needs. This model abstracts the various functions of unmanned equipment (such as reconnaissance, attack, communication, navigation, and obstacle avoidance) into independent, reusable service units, which are then flexibly combined and coordinated through standardized interfaces to achieve intelligent mission execution. Its core objective is to enhance the adaptability, decision-making autonomy, and collaborative combat effectiveness of unmanned equipment in complex battlefield environments. By introducing technologies such as artificial intelligence, machine learning, and data fusion, this model can dynamically adjust strategies, optimize resource allocation, and ensure interoperability between different platforms during mission execution, providing more efficient and precise support for command and control.

[0003] In the military field, target detection via real-time video streams refers to the use of optical, infrared, or multispectral cameras mounted on unmanned equipment to continuously collect real-time battlefield video during reconnaissance and strike missions. This video is then used as an input data source for intelligent target identification and tracking. Through embedded deep learning algorithms (such as YOLO, SSD, and Faster R-CNN), unmanned equipment can detect and identify key targets such as enemy personnel, vehicles, and weapons in real time within the video stream, while simultaneously extracting target location information, movement trajectories, and threat levels. This process relies on edge computing capabilities to ensure rapid response in a low-latency environment, while data links transmit the detection results to command centers or other combat units to achieve multi-platform collaborative operations and precision strikes.

[0004] The existing technology has the following shortcomings: When performing target detection via real-time video streams, the streams are vulnerable to transient and covert attacks, which current technologies often struggle to intelligently predict and identify. Enemy forces could exploit this vulnerability to tamper with or falsify video data, interfering with unmanned equipment's accurate assessment of the battlefield situation. For example, the enemy could disguise their own targets as friendly forces or environmental background, causing serious deviations in the tactical execution of unmanned equipment. Such attacks could lead to misidentification of threat targets, wasting operational resources and missing crucial strike opportunities. Furthermore, misjudgments could result in friendly fire or critical infrastructure strikes, causing significant losses, directly impacting the accuracy of battlefield command, leading to errors in overall tactical deployment, and potentially altering the course of the battle, causing severe strategic disadvantages.

[0005] The information disclosed in the background section is only intended to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0006] The purpose of this invention is to provide a service-oriented method for constructing a conceptual model of intelligent behavior for unmanned equipment. Utilizing multispectral data acquisition technology, it enhances target recognition accuracy under different environmental conditions and accurately extracts potential attack features by monitoring video stream transmission information in real time, providing a solid data foundation for subsequent intelligent attack prediction. By inputting the extracted features into a deep learning model, it achieves efficient identification of potential attack threats, enabling the system to adaptively adjust detection strategies in high-risk environments. This enhances the detection capability against transient and covert attacks, ensuring the accuracy and timeliness of tactical execution. It not only optimizes the target recognition efficiency of unmanned equipment and effectively reduces the risk of misjudgment and missed detection due to inference delays, but also ultimately improves the utilization efficiency of combat resources and the reliability of mission execution. This provides an efficient, accurate, and adaptive solution for the intelligent application of unmanned equipment in modern warfare, addressing the problems mentioned in the background technology.

[0007] To achieve the above objectives, the present invention provides the following technical solution: a method for constructing a service-oriented intelligent behavior conceptual model for unmanned equipment, comprising the following steps: When performing reconnaissance and strike missions, unmanned equipment is equipped with optical, infrared and multispectral cameras to continuously collect real-time battlefield video. Through multispectral data acquisition, it maintains efficient target identification and tracking capabilities in various complex battlefield environments, reducing identification errors caused by a single spectral data source. The acquired real-time video stream is transmitted to the edge computing unit via a communication link. During the transmission process, the transmission information of the video stream is acquired in real time for subsequent attack feature extraction and analysis. Within the monitoring window, feature extraction is performed on the acquired transmission data. By extracting transmission attack features, potential attack behaviors in the video stream transmission process are initially identified, providing a key basis for subsequent attack prediction and response. The extracted transmission attack features are used as feature vectors and input into a pre-trained deep learning model for analysis. This enables intelligent prediction of potential attack risks during video stream transmission and early identification of potential attack risks. When a deep learning model identifies a potential attack risk in video stream transmission, it intelligently shortens the target identification and processing interval based on the level of attack risk, enhancing the detection capability for short-lived and covert attacks and ensuring that unmanned equipment can identify and respond to potential threats in a timely manner. While increasing the detection frequency, the algorithm can also increase the number of inferences in a short period of time to ensure that target recognition can be completed quickly and accurately in each detection cycle under high-frequency detection, so as to detect and respond to potential threats in a timely manner and reduce the risk of misjudgment and missed detection caused by inference delay.

[0008] Preferably, wireless communication, satellite communication, wired network, and hybrid transmission technologies are used to transmit the acquired real-time video stream to the edge computing unit.

[0009] Preferably, within the monitoring window, feature extraction is performed on the acquired transmission data. The specific process is as follows: The frequency of changes in the transmission path of the monitored video stream and the distribution of data packet sizes in the video stream are extracted from the acquired transmission data. Within the monitoring window, feature engineering is performed on the extracted frequency of changes in the transmission path of the monitored video stream and the distribution of data packet sizes in the video stream to generate quantified values ​​of transmission path change frequency and abnormal data packet size distribution. The quantified values ​​of transmission path change frequency and abnormal data packet size distribution are used to initially identify potential attack behaviors in the video stream transmission process, providing key basis for subsequent attack prediction and response.

