High complexity gnss induced spoofing detection method, apparatus, device and storage medium
By constructing the absolute value detection quantity output by the tracking loop of the GNSS receiver, and performing Gaussian distribution verification and sliding variance processing, the problem of high-complexity GNSS induced deception detection is solved, and accurate detection of in-phase and in-frequency deception signals is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHENZHEN KUANGWEI TECH CO LTD
- Filing Date
- 2025-09-02
- Publication Date
- 2026-04-24
AI Technical Summary
Existing technologies cannot effectively detect highly complex GNSS-induced spoofing attacks, especially enhanced spoofing attacks that are in the same frequency and phase and involve data bit estimation and replay.
By constructing the absolute value of the tracking loop output of the GNSS receiver, an AOSTL primary detection quantity is generated. After Gaussian distribution verification and sliding variance processing, an AOSTL-MV secondary detection quantity is constructed. Based on the Gaussian distribution characteristics, the detection threshold and probability are determined, and a binary decision is performed to determine whether there is deception interference in the GNSS satellite signal.
It improves the detection sensitivity of in-phase and in-frequency deception signals, enhances the detection performance of covert deception, and ensures accurate detection of deception signals.
Smart Images

Figure CN121276545B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of GNSS detection, and in particular to a highly complex GNSS induced deception detection method, apparatus, equipment, and storage medium. Background Technology
[0002] Global Navigation Satellite System (GNSS) utilizes information such as broadcast pseudorange, ephemeris, and signal transmission time to provide users with all-weather, all-time positioning, velocity, and time services, and is widely used in transportation, aerospace, environmental monitoring, and other fields. Due to its weak energy, publicly available signal structure, and long transmission distance, GNSS is susceptible to various forms of interference, with spoofing attacks being the most serious. In a spoofing attack, the attacker broadcasts false satellite signals, unknowingly guiding the tracking loop to the deceptive signal, causing the receiver to output parameters such as position, velocity, and time that the attacker intends to control. GNSS navigation spoofing attacks are one of the hot research topics in GNSS spatiotemporal information security.
[0003] Traditional Signal Quality Monitoring (SQM) detection algorithms mainly include Delta, Ratio, and ELP. Delta and Ratio algorithms both utilize the outputs of the leading, instantaneous, and lagging correlators in the in-phase branch to construct the detection measure to monitor the distortion degree of the correlation peak. However, their detection performance deteriorates when the composite signal fluctuates in the in-phase and positive-path channels. The ELP (Early-Late Phase) algorithm uses the phase difference between the leading and lagging phases as the detection measure, but its detection performance deteriorates sharply when the phase difference between the spoofed signal and the real signal is close to an integer multiple. Therefore, for high-complexity spoofing attacks that are enhanced, in-phase, and involve data bit estimation and replay, the detection performance of traditional SQM spoofing detection algorithms deteriorates sharply or even fails. Summary of the Invention
[0004] The main objective of this invention is to provide a high-complexity GNSS induced deception detection method, apparatus, device, and storage medium, aiming to solve the technical problem that existing high-complexity GNSS induced deception detection algorithms cannot effectively detect high-complexity deception attacks that are enhanced, co-frequency, in-phase, and involve data bit estimation and replay.
[0005] To achieve the above objectives, this invention provides a highly complex GNSS induced deception detection method, the method comprising the following steps:
[0006] The GNSS receiver is used to track and monitor multiple GNSS satellite signals that are in the same frequency and phase.
[0007] The AOSTL first-order detection quantity for each GNSS satellite signal is constructed based on the absolute value of the output of the tracking loop of the GNSS receiver. The output of the tracking loop includes the output of the instantaneous correlator, the lead correlator, and the lag correlator of the in-phase and quadrature branches. The AOSTL first-order detection quantity is expressed as follows:
[0008] AOSTL = |I E |+|I P |+|I L |+|Q E |+|Q P |+|Q L |
[0009] Where AOSTL represents the AOSTL Level 1 detection quantity, I P Q represents the output of the instantaneous correlator of the in-phase branch. P I represents the output of the instantaneous correlator of the orthogonal branch. E Q represents the output of the lead correlator in the in-phase branch. E I represents the output of the lead correlator of the orthogonal branch. L Q represents the output of the hysteresis correlator in the in-phase branch. L This represents the output of the hysteresis correlator for the orthogonal branch;
[0010] The Gaussian distribution of the AOSTL primary detection quantity was verified.
[0011] In response to the fact that the AOSTL primary detection quantity follows a Gaussian distribution, the AOSTL primary detection quantity is processed by sliding variance to construct the AOSTL-MV secondary detection quantity;
[0012] The detection threshold is determined based on the Gaussian distribution characteristics, and the detection probability is calculated based on the detection threshold.
[0013] Based on the detection probability and the AOSTL-MV secondary detection quantity, a binary decision is made on each GNSS satellite signal to obtain a binary decision result. The binary decision result is used to determine whether there is deception interference in the GNSS satellite signal.
[0014] Optionally, the Gaussian distribution verification of the AOSTL first-level detection quantity includes:
[0015] A skewness function is constructed, and the sample skewness of the AOSTL Level 1 detection quantity is determined based on the skewness function. The skewness function is expressed as follows:
[0016]
[0017] in, N represents sample skewness. S U(i) represents the number of sample points, and U(i) represents the sample value of the i-th AOSTL Level 1 detection quantity. This represents the mean of sample U;
[0018] The symmetry of the probability density function of the AOSTL first-level detection quantity is verified based on the sample skewness.
[0019] Construct an excess kurtosis function, and determine the sample excess kurtosis of the AOSTL Level 1 detection quantity based on the excess kurtosis function. The excess kurtosis function is expressed as:
[0020]
[0021] in, Indicates the excess kurtosis of the sample;
[0022] The tail thickness of the probability density function of the AOSTL Level 1 detection quantity is quantified based on the excess peak of the sample.
