Privacy protection method for industrial information physical system under end-side cloud collaborative architecture
By adding privacy noise and optimizing the model in an edge-cloud architecture, the problems of privacy leakage and performance degradation in industrial cyber-physical systems are solved, achieving a balance between privacy protection and system performance.
Patent Information
- Application Number
- CN202511660138.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-13
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2045-11-13
AI Technical Summary
Under the edge-cloud collaborative architecture, industrial cyber-physical systems face the risk of privacy leakage and the impact of active perturbation technology on system performance, making it difficult to balance privacy and system performance.
A privacy protection model under the edge-cloud collaborative architecture is established. By adding zero-mean Gaussian distributed privacy noise to data transmission, and combining Kalman filter and proportional control method, an attack detector and setpoint optimization module are designed to optimize the privacy noise covariance to protect privacy and control performance loss.
While protecting the privacy of industrial process data to the greatest extent, it effectively controls the system performance loss caused by disturbances, ensuring that the system's privacy and control performance are within a controllable range.
Smart Images

Figure CN121125358A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of privacy and security in the Industrial Internet, specifically to a method for privacy protection of industrial cyber-physical systems under an edge-cloud collaborative architecture. Background Technology
[0002] In recent years, with the development of cloud computing technology, edge-cloud architecture has been widely applied in industrial cyber-physical systems (IPS). Under this architecture, industrial cloud servers are responsible for processing massive amounts of operational data and optimizing the control objectives of various industrial equipment based on production indicators. The edge devices control the operation of production equipment according to the control objectives issued by the cloud server. However, the open and interconnected operating environment also makes it more vulnerable to various malicious attacks and privacy leaks, seriously affecting the secure operation of the system. Active perturbation technology adds interference signals to the data transmitted between the cloud and the edge to increase the randomness of the data, thereby achieving the purpose of protecting privacy. However, this also affects the cloud's data processing, causing a decline in control performance and attack detection performance. Therefore, to ensure the high-efficiency operation of IPS, the design of privacy mechanisms based on active perturbation needs to balance privacy and system performance, preventing the leakage of production data privacy while ensuring that system performance loss is within a certain range. Summary of the Invention
[0003] Purpose of the invention: The technical problem to be solved by this invention is to address the shortcomings of existing technologies by providing a privacy protection method for industrial cyber-physical systems under an edge-cloud collaborative architecture, comprising the following steps: Step 1: Establish a privacy protection model based on an active perturbation strategy under the edge-cloud collaborative architecture; Step 2: Derive the detection performance index under active perturbation to obtain the theoretical upper limit of the false alarm rate; Step 3: Based on the upper limit of false alarm rate, relax the privacy protection model into a convex optimization problem and solve it to obtain the privacy noise covariance.
[0004] Step 1 includes the following steps: Step 1-1: Establish the end-side model, which includes industrial equipment, industrial processes, secondary sensors, and primary sensors; Steps 1-2: Establish an edge-side model, which includes a sub-filter and a controller; Steps 1-3: Establish a cloud-side model, which includes an attack detector, a main filter, and a setpoint optimization module; Steps 1-4: Establish a privacy protection target model.
[0005] In step 1-1, a state-space model of the industrial equipment is established: , in, , , These represent the device's state, control input, and secondary sensor measurement value at time k, respectively. and These represent the process noise and measurement noise of the state-space model of industrial equipment, respectively. and The covariance matrices are respectively , ; The system matrix is the state-space model of industrial equipment. This is the input matrix for the state-space model of the industrial equipment. This is the output matrix of the state-space model of the industrial equipment; Target values of production indicators in industrial processes Using the working point as the starting point, establish a state-space model to describe the changing patterns of production indicators in the industrial process: , in, Represents the state variables of the model. Indicates production indicators and target values The measured value of the inter-sensor deviation is obtained through the main sensor. and The process noise and measurement noise of the state-space model representing the variation law of production indicators are respectively used. and The covariance matrices are respectively , ; The system matrix is a state-space model of the changing patterns of production indicators. This is the input matrix for the state-space model of the changing patterns of production indicators. The output matrix of the state-space model of the changing patterns of production indicators; vector This indicates a sensor attack.