[0010] Preferably, the extracted transmission path change frequency quantization value and data packet size distribution anomaly quantization value are used as feature vectors and input into a pre-trained deep learning model for analysis. The deep learning model generates potential intrusion assessment coefficients, and based on the potential intrusion assessment coefficients, it intelligently predicts potential attack risks during video stream transmission and identifies potential attack risks in advance.

[0011] Preferably, within the monitoring window, the specific steps for generating a quantified value of the transmission path change frequency after performing feature engineering on the extracted frequency of changes in the transmission path of the monitoring video stream are as follows: Within the monitoring window, changes in the video stream transmission path are sampled, features related to path changes are extracted, and the quantization value of the transmission path change frequency is calculated. First, the following parameters are defined: Indicates the first i The video stream transmission path number at the time of the next sample. i An index representing the video stream transmission path number; N This indicates the total number of samples taken within the monitoring window; The path change between two adjacent samples is defined as follows: Where 1 indicates that the path has changed, when When 0 indicates that the transmission path of the video stream has switched or been adjusted between two consecutive samples; 0 indicates that the path has not changed. This indicates that the transmission path of the video stream remains consistent between two consecutive samples, the transmission link is stable, and no switching has occurred; The cumulative magnitude of path changes within the monitoring window is calculated as follows:

[0012] in, and It is a hash function that maps path identifiers to a high-dimensional feature space to enhance the nonlinear effects of scheduling changes; After extracting the path change factor, the quantized value of the transmission path change frequency is calculated as a key indicator for preliminary identification of attack behavior. The calculation expression is as follows:

[0013] in: To change the frequency quantization value for the transmission path, The path change sensitivity coefficient is used to adjust the response sensitivity of the quantization value of the transmission path change frequency. This is a non-linear adjustment coefficient used to balance the response amplitude of the frequency quantization value when the transmission path changes. The time weighting for path changes reflects the impact of transmission link switching delay. To prevent smoothing factors with a denominator of zero.

[0014] Preferably, the specific steps for generating a quantification value of packet size distribution anomalies after feature engineering the distribution of packet sizes in the extracted video stream within the monitoring window are as follows: The size distribution deviation features of each data packet during transmission are extracted. A deviation function is constructed using the cumulative distribution characteristics of data packet sizes. Through nonlinear mapping and cumulative transformation, the deviation features of the data packet size distribution are obtained. The data packet size sequence in the video stream is defined as follows: ,in Indicates the first p The size of each data packet m To determine the total number of data packets, construct a cumulative deviation function. The specific expression for the cumulative deviation function is as follows:

[0015] in: This is the cumulative deviation function, representing the cumulative deviation value from the first data packet to the current data packet. Indicates the first k The size of each data packet k This represents a loop variable indicating the number of the currently processed data packet. During the cumulative summation process, it is used to iterate through all received data packets. This is the deviation sensitivity factor, which controls the intensity of the deviation response to large data packets. This represents the maximum size of the data packet, used for normalization. By utilizing the cumulative deviation function and nonlinear mapping, a weighted cumulative model is used to reflect the overall anomaly of packet distribution. The quantification value of packet size distribution anomaly is defined as:

[0016] in: This is a quantification value for packet size distribution anomalies, representing the overall degree of deviation in the packet size distribution. This is a nonlinear mapping function that nonlinearly amplifies the cumulative deviation function to highlight the contribution of abnormal data packets. The dynamic weighting function assigns anomaly weights to different data packets, depending on the median size. The relative differences are calculated, and the expression for the dynamic weighting function is as follows:

[0017] This is a weighted sensitivity factor that controls the intensity of the response to relative differences.

[0018] Preferably, the potential intrusion assessment coefficient generated when intelligently predicting potential attack risks in video stream transmission using a pre-trained deep learning model within the monitoring window is compared and analyzed with a pre-set reference threshold to identify potential attack risks during video stream transmission. The specific process is as follows: If the potential intrusion assessment coefficient is greater than the reference threshold, a risk signal is generated, indicating that there is a potential attack risk during video stream transmission. If the potential intrusion assessment coefficient is less than or equal to the reference threshold, a normal signal is generated, indicating that the video stream is being transmitted efficiently.

[0019] Preferably, when the deep learning model identifies a potential attack risk in the video stream transmission, i.e., when the video stream transmission generates a risk signal, the interval time for target recognition processing is intelligently shortened according to the degree of attack risk, while increasing the number of inferences of the target recognition algorithm in a short period of time. The specific steps are as follows: When a deep learning model identifies a potential attack vulnerability in a video stream, it intelligently adjusts the target recognition processing interval based on the potential intrusion assessment coefficient and a preset reference threshold. To enhance the detection capability against brief and covert attacks, the nonlinear mapping relationship between the processing interval and the potential intrusion assessment coefficient is dynamically adjusted to ensure that the detection interval is shortened and the recognition frequency is increased under high-risk conditions. The expression for dynamic adjustment is:

[0020] in, This is the adjusted target recognition processing interval. The initial target identification processing interval represents the detection cycle under normal circumstances. The potential intrusion assessment coefficient, generated by a deep learning model, reflects the current level of intrusion risk. The reference threshold is set. When the potential intrusion assessment coefficient exceeds the reference threshold, the identification interval will be shortened. To adjust the sensitivity coefficient, the extent to which the interval time is shortened is determined. As a smoothing factor, it controls the stability of the adjustment process and avoids instability caused by sudden changes; While shortening the target recognition processing interval, the number of inferences within a short period is dynamically increased to ensure efficient target recognition capabilities at higher detection frequencies. The number of inferences is exponentially amplified based on the potential intrusion assessment coefficient and a preset reference threshold to adapt to detection needs at different risk levels. The specific dynamic adjustment expression is as follows:

[0021] in, The adjusted number of inference steps for target recognition. The number of inferences for initial target identification represents the number of inferences executed under normal circumstances. The adjustment factor for the number of inferences determines the degree of inference amplification when the attack risk increases. It is a non-linear exponential factor that determines the rate of increase in the number of inferences to deal with different levels of threats; To support higher-frequency target detection and inference, and to ensure a balance between task real-time performance and energy consumption, the resource allocation strategy is dynamically adjusted based on the potential intrusion assessment coefficient and system resource availability. Priority is given to allocating more computing resources to inference tasks, while energy consumption strategies are optimized to prevent over-computation from degrading device performance. The expression for adjusting the resource allocation strategy is as follows:

[0022] in, The computing resources allocated for target identification, To maximize the allocable computing resources, This represents the proportion of currently available computing resources, which is dynamically adjusted according to changes in load. This is a sensitivity coefficient for resource allocation, used to control the magnitude of resource adjustments.

[0023] The technical effects and advantages provided by the present invention in the above technical solution are as follows: This invention utilizes multispectral data acquisition technology to enhance target recognition accuracy under different environmental conditions. By monitoring video stream transmission information in real time, it accurately extracts potential attack features, providing a solid data foundation for subsequent intelligent attack prediction. By inputting the extracted features into a deep learning model, it achieves efficient identification of potential attack threats, enabling the system to adaptively adjust detection strategies in high-risk environments. This enhances the detection capability against transient and covert attacks, ensuring the accuracy and timeliness of tactical execution. It not only optimizes the target recognition efficiency of unmanned equipment and effectively reduces the risk of misjudgment and missed detection due to inference delays, but also ultimately improves the utilization efficiency of combat resources and the reliability of mission execution, providing an efficient, accurate, and adaptive solution for the intelligent application of unmanned equipment in modern warfare. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0025] Figure 1 This is a schematic diagram of the modules of a service-oriented intelligent behavior conceptual model construction method for unmanned equipment according to the present invention. Detailed Implementation

[0026] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, they are provided so that the description of this disclosure will be more complete and fully convey the concept of the exemplary embodiments to those skilled in the art.

[0027] This invention provides, for example Figure 1 The method for constructing a service-oriented intelligent behavior conceptual model for unmanned equipment, as shown, includes the following steps: When performing reconnaissance and strike missions, unmanned equipment is equipped with optical, infrared and multispectral cameras to continuously collect real-time battlefield video. Through multispectral data acquisition, it maintains efficient target identification and tracking capabilities in various complex battlefield environments, reduces identification errors caused by single spectral data sources, and improves the reliability and accuracy of overall reconnaissance. These multispectral cameras can operate under various lighting and environmental conditions, providing a wealth of environmental information. For example, optical cameras are suitable for high-resolution image acquisition during the day and in good lighting conditions, infrared cameras can capture heat source information at night or in low light conditions, and multispectral cameras combine multiple spectral data to enhance the accuracy of target recognition.

[0028] The acquired real-time video stream is transmitted to the edge computing unit via a communication link. During the transmission process, the transmission information of the video stream is acquired in real time for subsequent attack feature extraction and analysis. Real-time monitoring of data transmission information during video stream transmission can promptly detect any anomalies that may occur during transmission, providing fundamental data support for subsequent attack detection and defense measures, and ensuring the integrity and reliability of the video stream.

[0029] Transmitting the acquired real-time video stream to the edge computing unit can be achieved through various methods, primarily including wireless communication, satellite communication, wired networks, and hybrid transmission technologies. For wireless communication, common methods include 5G, Wi-Fi 6, millimeter-wave communication (mmWave), and MANET (Multi-Aggregate Network). 5G networks offer advantages such as low latency and high bandwidth, making them suitable for high-speed data transmission in battlefield environments, while MANET can build flexible tactical communication networks in dynamic environments. Satellite communication (such as Ka-band and L-band) is suitable for long-range reconnaissance and complex environments, enabling global real-time video transmission with strong anti-jamming capabilities. For wired networks, fiber optics or Ethernet can be deployed at fixed tactical base stations or forward command centers to ensure high reliability and high-capacity transmission. Hybrid transmission technologies combine wireless and wired methods; for example, using wireless communication as the primary link and switching to satellite or fiber optic links when the signal is interfered with or lost, ensuring the continuity and stability of the data stream. The selection of a specific transmission method needs to be optimized based on factors such as the combat environment, bandwidth requirements, anti-interference capabilities, and equipment power consumption, in order to ensure that the video stream is transmitted efficiently, stably, and securely to the edge computing unit, enabling real-time analysis and decision support of the battlefield situation.

[0030] Within the monitoring window, feature extraction is performed on the acquired transmission data. By extracting transmission attack features, potential attack behaviors in the video stream transmission process are initially identified, providing a key basis for subsequent attack prediction and response. Within the monitoring window, feature extraction is performed on the acquired transmission data. The specific process is as follows: The frequency of changes in the transmission path of the monitored video stream and the distribution of data packet sizes in the video stream are extracted from the acquired transmission data. Within the monitoring window, feature engineering is performed on the extracted frequency of changes in the transmission path of the monitored video stream and the distribution of data packet sizes in the video stream to generate quantified values ​​of transmission path change frequency and abnormal data packet size distribution. The quantified values ​​of transmission path change frequency and abnormal data packet size distribution are used to initially identify potential attack behaviors in the video stream transmission process, providing key basis for subsequent attack prediction and response.