[0023] Gaussian distribution verification was performed based on the symmetry of the probability density function and the tail thickness of the AOSTL first-level detection quantity.
[0024] Optionally, determining the detection threshold based on Gaussian distribution characteristics includes:
[0025] The probability density function of the AOSTL first-level detection quantity is constructed based on the Gaussian distribution characteristics:
[0026]
[0027] Where f(·) represents the probability density function of the AOSTL Level 1 detector, μ AOSTL and Let represent the mean and variance of the AOSTL Level 1 detection volume following a Gaussian distribution, respectively; let represent the exponential function; and let x represent the auxiliary variable of the AOSTL Level 1 detection volume.
[0028] The detection threshold is determined based on the probability density function following a Gaussian distribution and the preset false alarm probability of the AOSTL Level 1 detection quantity. The detection threshold includes an upper detection limit and a lower detection limit, and is expressed as follows:
[0029]
[0030] Among them, V u V represents the detection limit. l Indicates the detection limit, erfc -1(·) denotes the inverse Gaussian function, and δ represents the detection threshold relative to the mean μ. AOSTL The offset, σ AOSTL P represents the standard deviation of a Gaussian distribution. fa This represents the preset false alarm probability of AOSTL Level 1 detection.
[0031] Optionally, calculating the detection probability based on the detection threshold includes:
[0032] A dual-threshold detection function is constructed based on the probability density function of the AOSTL first-level detection quantity following a Gaussian distribution. The dual-threshold detection function is expressed as follows:
[0033]
[0034] Where, represents the detection probability of AOSTL Level 1 detection quantity, f(·) represents the probability density function, H0 represents no deception interference, H1 represents deception interference, f(z|H0) represents the probability density function without deception, f(z|H1) represents the probability density function with deception, and z represents the auxiliary variable of AOSTL Level 1 detection quantity;
[0035] The AOSTL first-level detection quantity is detected based on the detection threshold and the dual-threshold detection function, and the detection probability is calculated.
[0036] Optionally, the step of detecting the AOSTL first-level detection quantity based on the detection threshold and the dual-threshold detection function, and calculating the detection probability, includes:
[0037] Construct a statistical function, and based on the statistical function, the detection threshold, and the dual-threshold detection function, perform detection on the AOSTL first-level detection quantity, and calculate the detection probability, referring to the following formula:
[0038]
[0039] Where q represents the total number of samples in the window, and Num(·) represents the statistical function.
[0040] Optionally, the step of performing sliding variance processing on the AOSTL primary detection quantity to construct the AOSTL-MV secondary detection quantity includes:
[0041] The AOSTL primary detection quantity is processed using sliding variance to construct the AOSTL-MV secondary detection quantity, which is expressed as follows:
[0042]
[0043] Where ω represents the moving average window length, N represents the number of sliding windows, L represents the sliding interval, AOSTL_MV(n) represents the AOSTL-MV secondary detection quantity corresponding to the nth sliding window after sliding variance processing, n represents the sliding window index, and i represents the AOSTL primary detection quantity index;
[0044] Optionally, calculating the detection probability based on the detection threshold further includes:
[0045] Obtain the preset false alarm probability of the AOSTL-MV secondary detection quantity, and determine the detection threshold based on the preset false alarm probability. The function relating the preset false alarm probability and the detection threshold is expressed as:
[0046]
[0047] Where M represents the total number of samples for the AOSTL-MV secondary detection without interference, Th represents the detection threshold of the AOSTL-MV secondary detection, and Num(·) represents the statistical function. This represents the preset false alarm probability of the AOSTL-MV secondary detection quantity;
[0048] The AOSTL-MV secondary detection quantity is detected based on the aforementioned detection threshold to obtain the detection probability:
[0049]
[0050] in, N represents the detection probability of the AOSTL-MV secondary detection quantity, and N′ represents the number of samples within the sliding window.
[0051] Furthermore, to achieve the above objectives, the present invention also proposes a high-complexity GNSS induced deception detection device, which includes:
[0052] The signal tracking and monitoring module is used to call the GNSS receiver to track and monitor multiple GNSS satellite signals of the same frequency and phase.
[0053] The first-level detection quantity construction module is used to construct the AOSTL first-level detection quantities of each GNSS satellite signal based on the absolute value of the output result of the tracking loop of the GNSS receiver. The output result of the tracking loop includes the output results of the instantaneous correlator, the lead correlator, and the lag correlator of the in-phase branch and the quadrature branch. The AOSTL first-level detection quantity is expressed as:
[0054] AOSTL = |I E |+|I P |+|I L |+|Q E|+|Q P |+|Q L |
[0055] Where AOSTL represents the AOSTL Level 1 detection quantity, I P Q represents the output of the instantaneous correlator of the in-phase branch. P I represents the output of the instantaneous correlator of the orthogonal branch. E Q represents the output of the lead correlator in the in-phase branch. E I represents the output of the lead correlator of the orthogonal branch. L Q represents the output of the hysteresis correlator in the in-phase branch. L This represents the output of the hysteresis correlator for the orthogonal branch;
[0056] A Gaussian distribution verification module is used to perform Gaussian distribution verification on the AOSTL first-level detection quantity;
[0057] The secondary detection quantity construction module is used to construct the AOSTL-MV secondary detection quantity by performing sliding variance processing on the AOSTL primary detection quantity in response to the fact that the AOSTL primary detection quantity follows a Gaussian distribution.
[0058] The detection probability calculation module is used to determine the detection threshold based on the Gaussian distribution characteristics, and to calculate the detection probability based on the detection threshold.
[0059] The deception decision module is used to perform binary decision on each GNSS satellite signal based on the detection probability and the AOSTL-MV secondary detection quantity, and obtain a binary decision result. The binary decision result is used to determine whether there is deception interference in the GNSS satellite signal.