[0006] In steps 1-2, the secondary filter uses a Kalman filter to obtain an estimate of the state of the industrial equipment: , in, Yes The estimated value; the state estimation gain matrix Represented as: , Among them, superscript Represents the transpose of a matrix. Let be the prior covariance matrix of the edge-side state estimation error, satisfying the following algebraic Riccati equation: ; At the edge, privacy noise with a zero-mean Gaussian distribution will be added to the network. The subsequent state estimate is transmitted to the cloud for privacy protection. The privacy mechanism is represented as follows: , The controller uses proportional control to enable the industrial equipment to track the setpoint. : ,in, This represents the proportional gain matrix, which can be designed according to the pole placement method.
[0007] In steps 1-3, the main filter utilizes Constructing a Kalman filter to estimate the state variables at time k of an industrial process : , in, Yes Estimated values; filter gain Represented as: , in The prior covariance matrix of the main filter estimation error without added privacy noise satisfies the following algebraic Riccati equation: ; The main filter estimation error is defined as follows: residual Defined as: ; The setpoint optimization module generates a reference signal. , making It can stabilize at zero, in the form of: , in, It is gain; The following attack detector is constructed based on the generalized likelihood ratio test criterion: , in Let k represent the test statistic at time k. and These represent the absence and presence of the attack, respectively. For the detection threshold, This represents the residual calculated without adding privacy noise. covariance for: , The posterior covariance matrix of the secondary filter estimation error The posterior covariance matrix of the estimation error of the main filter , where I is the identity matrix.
[0008] In steps 1-4, the cumulative false alarm rate over time 0 to N is used to describe the detection performance of the attack detector, expressed as: , in, This represents the test statistic at time k, assuming the attack does not exist. Exceeding the detection threshold The probability, Represents probability; Simultaneously, a cumulative quadratic cost function is used from time 0 to N. Description of control performance: , in, It is the state weight matrix. It is the control weight matrix.
[0009] Fisher Information As a cloud-side slave signal Obtain The measure of privacy information is defined as: , in, It is a conditional distribution The probability density function, where log represents the natural logarithm. It is about The biased directional quantity; Establish the following optimization problem description privacy protection model: , , in Indicates limitations; selection of privacy noise. covariance matrix As an optimization decision variable The upper bound of the expected detection performance loss, This indicates how to control performance costs without privacy noise. The value, Let Tr be the upper bound of the desired control performance loss, and let Tr represent the trace of the matrix.
[0010] Step 2 includes: Variables in the attack detector Upper bound of covariance for: , in, Satisfying the following algebraic Riccati equation: , Among them, the estimation error update matrix .
[0011] Step 3 includes: The privacy protection model is relaxed into the following convex optimization problem: , , , , , Wherein, the state transition matrix Noise injection matrix Performance-cost weight matrix State selection matrix Control gain matrix ; Let q denote the incomplete gamma function in terms of regularization, where q is a vector. The dimension of.
[0012] The optimal privacy noise covariance is obtained by solving the convex optimization problem using the CVX toolbox. .
[0013] The present invention also provides an electronic device, including a processor and a memory, the memory storing program code that, when executed by the processor, causes the processor to perform the steps of the method.
[0014] The present invention also provides a storage medium storing a computer program or instructions that, when the computer program or instructions are run on a computer, execute the steps of the method described.