[0031] When performing target detection using real-time video streams, a high frequency of changes in the video stream's transmission path usually indicates a potential attack during transmission. Normally, the video stream's transmission path should remain relatively stable, with network routers selecting the optimal path to ensure stable transmission with low latency and high bandwidth. However, frequent path changes may be caused by adversaries implementing route hijacking attacks, traffic redirection attacks, man-in-the-middle (MITM) attacks, or interference spoofing. For example, attackers may use methods such as tampering with routing tables, DNS spoofing, or hijacking Border Gateway Protocol (BGP) to redirect video data to malicious nodes, resulting in data interception, tampering, or delay. Furthermore, adversaries may use interference techniques to force the video stream to constantly switch paths, increasing transmission uncertainty and affecting the accuracy of battlefield situational awareness.

[0032] Within the monitoring window, the specific steps for generating a quantified value of the transmission path change frequency after performing feature engineering on the extracted frequency of changes in the transmission path of the monitoring video stream are as follows: Within the monitoring window, changes in the video stream transmission path are sampled, features related to path changes are extracted, and the quantization value of the transmission path change frequency is calculated. First, the following parameters are defined: Indicates the first i The video stream transmission path number at the time of the next sample. i An index representing the video stream transmission path number; N This indicates the total number of samples taken within the monitoring window; The path change between two adjacent samples is defined as follows: ,in, , A value of 0 indicates that the video stream's transmission path has switched or been adjusted between two consecutive samples (e.g., the router has chosen a different transmission path). This path change could be a normal behavior of dynamic network adjustments, or it could be the result of a potential attack (such as route hijacking or traffic redirection); 0 indicates that the path has not changed. This indicates that the transmission path of the video stream remains consistent between two consecutive samples, the transmission link is stable, and no switching has occurred; The cumulative magnitude of path changes within the monitoring window is calculated as follows:

[0033] in, and It is a hash function that maps path identifiers to a high-dimensional feature space to enhance the nonlinear effects of scheduling changes; The purpose of this step is to extract variation patterns from the original transmission path sequence and introduce non-linear characteristics of the path using a hash function, thereby enhancing the model's sensitivity to potential attacks. (Cumulative magnitude of path changes) It reflects both the frequency and magnitude of changes, providing richer information on dynamic changes.

[0034] After extracting the path change factor, the quantized value of the transmission path change frequency is calculated as a key indicator for preliminary identification of attack behavior. The calculation expression is as follows:

[0035] in: To change the frequency quantization value for the transmission path, The path change sensitivity coefficient is used to adjust the response sensitivity of the quantization value of the transmission path change frequency. This is a non-linear adjustment coefficient used to balance the response amplitude of the frequency quantization value when the transmission path changes. The time weighting for path changes reflects the impact of transmission link switching delay. To prevent the smoothing factor from being zero in the denominator, it is usually taken as a very small positive number; The purpose of this step is to provide a sensitive detection capability for potential attacks by constructing a quantized value of transmission path change frequency, taking into account the frequency of path changes, and combining weights and nonlinear adjustment factors.

[0036] As can be seen from the transmission path change frequency quantification value, within the monitoring window, a higher value indicates a higher risk of potential attacks during video stream transmission, after feature engineering of the extracted transmission path change frequency. Conversely, a lower value indicates a lower risk. Within the monitoring window, the system performs feature engineering on the transmission path change frequency of the video stream, extracts key features, and calculates the transmission path change frequency quantification value. This value quantifies the frequency of path switching and the complexity of its characteristics. Typically, in a stable network environment, the video stream's transmission path should remain relatively fixed with a low change frequency, resulting in a low transmission path change frequency quantification value. However, when attackers attempt traffic redirection, route hijacking, denial-of-service (DoS) attacks, or malicious interference, it can lead to abnormal path switching and irregular frequency changes, causing the transmission path change frequency quantification value to rise. Therefore, a higher transmission path change frequency quantification value usually indicates that the video stream is facing potential threats, such as link spoofing, malicious traffic injection, or dynamic redirection, while a lower value indicates that the video stream is in a relatively stable transmission environment.

[0037] When performing target detection via real-time video streams, significant variations in packet size distribution, especially the presence of abnormally large packets, may indicate potential attacks during transmission. Normally, video stream packet sizes follow a distribution pattern, exhibiting relatively stable fluctuations influenced by factors such as encoding format, resolution, frame rate, and network bandwidth. However, substantial deviations in packet size during transmission, such as unusually large or small packets, could indicate packet insertion attacks, bandwidth exhaustion attacks, traffic obfuscation attacks, or covert channel attacks. Attackers might intentionally send excessively large packets to cause buffer overflows at the receiving end, or insert excessively small packets to increase network overhead, interfering with normal video stream transmission, or even embed malicious code within packets for further attacks. Therefore, monitoring abnormal changes in packet size distribution can effectively identify and respond to potential attack threats, ensuring the integrity and security of the video stream.

[0038] Within the monitoring window, the specific steps for generating quantification values ​​of packet size distribution anomalies after feature engineering of the packet size distribution in the extracted video stream are as follows: The size distribution deviation features of each data packet during transmission are extracted. A deviation function is constructed using the cumulative distribution characteristics of data packet sizes. Through nonlinear mapping and cumulative transformation, the deviation features of the data packet size distribution are obtained. The data packet size sequence in the video stream is defined as follows: ,in Indicates the first p The size of each data packet m To determine the total number of data packets, construct a cumulative deviation function. The specific expression for the cumulative deviation function is as follows:

[0039] in: This is the cumulative deviation function, representing the cumulative deviation value from the first data packet to the current data packet. Indicates the first k The size of each data packet k This represents a loop variable indicating the number of the currently processed data packet. During the cumulative summation process, it is used to iterate through all received data packets. This is the deviation sensitivity factor, which controls the strength of the deviation response to larger data packets. This represents the maximum size of the data packet, used for normalization. By using the cumulative deviation function, the gradual trend of packet size changes is captured, enhancing the sensitivity to abnormal packet sizes.