[0060] Furthermore, to achieve the above objectives, this application also proposes a high-complexity GNSS induced deception detection device, the device comprising: a memory, a processor, and a high-complexity GNSS induced deception detection program stored in the memory, the processor being used to run the high-complexity GNSS induced deception detection program, the computer program being configured to implement the steps of the high-complexity GNSS induced deception detection method as described above.
[0061] In addition, to achieve the above objectives, this application also proposes a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the high-complexity GNSS induced deception detection method described above.
[0062] In addition, to achieve the above objectives, this application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the high-complexity GNSS induced deception detection method described above.
[0063] This invention tracks and monitors multiple in-phase and co-frequency GNSS satellite signals using a GNSS receiver. Based on the absolute values of the tracking loop output of the GNSS receiver, it constructs AOSTL Level 1 detection parameters for each GNSS satellite signal. The tracking loop output includes the instantaneous correlator output, lead correlator output, and lag correlator output of the in-phase and quadrature branches. The AOSTL Level 1 detection parameters are verified using a Gaussian distribution. Responding to the Gaussian distribution, the AOSTL Level 1 detection parameters are processed using sliding variance to construct an AOSTL-MV Level 2 detection parameter. The detection quantity is determined based on the Gaussian distribution characteristics to establish a detection threshold, and the detection probability is calculated based on the detection threshold. A binary decision is then performed on each GNSS satellite signal based on the detection probability and the AOSTL-MV secondary detection quantity to obtain a binary decision result. This binary decision result is used to determine whether GNSS satellite signals exhibit deception interference. Since this invention constructs the detection quantity based on the absolute values of the correlator outputs of the in-phase and quadrature branches of the tracking loop, it ensures that the detection quantity is not affected by carrier synchronization, thereby improving the detection sensitivity of deception signals and enabling accurate detection of deception signals that are in phase and frequency with the real signal, thus improving the performance of covert deception detection. Attached Figure Description
[0064] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0065] Figure 1 This is a schematic diagram of the structure of a highly complex GNSS-induced deception detection device with a hardware operating environment involved in the embodiments of the present invention;
[0066] Figure 2 This is a flowchart illustrating the first embodiment of the high-complexity GNSS induced deception detection method of the present invention;
[0067] Figure 3 This is a schematic diagram of an inducing deception process;
[0068] Figure 4 This is a schematic diagram of the AOSTL first-level detection output distribution in one embodiment of the high-complexity GNSS induced deception detection method of the present invention;
[0069] Figure 5 This is a flowchart illustrating the second embodiment of the high-complexity GNSS induced deception detection method of the present invention;
[0070] Figure 6 This is a schematic diagram of the sliding variance processing of AOSTL-MV in one embodiment of the high-complexity GNSS induced deception detection method of the present invention;
[0071] Figure 7 This is a schematic diagram illustrating the detection principle of the AOSTL-MV secondary detection quantity in one embodiment of the high-complexity GNSS induced deception detection method of the present invention;
[0072] Figure 8 This is a schematic diagram of the output waveform of the AOSTL primary detection quantity;
[0073] Figure 9 This is a schematic diagram of the output waveform of the secondary detection quantity of AOSTL-MV;
[0074] Figure 10 A diagram showing the comparison of detection probabilities of the original detection data for PRN3 satellites;
[0075] Figure 11 A diagram showing the comparison of detection probabilities of the original detection data for PRN6 satellites;
[0076] Figure 12 A diagram showing the comparison of detection probabilities of the original detection data for satellites numbered PRN19;
[0077] Figure 13(a) is a schematic diagram comparing the detection probabilities of AOSTL-MV secondary detection quantities for PRN3 satellites;
[0078] Figure 13(b) is a schematic diagram comparing the detection probabilities of AOSTL-MV secondary detection quantities for PRN6 satellites;
[0079] Figure 13(c) is a schematic diagram comparing the detection probabilities of AOSTL-MV secondary detection quantities for PRN19 satellites.
[0080] Figure 14(a) is a schematic diagram of the binary decision result of AOSTL-MV;
[0081] Figure 14(b) is a schematic diagram of the binary decision result of Ratio-MV;
[0082] Figure 14(c) is a schematic diagram of the binary decision result of ELP-MV;
[0083] Figure 14(d) is a schematic diagram of the binary decision result of Delta-MV;
[0084] Figure 15This is a diagram illustrating the comparison of deception detection probability results;
[0085] Figure 16 This is a diagram illustrating the comparison of ROC curves;
[0086] Figure 17 This is a structural block diagram of the first embodiment of the high-complexity GNSS induced deception detection device of the present invention.
[0087] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0088] It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the invention.
[0089] Reference Figure 1 , Figure 1 This is a schematic diagram of the structure of a highly complex GNSS-induced deception detection device with a hardware operating environment involved in the embodiments of the present invention.
[0090] like Figure 1 As shown, this highly complex GNSS-induced spoofing detection device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to establish communication between these components. The user interface 1003 may include a display screen or an input unit such as a keyboard; optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wireless-Fidelity (Wi-Fi) interface). The memory 1005 may be high-speed random access memory (RAM) or stable non-volatile memory (NVM), such as a disk storage device. The memory 1005 may also optionally be a storage device independent of the aforementioned processor 1001.
[0091] Those skilled in the art will understand that Figure 1 The structure shown does not constitute a limitation on highly complex GNSS induced deception detection equipment, which may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0092] like Figure 1As shown, the memory 1005, which is a computer-readable storage medium, may include an operating system, a network communication module, a user interface module, and a highly complex GNSS induced deception detection program.
[0093] exist Figure 1 In the high-complexity GNSS induced deception detection device shown, the network interface 1004 is mainly used for data communication with the network server; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and memory 1005 in the high-complexity GNSS induced deception detection device of the present invention can be set in the high-complexity GNSS induced deception detection device. The high-complexity GNSS induced deception detection device calls the high-complexity GNSS induced deception detection program stored in the memory 1005 through the processor 1001 and executes the high-complexity GNSS induced deception detection method provided in the embodiment of the present invention.