[0015] Compared with the prior art, the present invention has the following beneficial effects: The present invention is aimed at the edge-cloud architecture and designs a privacy protection mechanism based on an active perturbation strategy. The mechanism takes into account both privacy and system performance in the industrial environment during the design. By artificially adding interference signals to the data transmitted between the cloud and the edge, the privacy of industrial process data is protected to the greatest extent while effectively controlling the system performance loss caused by the introduction of perturbation. Attached Figure Description
[0016] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments, and the advantages of the present invention in the above and / or other aspects will become clearer.
[0017] Figure 1 This is a flowchart of the method of the present invention.
[0018] Figure 2 This is a structural diagram of an industrial cyber-physical system under a cloud-edge-device architecture.
[0019] Figure 3 This is a Fisher-Price information comparison chart according to an embodiment of the present invention.
[0020] Figure 4 This is a comparison chart of false alarm rate and threshold according to an embodiment of the present invention.
[0021] Figure 5 This is a comparison chart of control performance cost and threshold according to an embodiment of the present invention. Detailed Implementation
[0022] like Figure 1 As shown, this embodiment of the invention provides a privacy protection method for industrial cyber-physical systems under an edge-cloud collaborative architecture, comprising the following steps: S1: Establish a privacy protection model based on an active perturbation strategy under the edge-cloud collaborative architecture. Edge-side model: like Figure 2 As shown in the figure, this embodiment of the invention provides a structural diagram of an industrial cyber-physical system under a cloud-edge-device architecture, wherein the device-side model includes industrial equipment, industrial processes, secondary sensors, and primary sensors.
[0023] Establishing state-space models of industrial equipment based on methods such as physical mechanisms and system identification: , in, , , These represent the device's state, control input, and secondary sensor measurement value at time k, respectively. and These represent the process noise and measurement noise of the state-space model of industrial equipment, respectively. and The covariance matrices are respectively , ; The system matrix is the state-space model of industrial equipment. This is the input matrix for the state-space model of the industrial equipment. This is the output matrix of the state-space model of the industrial equipment; The production indicators of industrial processes are affected by the condition of industrial equipment, with the target value of the production indicators as the benchmark. Using the operating point as the working point, a state-space model describing the changing patterns of production indicators in the industrial process is established based on expert experience and system identification methods: , in, Represents the state variables of the model. Indicates production indicators and target values The measured value of the inter-deviation; and The process noise and measurement noise of the state-space model representing the variation law of production indicators are respectively used. and The covariance matrices are respectively , ; The system matrix is a state-space model of the changing patterns of production indicators. This is the input matrix for the state-space model of the changing patterns of production indicators. The output matrix of the state-space model of the changing patterns of production indicators; vector This indicates a sensor attack; The edge-side model includes a sub-filter and a controller.
[0024] The secondary filter uses a Kalman filter to obtain an estimate of the state of the industrial equipment: , in, Yes The estimated value. State estimation gain matrix. Represented as: , superscript This represents the transpose of a vector. Let be the prior covariance matrix of the edge-side state estimation error, satisfying the following algebraic Riccati equation: ; Furthermore, when the Kalman filter reaches steady state, the estimation error... It follows a zero-mean Gaussian distribution, i.e. ,in I is the identity matrix.
[0025] The controller uses proportional control to enable the industrial equipment to track the setpoint. : ,in, This represents the proportional gain matrix, which can be designed according to the pole placement method and must satisfy... It is stable.
[0026] To protect privacy, random zero-mean Gaussian noise is added to the state estimate. , The covariance matrix is defined as , The design methodology will be given in S3. This privacy mechanism is represented as follows: , The edge side uses the network to add noise to the state estimate. Transmitted to the cloud.
[0027] The cloud-based model includes an attack detector, a main filter, and a setpoint optimization module; The main filter utilizes Constructing a Kalman filter to estimate the state variables at time k of an industrial process : , in, Yes The estimated value.
[0028] In the aforementioned Kalman filter, the estimation error of the industrial equipment should be considered. Considered as except Additional noise sources, due to and Orthogonal, therefore the filter gain is designed as follows: , in The prior covariance matrix of the main filter estimation error without added privacy noise satisfies the following algebraic Riccati equation: ; The main filter estimation error is defined as follows: residual Defined as: .