[0040] By utilizing the cumulative deviation function and nonlinear mapping, a weighted cumulative model is used to reflect the overall anomaly of packet distribution. The quantification value of packet size distribution anomaly is defined as:

[0041] in: This is a quantification value for packet size distribution anomalies, representing the overall degree of deviation in the packet size distribution. This is a nonlinear mapping function that nonlinearly amplifies the cumulative deviation function to highlight the contribution of abnormal data packets. The dynamic weighting function assigns anomaly weights to different data packets, depending on the median size. The relative differences are calculated, and the expression for the dynamic weighting function is as follows:

[0042] This is the weighted sensitivity factor, which controls the intensity of the response to relative differences; By weighted and cumulatively integrating the anomalies of all data packets, a quantitative assessment of the overall distribution deviation is formed, using dynamic weights. It amplifies the importance of data packets that deviate significantly from the median, better reflecting potential attack behaviors caused by distribution anomalies.

[0043] The packet size distribution anomaly quantification value reveals that, within the monitoring window, a larger value, generated after feature engineering of the packet size distribution in the extracted video stream, indicates a higher risk of potential attacks during video stream transmission; conversely, a smaller value indicates a lower risk. This packet size distribution anomaly quantification value quantifies the degree of anomaly and distribution deviation of packet sizes by performing feature engineering on the packet size distribution of the real-time video stream extracted within the monitoring window. A large packet size distribution anomaly quantification value indicates significant anomalies in packet size distribution, such as sudden bursts of extremely large or small packets, skewed distribution, or abnormal fluctuations. This may be caused by malicious traffic injection, bandwidth exhaustion attacks, covert channel attacks, or data tampering. Conversely, a small packet size distribution anomaly quantification value indicates a relatively stable packet size distribution, consistent with normal transmission characteristics, and no obvious signs of attack detected. Therefore, the packet size distribution anomaly quantification value can serve as an important indicator for real-time monitoring of video stream security, providing a valid basis for attack prediction and response, and ensuring the stability and integrity of video stream transmission.

[0044] The extracted transmission attack features are used as feature vectors and input into a pre-trained deep learning model for analysis. This enables intelligent prediction of potential attack risks during video stream transmission and early identification of potential attack risks. The extracted transmission path change frequency quantization value and data packet size distribution anomaly quantization value are used as feature vectors and input into a pre-trained deep learning model for analysis. The deep learning model generates potential intrusion assessment coefficients, and based on these coefficients, it intelligently predicts potential attack risks during video stream transmission, thus identifying potential attack risks in advance.

[0045] A pre-trained deep learning model refers to a neural network model that has been thoroughly trained and optimized on a large historical dataset before the actual video streaming task is executed. After training, this model possesses the ability to identify potential attack vulnerabilities during video streaming. It can intelligently analyze the current transmission status based on input feature vectors (such as quantized values ​​of transmission path change frequency and abnormal packet size distribution) and output a potential intrusion assessment coefficient to evaluate the intrusion risk. During the training process, a large amount of labeled data is typically used, including instances of normal transmission behavior and various known attack behaviors. Deep learning algorithms automatically extract data features and establish a mapping relationship from input features to attack risk probabilities. The training process usually includes data preprocessing, feature engineering, model training, hyperparameter optimization, and cross-validation to ensure that the model has high generalization ability and real-time prediction capability when dealing with complex and changing network environments. Using a pre-trained model helps reduce computational overhead during actual task execution while ensuring that the system can respond quickly to potential threats.

[0046] In practical deployments, pre-trained deep learning models are typically trained using supervised or semi-supervised learning strategies, leveraging known attack patterns and normal transmission patterns for classification or regression analysis. For example, convolutional neural networks (CNNs) are used to extract spatial patterns of packet distribution features, or long short-term memory networks (LSTMs) are used to analyze the temporal series features of transmission path change frequency. During training, the model learns unique patterns in data distribution for different attack types, such as distribution bias caused by malicious packet insertion and frequent path switching due to path hijacking. Once the model is trained and achieves high accuracy and robustness on the test set, it can be deployed to edge computing units of unmanned equipment or command centers for efficient inference on real-time data. When the system receives input feature vectors, the deep learning model comprehensively analyzes the complex relationships between features and generates a potential intrusion assessment coefficient, providing an intelligent assessment of whether the current video stream is under attack, helping command personnel or automated systems make rapid response decisions. By using pre-trained models, risk assessments can be provided quickly and accurately in the face of unknown or complex attacks, and the impact of attacks can be effectively reduced by adjusting target recognition and processing strategies, ensuring the integrity and security of the video stream.

[0047] Without specifying particular limitations, the deep learning model here is capable of quantizing the frequency of transmission path changes. and data packet size distribution anomaly quantization value A comprehensive analysis is conducted to generate potential intrusion assessment coefficients. Any deep learning model is acceptable. To achieve the technical solution of this invention, this invention provides a specific implementation method; potential intrusion evaluation coefficient. The generated expression is:

[0048] In the formula, , These are the frequency quantization values ​​for transmission path changes. and data packet size distribution anomaly quantization value The preset proportional coefficient, and , All are greater than 0.