[0094] This invention provides a highly complex GNSS induced deception detection method, referring to... Figure 2 , Figure 2 This is a flowchart illustrating the first embodiment of the high-complexity GNSS induced deception detection method of the present invention.
[0095] In this embodiment, the high-complexity GNSS induced deception detection method includes the following steps:
[0096] Step S10: Call the GNSS receiver to track and monitor multiple GNSS satellite signals with the same frequency and phase.
[0097] It should be noted that this embodiment is applied to the detection of highly complex spoofing attacks on GNSS that involve co-frequency and co-phase signals and data bit estimation and replay. "Enhanced co-frequency and co-phase" means that the fake satellite signal emitted by the spoofer is highly consistent with the real satellite signal in terms of frequency and phase, making it more difficult for the receiver to distinguish between the real and fake signals. "Data bit estimation and replay" means that the spoofer estimates and analyzes the data bits of the real signal and then replays the processed signal to achieve the purpose of more covertly interfering with the receiver. This causes the receiver to be unknowingly drawn to the spoofed signal and output parameters such as position, speed and time that the attacker intends to control, thereby disrupting the normal positioning, velocity measurement and time synchronization services of GNSS.
[0098] It should be understood that the executing entity of this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or a terminal electronic device capable of performing the above functions. The following description uses a high-complexity GNSS induced deception detection device (hereinafter referred to as the detection device) as an example to illustrate this embodiment and the following embodiments.
[0099] It should be noted that this embodiment uses an induced spoofing attack as an example for explanation. The process of an induced spoofing attack consists of four stages: spoofing injection (Ⅰ), spoofing alignment (Ⅱ), spoofing pull (Ⅲ), and spoofing separation (Ⅳ). Stage Ⅰ: The spoofing signal maintains a certain distance from the real signal and continuously approaches it; the receiver tracks the real signal. Stage Ⅱ: The spoofing signal aligns with the real signal and gradually increases its power; the receiver still tracks the real signal. Stage Ⅲ: The spoofing signal uses its power advantage to seize control of the receiver; the receiver is pulled towards the spoofing signal. Stage Ⅳ: The spoofing signal slowly deviates from the real signal by adjusting its code rate; the completion of the induced spoofing has an irreversible impact on the receiver. The induced spoofing process is as follows: Figure 3 As shown, Figure 3 This is a schematic diagram of an inducement-based deception process.
[0100] When deception interference is present, the received signal of a GNSS receiver consists of the real signal, the deception signal, and noise, as shown in the following formula:
[0101] x(t)=x a (t)+x s (t)+n(t)
[0102] Where x(t) represents the received signal, x a (t) represents the real signal, x s (t) represents the deception signal, and n(t) represents zero-mean Gaussian white noise.
[0103] Real signal x a (t) is represented as:
[0104]
[0105] Among them, P a C represents the actual signal power. a For the pseudo-random spreading code of the real signal, D a For the actual signal navigation data of ±1, τ a The actual signal code delay is given, and f0 is the center frequency. This represents the Doppler frequency shift of the actual signal. The carrier phase of the real signal is represented by j, which represents the imaginary unit.
[0106] Since the deceptive signal and the real signal have the same signal structure, the deceptive signal is:
[0107]
[0108] Among them, P s To deceive the signal power, C sTo deceive the signal using a pseudo-random spreading code, D s For ±1 deception signal navigation data, τ s To deceive the signal code delay, To deceive the signal through Doppler frequency shift, The carrier phase of the deception signal.
[0109] Step S20: Construct the AOSTL Level 1 detection quantity for each GNSS satellite signal based on the absolute value of the output result of the tracking loop of the GNSS receiver.
[0110] It should be noted that the output of the tracking loop is the output of the correlators in each branch of the tracking loop. The tracking loop correlators include a leading correlator, an instantaneous correlator, and a lagging correlator, and the autocorrelation power includes leading autocorrelation power, instantaneous autocorrelation power, and lagging autocorrelation power.
[0111] It should be noted that the output of the tracking loop includes the instantaneous correlator output, the lead correlator output, and the lag correlator output of the in-phase branch and the quadrature branch.
[0112] It should be noted that the tracking loop correlator, as a core component of the receiver, functions to remove pseudocode. Taking the C / A code of the Global Positioning System (GPS) L1 carrier as an example, the correlation output refers to the following output correlation function:
[0113] R(t,τ)=R a (t,τ)+R s (t,τ)+R n (t,τ)
[0114] Based on the characteristics of PRN codes, the cross-correlation result between the real signal and the local signal of the GNSS receiver is as follows:
[0115]
[0116] If the deceptive signal and the real signal have similar signal structures and comparable power, then the cross-correlation result between the deceptive signal and the local signal can be expressed as:
[0117] R s (t,τ)=R a (t,τ1)
[0118] Where R(t,τ) represents the output of the trace loop correlator, R a (t,τ) represents the cross-correlation result between the real signal and the local signal of the GNSS receiver, R s (t,τ) represents the cross-correlation result between the deception signal and the local signal, R n(t,τ) represents the cross-correlation result between the noise signal and the local signal, τ1 represents the code phase difference between the spoof signal and the real signal, and R(·) represents the cross-correlation function of the spreading code.