[0029] The setpoint optimization module generates a reference signal. , making Able to stabilize at zero point (i.e., production indicators) Able to track target values ), in the following format: , in, It is the gain, which can be calculated using methods such as real-time optimization (RTO) and model predictive control (MPC), and its design must meet the stability requirements of the closed-loop system.
[0030] To detect malicious attacks, an attack detector was constructed based on the generalized likelihood ratio test criterion, and its form is as follows: , in, and These represent the absence and presence of the attack, respectively. For the detection threshold, This represents the residual calculated without adding privacy noise. covariance for: .
[0031] Privacy protection target model: The detection performance of the attack detector is described by the cumulative false alarm rate over time 0 to N, expressed as: , in, This represents the test statistic at time k, assuming the attack does not exist. Exceeding the detection threshold The probability, It represents probability.
[0032] Simultaneously, a cumulative quadratic cost function is used from time 0 to N. Description of control performance: , in, It is the state weight matrix. It is the control weight matrix.
[0033] Fisher Information As a cloud-side slave signal Obtain The measure of privacy information is defined as follows: , in, It is a conditional distribution The probability density function, Represents the natural logarithm. It is about The biased directional quantity.
[0034] Establish the following optimization problem description privacy protection model: , , in Indicates being limited by This is the upper bound of the designed detection performance loss. This indicates how to control performance costs without privacy noise. The value, The upper bound for the control performance loss is defined by Tr, which represents the trace of the matrix. This model uses privacy noise. covariance matrix As an optimization decision variable, the goal is to minimize Fisher information, and the detection performance loss and control performance loss are constrained within a certain range.
[0035] S2: Derive the detection performance index under active perturbation conditions to obtain the theoretical upper limit of the false alarm rate. The specific steps are as follows: Under the above conditions, the posterior covariance of the main filter estimation error in the absence of attack consists of two parts: the original posterior covariance and the covariance introduced by privacy noise. The expression is as follows: , in, Estimated error update matrix , This is the posterior covariance matrix of the estimation error of the main filter in the absence of privacy-preserving noise.
[0036] Attack detector residual The covariance is: , When the system reaches steady state When there is no attack, the estimation error covariance satisfies the following algebraic Riccati equation: , So, , Residual Covariance As time increases, the detection volume also increases, resulting in: , Therefore: ; In order to satisfy the original constraints Only if the following conditions are met: .
[0037] S3: Solving for the privacy noise covariance using convex optimization under performance constraints, the specific steps include: Solve for the Fisher information and control performance loss expression: Based on inequality relations: , The objective function relaxation .
[0038] Privacy noise causes a loss of control performance. for: , Wherein, the state transition matrix Noise injection matrix Performance-cost weight matrix State selection matrix Control gain matrix .
[0039] Can be transformed into constraints: .
[0040] Due to the injection of privacy noise, the analytical expression for the false alarm rate in steady state is... Unable to compute. To solve this problem, we introduce a variable that allows us to find an upper bound for the analytic expression: , in Statistic It follows a central chi-square distribution with q degrees of freedom, where q is a vector. The dimension of.
[0041] Based on the properties of the chi-square distribution: if , Let Gamma be an incomplete gamma function on regularization, then: .
[0042] Therefore, it is only necessary to let It is always true, that is This ensures that the following condition is met for all finite N. .
[0043] In time interval arrive Within, given the optimization objective Performance threshold and The optimal privacy noise covariance can be obtained by solving the following convex optimization problem using the CVX toolbox. : , , , , .