[0049] In this formula, a preset proportionality coefficient is used. and Used to balance and adjust different features in the potential intrusion assessment coefficient Influence weights in the calculation. Since the quantization values ​​of transmission path change frequency and packet size distribution anomalies may have different physical meanings and numerical ranges, directly combining them in the calculation may lead to one feature dominating the result while weakening the contribution of another. The introduction of preset scaling factors helps to reasonably allocate the influence of each feature in the formula, maintaining a reasonable balance when assessing potential attack risks. Furthermore, preset scaling factors can be set based on historical data experience or expert knowledge to ensure adaptability to various network environments in different application scenarios, improving the system's sensitivity and robustness to potential intrusions. Values ​​greater than zero indicate that all features contribute positively to the final result; simultaneously, the introduction of squared terms reduces sensitivity to extreme values ​​and enhances the stability of the evaluation results.

[0050] As can be seen from the potential intrusion assessment coefficient, within the monitoring window, the larger the performance value of the transmission path change frequency quantification value generated after feature engineering of the frequency of changes in the extracted monitoring video stream transmission path, and the larger the performance value of the data packet size distribution anomaly quantification value generated after feature engineering of the data packet size distribution in the extracted video stream, the larger the performance value of the potential intrusion assessment coefficient generated when the pre-trained deep learning model intelligently predicts the potential attack risks of video stream transmission within the monitoring window, the higher the risk of potential attack behavior in the video stream transmission process, and vice versa.

[0051] The potential intrusion assessment coefficient generated when a pre-trained deep learning model intelligently predicts potential attack risks in video stream transmission within the monitoring window is compared and analyzed with a pre-set reference threshold to identify potential attack risks during video stream transmission. The specific process is as follows: If the potential intrusion assessment coefficient is greater than the reference threshold, a risk signal is generated, indicating that there is a potential attack risk during video stream transmission. If the potential intrusion assessment coefficient is less than or equal to the reference threshold, a normal signal is generated, indicating that the video stream is being transmitted efficiently.

[0052] When a deep learning model identifies a potential attack risk in a video stream, it intelligently shortens the target identification and processing interval based on the level of attack risk, enhancing the ability to detect short-lived and covert attacks, ensuring that unmanned equipment can identify and respond to potential threats in a timely manner, and avoiding missing key intelligence or tactical opportunities due to excessively long detection intervals. While increasing the detection frequency, the number of inferences of the target recognition algorithm in a short period of time is increased to ensure that the target recognition in each detection cycle can be completed quickly and accurately under high-frequency detection, so as to detect and respond to potential threats in a timely manner and reduce the risk of misjudgment and missed detection due to inference delay. When a deep learning model identifies a potential attack vulnerability in a video stream transmission, i.e., when the video stream transmission generates a risk signal, the interval for target identification processing is intelligently shortened based on the degree of attack risk. Simultaneously, the number of inferences performed by the target identification algorithm within a short time is increased. The specific steps are as follows: When a deep learning model identifies a potential attack vulnerability in a video stream, it intelligently adjusts the target recognition processing interval based on the potential intrusion assessment coefficient and a preset reference threshold. To enhance the detection capability against brief and covert attacks, the nonlinear mapping relationship between the processing interval and the potential intrusion assessment coefficient is dynamically adjusted to ensure that the detection interval is shortened and the recognition frequency is increased under high-risk conditions. The expression for dynamic adjustment is:

[0053] in, This is the adjusted target recognition processing interval. The initial target identification processing interval represents the detection cycle under normal circumstances. The potential intrusion assessment coefficient, generated by a deep learning model, reflects the current level of intrusion risk. The preset reference threshold will be used to significantly shorten the identification interval when the potential intrusion assessment coefficient exceeds the reference threshold. To adjust the sensitivity coefficient, the extent to which the interval time is shortened is determined. As a smoothing factor, it controls the stability of the adjustment process and avoids sudden changes that could lead to system instability; This step intelligently adjusts the recognition interval, enabling unmanned equipment to perform target recognition more frequently in high-risk environments, reducing the possibility of missing critical threats due to long detection intervals, and ensuring the system's real-time response capability.

[0054] While shortening the target recognition processing interval, the number of inferences within a short period is dynamically increased to ensure efficient target recognition capabilities at higher detection frequencies. The number of inferences is exponentially amplified based on the potential intrusion assessment coefficient and a preset reference threshold to adapt to detection needs at different risk levels. The specific dynamic adjustment expression is as follows:

[0055] in, The adjusted number of inference steps for target recognition. The number of inferences for initial target identification represents the number of inferences executed under normal circumstances. The adjustment factor for the number of inferences determines the degree of inference amplification when the attack risk increases. It is a non-linear exponential factor that determines the rate of increase in the number of inferences to deal with different levels of threats; This step ensures that the system can complete target identification at a faster inference speed in high-frequency detection mode, reducing the risk of misjudgment and missed detection due to insufficient processing time, and improving the system's responsiveness in battlefield environments.

[0056] To support higher-frequency target detection and inference, computing resources need to be allocated rationally to ensure a balance between task real-time performance and energy consumption. Based on the potential intrusion assessment coefficient and system resource availability, the resource allocation strategy should be dynamically adjusted, prioritizing the allocation of more computing resources to inference tasks while optimizing energy consumption strategies to prevent over-computation from degrading device performance. The expression for adjusting the resource allocation strategy is as follows:

[0057] in, The computing resources (CPU / GPU / memory, etc.) allocated to target recognition. To maximize the allocable computing resources, This represents the proportion of currently available computing resources, which is dynamically adjusted according to changes in load. This is a sensitivity coefficient for resource allocation, used to control the magnitude of resource adjustments.