[0119] It should be noted that the tracking loop correlator uses three pairs of correlators: lead, instant, and lag. The interval between adjacent correlators is 0.5 chips, and the coherence integration time is 1 ms. Each correlator pair consists of an in-phase branch and a quadrature branch. If the navigation data code is 1, the instant code is in the in-phase branch I. P and the orthogonal branch Q P The instant outputs are as follows:
[0120]
[0121] Among them, I P Q represents the output of the instantaneous correlator on the in-phase branch. P P represents the output of the instantaneous correlator on the orthogonal branch. a P represents the power of the actual signal. s τ represents the power of the deception signal. c Indicates the local spreading code phase, τ a τ represents the code phase of the actual signal. s The code phase represents the deception signal. Represents the carrier phase of the real signal. Indicates the carrier phase of the replicated signal. This represents the carrier phase of the deception signal. If the navigation data code is -1, then I... P and Q P These are the opposites of the instantaneous output results mentioned above.
[0122] It is understandable that this embodiment addresses the problem that traditional SQM-type detection algorithms cannot effectively detect enhanced in-frequency and in-phase high-stealth spoofing attacks and have unsatisfactory detection performance. It uses the Absolute Output Sum of the Tracking Loop (AOSTL) first-level detection quantity from the GNSS receiver tracking loop, which is expressed as:
[0123] AOSTL = |I E |+|I P |+|I L |+|Q E |+|Q P |+|Q L |
[0124] Where AOSTL represents the AOSTL Level 1 detection quantity, I P Q represents the output of the instantaneous correlator of the in-phase branch. PI represents the output of the instantaneous correlator of the orthogonal branch. E Q represents the output of the lead correlator in the in-phase branch. E I represents the output of the lead correlator of the orthogonal branch. L Q represents the output of the hysteresis correlator in the in-phase branch. L This represents the output of the hysteresis correlator for the orthogonal branch.
[0125] It should be understood that while Ratio and Delta use the output information of the in-phase branch to detect the degree of distortion of the correlation peak, their detection performance deteriorates sharply when the composite signal fluctuates between the quadrature and communication channels. Unlike Ratio and Delta, AOSTL utilizes both in-phase and quadrature branches, making full use of the tracking loop channel information. Its detection performance is less affected by fluctuations in the in-phase / quadrature channels. The ELP algorithm constructs the detection quantity using the carrier phase difference of the leading and lagging branches. Without spoofing, ELP is close to zero and is used to detect abnormal changes in carrier phase difference. However, the algorithm fails when the phase difference is close to an integer multiple of π. Unlike ELP, the AOSTL algorithm uses the absolute value of the tracking loop I / Q output to construct the detection quantity. It is unaffected by carrier synchronization and is more sensitive to spoofing signals.
[0126] Step S30: Perform Gaussian distribution verification on the AOSTL first-level detection quantity.
[0127] In practical implementation, the distribution characteristics of the detection quantity are the theoretical basis for setting the detection threshold in signal detection and are a key aspect of the detection process. Considering that the AOSTL algorithm constructs the detection quantity by summing the absolute values of the six branches of the GNSS tracking loop, its probability density function cannot be directly derived theoretically. For this reason, skewness (S) and kurtosis (K) are introduced in conjunction with the distribution characteristics of the AOSTL detection quantity. When |S| < 0.5 and |K| < 0.5, it can be considered to approximately follow a Gaussian distribution.
[0128] Furthermore, to accurately verify whether the AOSTL first-level detection quantity follows a Gaussian distribution, step S30 above may include:
[0129] Step S301: Construct a skewness function and determine the sample skewness of the AOSTL first-level detection quantity based on the skewness function;
[0130] Step S302: Verify the symmetry of the probability density function of the AOSTL first-level detection quantity based on the sample skewness.
[0131] It should be noted that sample skewness is used to measure the symmetry of the probability density function (PDF) of the AOSTL detection: when S > 0, the PDF is right-skewed, and vice versa; when S = 0, the PDF is symmetric about the mean. Since the actual number of sampled signals is limited, this embodiment uses sample skewness instead of the theoretical skewness. The skewness function is expressed as:
[0132]
[0133] in, N represents sample skewness. S U(i) represents the number of sample points, and U(i) represents the sample value of the i-th AOSTL Level 1 detection quantity. This represents the mean of sample U.
[0134] Step S303: Construct the excess kurtosis function, and determine the sample excess kurtosis of the AOSTL Level 1 detection quantity based on the excess kurtosis function;
[0135] Step S304: Quantify the tail thickness of the probability density function of the AOSTL Level 1 detection quantity based on the excess peak of the sample.
[0136] It should be noted that sample kurtosis reflects the thickness of the tails of the probability density function (PDF) of the AOSTL test result of the random variable. Compared with the standard normal distribution PDF, when K < 0, the PDF of the random variable exhibits fat tails, and vice versa; when K = 0, the PDF exhibits the tails of the standard normal distribution. In practice, this embodiment uses sample excess kurtosis instead of the theoretical excess kurtosis, and the excess kurtosis function is expressed as:
[0137]
[0138] in, This indicates the excess kurtosis of the sample.
[0139] Step S305: Perform Gaussian distribution verification based on the symmetry of the probability density function and the tail thickness of the AOSTL first-level detection quantity.
[0140] In some embodiments, the mean and variance of AOSTL detections under 100s of clean data from 10 randomly selected satellite sample signals are shown in Table 1:
[0141] Table 1. Skewness and kurtosis parameters of AOSTL corresponding to 10 satellite signal data.
[0142]
[0143] Table 1 shows the data for all satellites. This indicates that the distribution of AOSTL detection volume is approximately symmetrical; The value is close to 0, indicating that the envelope of the AOSTL detection volume distribution approximates the envelope of a standard normal distribution. Based on the above statistical results, it can be seen that the AOSTL detection volume closely follows a Gaussian distribution.
[0144] Step S40: In response to the fact that the AOSTL primary detection quantity follows a Gaussian distribution, the AOSTL primary detection quantity is processed by sliding variance to construct the AOSTL-MV secondary detection quantity.