[0044] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
[0045] In this embodiment, the flotation process operation control can be described as industrial equipment and industrial process. The industrial equipment mainly corresponds to the specific physical devices and actuators in the flotation system, realizing basic operations and signal acquisition. The industrial process, on the other hand, focuses on the overall flotation process, optimizing parameters based on mineral processing indicators and production targets. The state variables of the industrial equipment are two-dimensional vectors. In this two-dimensional vector, the first dimension represents the mud level height, and the second dimension represents the feed slurry flow rate. Sensor readings for mud level and feed slurry flow rate; industrial process state variables are four-dimensional vectors. The first and second dimensions represent the ore and gangue mass in the mud, respectively; the third and fourth dimensions represent the mineral and gangue mass in the foam, respectively; and the sensor detection value is a two-dimensional vector. The first dimension is the concentrate grade detection value, and the second dimension is the tailings grade detection value.
[0046] Based on the actual operating conditions of the flotation process, the above model, after linearization at the equilibrium point, yields the relevant parameters: , , , , , .
[0047] The noise covariance is: , , , .
[0048] The control gain is: , .
[0049] For different time steps N, the privacy noise covariance matrix obtained by CVX optimization is used to generate the corresponding privacy noise and update the system state.
[0050] Based on the simulation results, Figure 3 After enabling the privacy mechanism, the Fisher Information value dropped significantly. The privacy protection mechanism increases the system's resistance to privacy leaks and enhances the system's privacy.
[0051] Figure 4 The results show that the addition of privacy noise does increase the false alarm rate, but by properly designing the privacy noise, the increase in the false alarm rate can still be kept within a controllable range.
[0052] Figure 5 The results show that by properly designing privacy noise, the cost of control performance can be kept within a certain range, effectively balancing the relationship between the strength of privacy protection and control performance.
[0053] This invention provides a privacy protection method for industrial cyber-physical systems under an edge-cloud collaborative architecture. Many methods and approaches exist for implementing this technical solution; the above description is merely a preferred embodiment of the invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of this invention, and these improvements and modifications should also be considered within the scope of protection of this invention. All components not explicitly stated in this embodiment can be implemented using existing technologies.
Claims
1. A privacy protection method for industrial cyber-physical systems under an edge-cloud collaborative architecture, characterized in that, Includes the following steps: Step 1: Establish a privacy protection model based on an active perturbation strategy under the edge-cloud collaborative architecture; Step 2: Derive the detection performance index under active perturbation to obtain the theoretical upper limit of the false alarm rate; Step 3: Based on the upper limit of false alarm rate, relax the privacy protection model into a convex optimization problem and solve it to obtain the privacy noise covariance.
2. The method according to claim 1, characterized in that, Step 1 includes the following steps: Step 1-1: Establish the end-side model, which includes industrial equipment, industrial processes, secondary sensors, and primary sensors; Steps 1-2: Establish an edge-side model, which includes a sub-filter and a controller; Steps 1-3: Establish a cloud-side model, which includes an attack detector, a main filter, and a setpoint optimization module; Steps 1-4: Establish a privacy protection target model.
3. The method according to claim 2, characterized in that, In step 1-1, a state-space model of the industrial equipment is established: , in, , , These represent the device's state, control input, and secondary sensor measurement value at time k, respectively. and These represent the process noise and measurement noise of the state-space model of industrial equipment, respectively. and The covariance matrices are respectively , ; The system matrix is the state-space model of industrial equipment. This is the input matrix for the state-space model of the industrial equipment. This is the output matrix of the state-space model of the industrial equipment; Target values of production indicators in industrial processes Using the working point as the starting point, establish a state-space model to describe the changing patterns of production indicators in the industrial process: , in, Represents the state variables of the model. Indicates production indicators and target values The measured value of the inter-sensor deviation is obtained through the main sensor. and The process noise and measurement noise of the state-space model representing the variation law of production indicators are respectively used. and The covariance matrices are respectively , ; The system matrix is a state-space model of the changing patterns of production indicators. This is the input matrix for the state-space model of the changing patterns of production indicators. The output matrix of the state-space model of the changing patterns of production indicators; vector This indicates a sensor attack.