[0058] The aforementioned service-oriented intelligent behavior conceptual model construction method for unmanned equipment significantly enhances its autonomous reconnaissance, target identification, and attack response capabilities in complex battlefield environments. This scheme utilizes multispectral data acquisition technology to improve target identification accuracy under different environmental conditions and accurately extracts potential attack features by monitoring real-time video stream transmission information, providing a solid data foundation for subsequent intelligent attack prediction. By inputting the extracted features into a deep learning model, efficient identification of potential attack threats is achieved, enabling the system to adaptively adjust detection strategies in high-risk environments. For example, it intelligently shortens the target identification processing interval and increases the number of inferences, thereby enhancing the detection capability against transient and covert attacks and ensuring the accuracy and timeliness of tactical execution. Furthermore, this scheme optimizes the target identification efficiency of unmanned equipment, effectively reducing the risk of misjudgment and missed detection due to inference delays, ultimately improving the utilization efficiency of combat resources and the reliability of mission execution. This provides an efficient, accurate, and adaptive solution for the intelligent application of unmanned equipment in modern warfare environments.

[0059] The above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0060] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0061] The foregoing has only described certain exemplary embodiments of the present invention by way of illustration. Undoubtedly, those skilled in the art can modify the described embodiments in various ways without departing from the spirit and scope of the present invention. Therefore, the foregoing drawings and descriptions are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.

Claims

1. A method for constructing a service-oriented intelligent behavior conceptual model for unmanned equipment, characterized in that, Includes the following steps: When performing reconnaissance and strike missions, unmanned equipment is equipped with optical, infrared and multispectral cameras to continuously collect real-time battlefield video. Through multispectral data acquisition, it maintains efficient target identification and tracking capabilities in various complex battlefield environments, reducing identification errors caused by a single spectral data source. The acquired real-time video stream is transmitted to the edge computing unit via a communication link. During the transmission process, the transmission information of the video stream is acquired in real time for subsequent attack feature extraction and analysis. Within the monitoring window, feature extraction is performed on the acquired transmission data. By extracting transmission attack features, potential attack behaviors in the video stream transmission process are initially identified, providing a key basis for subsequent attack prediction and response. The extracted transmission attack features are used as feature vectors and input into a pre-trained deep learning model for analysis. This enables intelligent prediction of potential attack risks during video stream transmission and early identification of potential attack risks. When a deep learning model identifies a potential attack risk in video stream transmission, it intelligently shortens the target identification and processing interval based on the level of attack risk, enhancing the detection capability for short-lived and covert attacks and ensuring that unmanned equipment can identify and respond to potential threats in a timely manner. While increasing the detection frequency, the algorithm can also increase the number of inferences in a short period of time to ensure that target recognition can be completed quickly and accurately in each detection cycle under high-frequency detection, so as to detect and respond to potential threats in a timely manner and reduce the risk of misjudgment and missed detection caused by inference delay.

2. The method for constructing a service-oriented intelligent behavior conceptual model for unmanned equipment according to claim 1, characterized in that, The acquired real-time video stream is transmitted to the edge computing unit using wireless communication, satellite communication, wired network, and hybrid transmission technologies.

3. The method for constructing a service-oriented intelligent behavior conceptual model for unmanned equipment according to claim 1, characterized in that, Within the monitoring window, feature extraction is performed on the acquired transmission data. The specific process is as follows: The frequency of changes in the transmission path of the monitored video stream and the distribution of data packet sizes in the video stream are extracted from the acquired transmission data. Within the monitoring window, feature engineering is performed on the extracted frequency of changes in the transmission path of the monitored video stream and the distribution of data packet sizes in the video stream to generate quantified values ​​of transmission path change frequency and abnormal data packet size distribution. The quantified values ​​of transmission path change frequency and abnormal data packet size distribution are used to initially identify potential attack behaviors in the video stream transmission process, providing key basis for subsequent attack prediction and response.

4. The method for constructing a service-oriented intelligent behavior conceptual model for unmanned equipment according to claim 3, characterized in that, The extracted transmission path change frequency quantization value and data packet size distribution anomaly quantization value are used as feature vectors and input into a pre-trained deep learning model for analysis. The deep learning model generates potential intrusion assessment coefficients, and based on these coefficients, it intelligently predicts potential attack risks during video stream transmission, thus identifying potential attack risks in advance.

5. The method for constructing a service-oriented intelligent behavior conceptual model for unmanned equipment according to claim 3, characterized in that, Within the monitoring window, the specific steps for generating a quantified value of the transmission path change frequency after performing feature engineering on the extracted frequency of changes in the transmission path of the monitoring video stream are as follows: Within the monitoring window, changes in the video stream transmission path are sampled, features related to path changes are extracted, and the quantization value of the transmission path change frequency is calculated. First, the following parameters are defined: Indicates the first i The video stream transmission path number at the time of the next sample. i An index representing the video stream transmission path number; N This indicates the total number of samples taken within the monitoring window; The path change between two adjacent samples is defined as follows: Where 1 indicates that the path has changed, when When 0 indicates that the transmission path of the video stream has switched or been adjusted between two consecutive samples; 0 indicates that the path has not changed. This indicates that the transmission path of the video stream remains consistent between two consecutive samples, the transmission link is stable, and no switching has occurred; The cumulative magnitude of path changes within the monitoring window is calculated as follows: ,in, and It is a hash function that maps path identifiers to a high-dimensional feature space to enhance the nonlinear effects of scheduling changes; After extracting the path change factor, the quantized value of the transmission path change frequency is calculated as a key indicator for preliminary identification of attack behavior. The calculation expression is as follows: ,in: To change the frequency quantization value for the transmission path, The path change sensitivity coefficient is used to adjust the response sensitivity of the quantization value of the transmission path change frequency. This is a non-linear adjustment coefficient used to balance the response amplitude of the frequency quantization value when the transmission path changes. The time weighting for path changes reflects the impact of transmission link switching delay. To prevent smoothing factors with a denominator of zero.