[0145] In some embodiments, to suppress noise, reduce dynamic range, and improve detection performance, AOSTL is subjected to sliding variance processing with a fixed-length window. The variance of AOSTL within the window is calculated to construct the AOSTL-MV secondary detection quantity. Since the distribution characteristics of the AOSTL-MV secondary detection quantity are the same as those of the AOSTL primary detection quantity, after verifying the Gaussian distribution characteristics of the AOSTL primary detection quantity, the detection threshold of the AOSTL-MV secondary detection quantity is determined based on the Gaussian distribution characteristics. Detection is then performed based on the detection threshold of the AOSTL-MV secondary detection quantity, and the detection probability is calculated. Deception detection is then performed on each GNSS satellite signal based on the detection probability of the AOSTL-MV secondary detection quantity. The AOSTL-MV secondary detection quantity is expressed as:
[0146]
[0147] Where ω represents the moving average window length, N represents the number of sliding windows, L represents the sliding interval, AOSTL_MV(n) represents the AOSTL-MV secondary detection quantity corresponding to the nth sliding window after sliding variance processing, n represents the sliding window index, and o represents the AOSTL primary detection quantity index.
[0148] Step S50: Determine the detection threshold based on the Gaussian distribution characteristics, and calculate the detection probability based on the detection threshold.
[0149] In practical implementation, considering the variation in the detection quantity, detection problems usually adopt a dual-threshold method. Therefore, the detection equipment can determine the upper and lower limits of detection based on the Gaussian distribution characteristics, calculate the detection threshold, and then further evaluate the detection probability.
[0150] Furthermore, in order to accurately calculate the detection threshold, step S50 above may include:
[0151] Step S501: Construct the probability density function of the AOSTL first-level detection quantity based on the Gaussian distribution characteristics;
[0152] Step S502: Determine the detection threshold based on the probability density function that follows a Gaussian distribution and the preset false alarm probability of the AOSTL first-level detection quantity.
[0153] Understandably, in Table 1, all satellites... This indicates that the distribution of AOSTL detection volume is approximately symmetrical; The value being close to 0 indicates that the envelope of the AOSTL detection volume distribution approximates the envelope of a standard normal distribution. Based on the above statistical results, it can be seen that the AOSTL detection volume approximately follows a Gaussian distribution. Let its mean be the mean μ of a Gaussian distribution. AOSTL The variance is the mean and variance of a Gaussian distribution.
[0154] If X = AOSTL, then the probability density function of X can be expressed as:
[0155]
[0156] Where f(·) represents the probability density function of the AOSTL Level 1 detector, μ AOSTL and Let represent the mean and variance of the AOSTL Level 1 detections, respectively, which follow a Gaussian distribution; let represent the exponential function; and let x represent the auxiliary variable of the AOSTL Level 1 detections.
[0157] Based on the above analysis, taking sample satellite 3 as an example, AOSTL approximately follows a mean of 5.0112 × 10⁻⁶. 6 The variance is 1.9860 × 10⁻⁶. 13 The Gaussian distribution, and its output histogram statistics are as follows: Figure 4 As shown, Figure 4 This is a schematic diagram of the AOSTL primary detection output distribution, which clearly shows that its distribution characteristics are consistent with the theoretical analysis.
[0158] The detection threshold includes an upper detection limit and a lower detection limit, and the detection threshold is expressed as follows:
[0159]
[0160] Among them, V u V represents the detection limit. l Indicates the detection limit, erfc -1 (·) denotes the inverse Gaussian function, and δ represents the detection threshold relative to the mean μ. AOSTL The offset, σ AOSTL P represents the standard deviation of a Gaussian distribution. fa This represents the preset false alarm probability of AOSTL Level 1 detection.
[0161] Furthermore, in order to accurately calculate the detection probability, step S50 above also includes:
[0162] Step S511: Construct a dual-threshold detection function based on the probability density function of the AOSTL first-level detection quantity following a Gaussian distribution;
[0163] Step S512: Detect the AOSTL first-level detection quantity based on the detection threshold and the dual-threshold detection function, and calculate the detection probability.
[0164] It should be noted that, considering the variation in detection volume, detection problems typically employ a dual-threshold method. For a dual-threshold detection method, theoretically, the false alarm probability and the detection probability can be calculated using a dual-threshold detection function, which is expressed as:
[0165]
[0166]
[0167] Where, represents the detection probability of AOSTL Level 1 detection, f(·) represents the probability density function, H0 represents no deception interference, H1 represents deception interference, f(z|H0) represents the probability density function without deception, f(z|H1) represents the probability density function with deception, and z represents the auxiliary variable of AOSTL Level 1 detection.
[0168] Furthermore, to address the issue of time-varying and unknown parameters of the deception signal in actual detection scenarios, and thereby improve the accuracy of detection probability calculation, step S512 may include:
[0169] Step S5121: Construct a statistical function, and perform detection on the AOSTL first-level detection quantity based on the statistical function, the detection threshold, and the dual-threshold detection function, and calculate the detection probability.
[0170] Understandably, based on the Neyman-Pearson (NP) criterion, Pfa is pre-set, and the detection threshold is calculated from it before further evaluating Pd. In practice, the parameters of the deception signal are time-varying and unknown, making it impossible to obtain a theoretical result for Pd. Therefore, this embodiment can use a statistical method to calculate it, referring to the following formula:
[0171]
[0172] Where q represents the total number of samples in the window, and Num(·) represents the statistical function.
[0173] Step S60: Perform binary decision on each GNSS satellite signal based on the detection probability and the AOSTL-MV secondary detection quantity to obtain the binary decision result.
[0174] It should be noted that the binary decision result is used to determine whether there is deception interference in the GNSS satellite signal.
[0175] Understandably, the problem of detecting spoofing signals can be viewed as a binary hypothesis testing problem, where H0 represents the absence of spoofing interference and H1 represents the presence of spoofing interference:
[0176]
[0177] Specifically, when the AOSTL detection output is within the threshold, the signal is considered to be spoofed; when the AOSTL detection output is not within the threshold, the signal is considered to be spoofed.