4. The method according to claim 3, characterized in that, In steps 1-2, the secondary filter uses a Kalman filter to obtain an estimate of the state of the industrial equipment: , in, Yes The estimated value; the state estimation gain matrix Represented as: , Among them, superscript Represents the transpose of a matrix. Let be the prior covariance matrix of the edge-side state estimation error, satisfying the following algebraic Riccati equation: ; At the edge, privacy noise with a zero-mean Gaussian distribution will be added to the network. The subsequent state estimate is transmitted to the cloud to achieve privacy protection. The privacy mechanism is represented as follows: , The controller uses proportional control to enable the industrial equipment to track the setpoint. : ,in, This represents the proportional gain matrix.
5. The method according to claim 4, characterized in that, In steps 1-3, the main filter utilizes Constructing a Kalman filter to estimate the state variables at time k of an industrial process : , in, Yes Estimated values; filter gain Represented as: , in The prior covariance matrix of the main filter estimation error without added privacy noise satisfies the following algebraic Riccati equation: ; The main filter estimation error is defined as follows: residual Defined as: ; The setpoint optimization module generates a reference signal. , making It can stabilize at zero, in the form of: , in, It is gain; The following attack detector is constructed based on the generalized likelihood ratio test criterion: , in Let k represent the test statistic at time k. and These represent the absence and presence of the attack, respectively. For the detection threshold, This represents the residual calculated without adding privacy noise. covariance for: , The posterior covariance matrix of the secondary filter estimation error The posterior covariance matrix of the estimation error of the main filter , where I is the identity matrix.
6. The method according to claim 5, characterized in that, In steps 1-4, the cumulative false alarm rate over time 0 to N is used to describe the detection performance of the attack detector, expressed as: , in, This represents the test statistic at time k, assuming the attack does not exist. Exceeding the detection threshold The probability, Represents probability; Simultaneously, a cumulative quadratic cost function is used from time 0 to N. Description of control performance: , in, It is the state weight matrix. It is the control weight matrix; Fisher Information As a cloud-side slave signal Obtain The measure of privacy information is defined as: , in, It is a conditional distribution The probability density function, where log represents the natural logarithm. It is about The biased directional quantity; Establish the following optimization problem description privacy protection model: , , in Indicates limitations; selection of privacy noise. covariance matrix As an optimization decision variable The upper bound of the expected detection performance loss, This indicates how to control performance costs without privacy noise. The value, Let Tr be the upper bound of the desired control performance loss, and let Tr represent the trace of the matrix.
7. The method according to claim 6, characterized in that, Step 2 includes: Variables in the attack detector Upper bound of covariance for: , in, Satisfying the following algebraic Riccati equation: , Among them, the estimation error update matrix .
8. The method according to claim 7, characterized in that, Step 3 includes: The privacy protection model is relaxed into the following convex optimization problem: , , , , , Wherein, the state transition matrix Noise injection matrix Performance-cost weight matrix State selection matrix Control gain matrix ; Let q denote the incomplete gamma function in terms of regularization, where q is a vector. dimensionality; The optimal privacy noise covariance is obtained by solving the convex optimization problem using the CVX toolbox. .
9. An electronic device, characterized in that, It includes a processor and a memory, the memory storing program code that, when executed by the processor, causes the processor to perform the steps of the method as described in any one of claims 1 to 8.
10. A storage medium, characterized in that, It stores a computer program or instructions that, when run on a computer, perform the steps of the method as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Networked system data hidden attack detection method under differential privacy protection
CN115442160A
Data computing resource configuration method considering privacy protection under edge cloud collaboration framework
CN116614502A
Privacy protection method for remote state estimation eavesdropping attack of information physical system
CN117040771A
Data privacy protection method based on event triggering
CN118233140A
Optimal privacy protection transmission scheduling method and system for remote state estimation eavesdropping attack
CN118487831A