6. The method for constructing a service-oriented intelligent behavior conceptual model for unmanned equipment according to claim 3, characterized in that, Within the monitoring window, the specific steps for generating quantification values ​​of packet size distribution anomalies after feature engineering of the packet size distribution in the extracted video stream are as follows: The size distribution deviation features of each data packet during transmission are extracted. A deviation function is constructed using the cumulative distribution characteristics of data packet sizes. Through nonlinear mapping and cumulative transformation, the deviation features of the data packet size distribution are obtained. The data packet size sequence in the video stream is defined as follows: ,in Indicates the first p The size of each data packet m To determine the total number of data packets, construct a cumulative deviation function. The specific expression for the cumulative deviation function is as follows: ,in: This is the cumulative deviation function, representing the cumulative deviation value from the first data packet to the current data packet. Indicates the first k The size of each data packet k This represents a loop variable indicating the number of the currently processed data packet. During the cumulative summation process, it is used to iterate through all received data packets. This is the deviation sensitivity factor, which controls the intensity of the deviation response to large data packets. This represents the maximum size of the data packet, used for normalization. By utilizing the cumulative deviation function and nonlinear mapping, a weighted cumulative model is used to reflect the overall anomaly of packet distribution. The quantification value of packet size distribution anomaly is defined as: ,in: This is a quantification value for packet size distribution anomalies, representing the overall degree of deviation in the packet size distribution. This is a nonlinear mapping function that nonlinearly amplifies the cumulative deviation function to highlight the contribution of abnormal data packets. The dynamic weighting function assigns anomaly weights to different data packets, depending on the median size. The relative differences are calculated, and the expression for the dynamic weighting function is as follows: , This is a weighted sensitivity factor that controls the intensity of the response to relative differences.

7. The method for constructing a service-oriented intelligent behavior conceptual model for unmanned equipment according to claim 4, characterized in that, The potential intrusion assessment coefficient generated when a pre-trained deep learning model intelligently predicts potential attack risks in video stream transmission within the monitoring window is compared and analyzed with a pre-set reference threshold to identify potential attack risks during video stream transmission. The specific process is as follows: If the potential intrusion assessment coefficient is greater than the reference threshold, a risk signal is generated, indicating that there is a potential attack risk during video stream transmission. If the potential intrusion assessment coefficient is less than or equal to the reference threshold, a normal signal is generated, indicating that the video stream is being transmitted efficiently.

8. The method for constructing a service-oriented intelligent behavior conceptual model for unmanned equipment according to claim 7, characterized in that, When a deep learning model identifies a potential attack vulnerability in a video stream transmission, i.e., when the video stream transmission generates a risk signal, the interval for target identification processing is intelligently shortened based on the degree of attack risk. Simultaneously, the number of inferences performed by the target identification algorithm within a short time is increased. The specific steps are as follows: When a deep learning model identifies a potential attack vulnerability in a video stream, it intelligently adjusts the target recognition processing interval based on the potential intrusion assessment coefficient and a preset reference threshold. To enhance the detection capability against brief and covert attacks, the nonlinear mapping relationship between the processing interval and the potential intrusion assessment coefficient is dynamically adjusted to ensure that the detection interval is shortened and the recognition frequency is increased under high-risk conditions. The expression for dynamic adjustment is: ,in, This is the adjusted target recognition processing interval. The initial target identification processing interval represents the detection cycle under normal circumstances. The potential intrusion assessment coefficient, generated by a deep learning model, reflects the current level of intrusion risk. The reference threshold is set. When the potential intrusion assessment coefficient exceeds the reference threshold, the identification interval will be shortened. To adjust the sensitivity coefficient, the extent to which the interval time is shortened is determined. As a smoothing factor, it controls the stability of the adjustment process and avoids instability caused by sudden changes; While shortening the target recognition processing interval, the number of inferences within a short period is dynamically increased to ensure efficient target recognition capabilities at higher detection frequencies. The number of inferences is exponentially amplified based on the potential intrusion assessment coefficient and a preset reference threshold to adapt to detection needs at different risk levels. The specific dynamic adjustment expression is as follows: ,in, The adjusted number of inference steps for target recognition. The number of inferences for initial target identification represents the number of inferences executed under normal circumstances. The adjustment factor for the number of inferences determines the degree of inference amplification when the attack risk increases. It is a non-linear exponential factor that determines the rate of increase in the number of inferences to deal with different levels of threats; To support higher-frequency target detection and inference, and to ensure a balance between task real-time performance and energy consumption, the resource allocation strategy is dynamically adjusted based on the potential intrusion assessment coefficient and system resource availability. Priority is given to allocating more computing resources to inference tasks, while energy consumption strategies are optimized to prevent over-computation from degrading device performance. The expression for adjusting the resource allocation strategy is as follows: ,in, The computing resources allocated for target identification, To maximize the allocable computing resources, This represents the proportion of currently available computing resources, which is dynamically adjusted according to changes in load. This is a sensitivity coefficient for resource allocation, used to control the magnitude of resource adjustments.

Citation Information

Patent Citations

  • Self-adjusting method of fuzzy network control system in network attack environment

    CN118170010A

  • Artificial intelligence network security system based on multi-modal large model training

    CN120281550A

  • Network security risk assessment method for unmanned aerial vehicle system

    CN120321656A

  • Cyber-attack detection, localization, and neutralization for unmanned aerial vehicles

    US20190260768A1