[0178] This embodiment tracks and monitors multiple in-phase and in-frequency GNSS satellite signals using a GNSS receiver. Based on the absolute values of the tracking loop output of the GNSS receiver, AOSTL Level 1 detection parameters for each GNSS satellite signal are constructed. The tracking loop output includes the instantaneous correlator output, lead correlator output, and lag correlator output of the in-phase and quadrature branches. The AOSTL Level 1 detection parameters are verified using a Gaussian distribution. Responding to the Gaussian distribution, the AOSTL Level 1 detection parameters are processed using sliding variance to construct an AOSTL-MV² distribution. The AOSTL-MV secondary detection quantity is used to determine the detection threshold based on Gaussian distribution characteristics, and the detection probability is calculated based on the detection threshold. A binary decision is then performed on each GNSS satellite signal based on the detection probability and the AOSTL-MV secondary detection quantity to obtain a binary decision result. This binary decision result is used to determine whether GNSS satellite signals exhibit deception interference. Since this invention constructs the detection quantity based on the absolute values of the correlator outputs of the in-phase and quadrature branches of the tracking loop, it ensures that the detection quantity is not affected by carrier synchronization, thereby improving the detection sensitivity of deception signals and enabling accurate detection of deception signals that are in phase and frequency with the real signal, thus improving the performance of covert deception detection.
[0179] refer to Figure 5 , Figure 5 This is a flowchart illustrating the second embodiment of the high-complexity GNSS induced deception detection method of the present invention.
[0180] Based on the first embodiment described above, in this embodiment, step S40 may include:
[0181] Step S41: Perform sliding variance processing on the AOSTL primary detection quantity to construct the AOSTL-MV secondary detection quantity.
[0182] It should be noted that, in this embodiment, to suppress noise, reduce dynamic range, and improve detection performance, a moving variance (MV) processing method is applied to the AOSTL primary detection quantity using a fixed-length window to construct the AOSTL-MV secondary detection quantity. This aims to suppress the influence of noise, reduce the dynamic range, and simplify the detection process. The AOSTL-MV secondary detection quantity is expressed as follows:
[0183]
[0184] Where ω represents the moving average window length, N represents the number of sliding windows, L represents the sliding interval, AOSTL_MV(n) represents the AOSTL-MV secondary detection quantity corresponding to the nth sliding window after sliding variance processing, n represents the sliding window index, and i represents the AOSTL primary detection quantity index.
[0185] The sliding process of AOSTL-MV uses a window length of ω and a sliding interval of L to process the sliding variance, resulting in N sliding windows. The variance of the AOSTL detectors within each window is then calculated to construct the AOSTL-MV secondary detectors. The sliding process is as follows: Figure 6 As shown, Figure 6 This is a schematic diagram of the sliding variance processing procedure in AOSTL-MV.
[0186] To suppress noise interference, reduce dynamic range, and simplify the detection process, the AOSTL-MV algorithm is obtained by applying sliding variance processing to AOSTL. Its detection principle is as follows: Figure 7 As shown, Figure 7 This is a schematic diagram illustrating the detection principle of AOSTL-MV secondary detection quantity.
[0187] Step S42: Obtain the preset false alarm probability of the AOSTL-MV secondary detection quantity, and determine the detection threshold based on the preset false alarm probability;
[0188] Step S43: Detect the AOSTL-MV secondary detection quantity based on the detection threshold to obtain the detection probability.
[0189] It should be noted that since the essence of deception detection is to detect abnormal fluctuations in the signal, and variance is used to measure the degree of signal fluctuation, the closer the variance is to 0, the more stable the waveform and the lower the degree of distortion. In short, the moving variance (MV) simplifies dual-threshold detection to single-threshold detection while reducing the degree of signal fluctuation. Its false alarm probability and detection probability can be expressed as functions of the preset false alarm probability and the detection threshold, respectively:
[0190]
[0191] Where M represents the total number of samples for the AOSTL-MV secondary detection without interference, Th represents the detection threshold of the AOSTL-MV secondary detection, and Num(·) represents the statistical function. This represents the preset false alarm probability of the AOSTL-MV secondary detection quantity. N represents the detection probability of the AOSTL-MV secondary detection quantity, and N′ represents the number of samples within the sliding window.
[0192] This embodiment constructs an AOSTL-MV secondary detection quantity by performing sliding variance processing on the AOSTL primary detection quantity, obtains the preset false alarm probability of the AOSTL-MV secondary detection quantity, determines a detection threshold based on the preset false alarm probability, and detects the AOSTL-MV secondary detection quantity based on the detection threshold to obtain the detection probability. This effectively suppresses noise, reduces the dynamic range, and improves detection performance, thereby suppressing the influence of noise, reducing the dynamic range, and simplifying the detection process.
[0193] Furthermore, to verify the effectiveness of the embodiments of the present invention, the performance of the present invention is verified through experiments. The experiments use the DS8 dataset from the TEXBAT dataset for deception detection. DS8 is an enhanced carrier-synchronous GNSS navigation deception attack; its deception signal power is close to the real signal power. It has a sampling frequency of 24MHz, a code rate of 1.023MHz, a low-power matching traction strategy, a data length of 460s, and a data type of I / Q, making it a low-power static time deception dataset. Compared with the other seven deception attacks in TEXBAT, DS8 has stronger concealment and is more complex, injecting deception signals starting at 110s. Based on these reasons, deception detection experiments are conducted using DS8 as the dataset to analyze the detection performance of the proposed algorithm, including detection probability, detection immediacy, detection range, and detection accuracy.
[0194] This invention addresses the problem that traditional spoofing detection algorithms cannot effectively detect highly covert GNSS spoofing attacks with enhanced co-frequency and co-phase capabilities that involve data estimation. It proposes a spoofing detection algorithm based on AOSTL-MV. The AOSTL-MV construction process first constructs a first-level detection quantity based on the Absolute Output Sum of the Tracking Loop (AOSTL). Then, it applies Moving Variance (MV) processing to AOSTL to obtain a second-level detection quantity, which suppresses noise, reduces the dynamic range, and simplifies the detection process.
[0195] Verification of detection output:
[0196] Taking the DS8 PRN3 as an example, the corresponding AOSTL detection output waveform changes over time as follows: Figure 8 As shown, Figure 8 This is a schematic diagram of the output waveform of the AOSTL primary detection quantity.
[0197] Depend on Figure 8 The results show that the AOSTL detection output waveform exhibits a large fluctuation range and begins to distort around 120s. However, a significant portion of the detection output also falls within the detection threshold. To reduce the dynamic range of the detection, suppress noise, and simplify detection, a 25ms sliding window is used for MV processing, constructing an AOSTL-MV two-level detection system as follows: Figure 9 As shown, Figure 9 This is a schematic diagram of the output waveform of the AOSTL-MV secondary detection quantity.
[0198] according to Figure 9 The results analysis shows that the waveform output of AOSTL-MV is stable and distortion-free in the first 110s; after the deception is injected at 110s, the waveform of AOSTL-MV becomes stable and distortion-free at about 120s, and then becomes completely above the detection threshold at about 210s.
[0199] comprehensive Figure 8 and Figure 9 The results show that, compared to the AOSTL detection, the output waveform of the AOSTL-MV detection exhibits a clearer trend over time, and after distortion occurs around 120 seconds, it remains distinct from the output waveform under the non-spoofing condition (the first 110 seconds). Therefore, based on MV processing, on the one hand, the fluctuation range of the detection can be reduced, while clearly reflecting its trend over time; on the other hand, it simplifies dual-threshold detection into a single-threshold detection problem.
[0200] Detection probability verification:
[0201] In one embodiment, a false alarm probability of 10% is preset, and the upper and lower limits of the AOSTL detection quantity are calculated to further calculate the detection probability. To clearly reflect the change of the detection probability over time, a sliding window method is used to calculate the detection probability. Taking PRN3 as an example, the detection probability results of the four algorithms Delta, Ratio, ELP, and AOSTL are as follows: Figure 10 , Figure 11 and Figure 12 As shown, Figure 10 A diagram showing the comparison of detection probabilities for AOSTL Level 1 detection quantities for PRN3 satellites. Figure 11 A diagram showing the comparison of detection probabilities for AOSTL Level 1 detection quantities for PRN6 satellites. Figure 12 A diagram showing the comparison of detection probabilities for AOSTL Level 1 detection quantities for satellites numbered PRN19.
[0202] After 110 seconds, the detection probability of both AOSTL and Ratio exceeded 50%, but AOSTL's detection probability exceeded 50% more immediately. Unlike AOSTL and Ratio, the detection probabilities of ELP and Delta were mostly below 50% throughout the entire time. Compared with Delta, Ratio, and ELP algorithms, the AOSTL algorithm has the best detection timeliness and the widest detection range.
[0203] To further analyze the detection performance of the moving variance detectors, moving variance processing was applied to the Ratio, Delta, ELP, and AOSTL detectors. A fixed window length of ω = 25 ms was used, and the average value of the original detectors within the window was calculated as the detection probability curve for new data points. Taking PRN3 as an example, the detection probability curves are shown in Figures 13(a), 13(b), and 13(c). Figure 13(a) is a comparison of the detection probabilities of the AOSTL-MV secondary detectors for PRN3 satellites; Figure 13(b) is a comparison of the detection probabilities of the AOSTL-MV secondary detectors for PRN6 satellites; and Figure 13(c) is a comparison of the detection probabilities of the AOSTL-MV secondary detectors for PRN19 satellites.
[0204] Comparative analysis shows that, between 110s and 400s, the detection probability of AOSTL-MV is greater than 50% starting from 120s, and remains above 90% for the vast majority of the time after 200s; the detection probability of Ratio-MV starts to be greater than 50% around 180s, but fluctuates drastically; the detection probabilities of Delta-MV and ELP-MV are mostly less than 50%.
[0205] In summary, compared to the Delta, Ratio, and ELP algorithms, the AOSTL algorithm detects spoofing attacks more instantly. After MV processing enhancement, the AOSTL-MV algorithm can detect spoofing even more instantly, with a higher detection probability. Compared to the Delta-MV, Ratio-MV, and ELP-MV algorithms, AOSTL-MV has a higher detection probability, wider detection range, and better detection immediacy; compared to the AOSTL algorithm, the AOSTL-MV algorithm has better detection immediacy and a higher detection probability.
[0206] Based on binary decision, if the detection probability is not less than 50%, it is judged as spoofing and outputs 1; otherwise, it is judged as no spoofing interference and outputs 0. Taking PRN3 as an example, the binary decision results of four algorithms, Delta-MV, Ratio-MV, ELP-MV and AOSTL-MV, are shown in Figure 14. Among them, Figure 14(a) is a schematic diagram of the binary decision result of AOSTL-MV, Figure 14(b) is a schematic diagram of the binary decision result of Ratio-MV, Figure 14(c) is a schematic diagram of the binary decision result of ELP-MV, and Figure 14(d) is a schematic diagram of the binary decision result of Delta-MV.
[0207] As shown in Figure 14, the number of times AOSTL-MV judged as 1 was significantly higher than that of Ratio-MV, ELP-MV, and Delta-MV. After the spoofing injection occurred at 110 s, AOSTL-MV judged all instances of spoofing from 120 to 400 s, and the number of judgments was significantly higher than the other four MV algorithms. Ratio-MV only judged as 1 after 180 s, and the instances of 0 and 1 appeared alternately. Unlike AOSTL-MV and Ratio-MV, ELP-MV and Delta-MV showed serious misjudgments, indicating that the detection algorithms failed.
[0208] With ω set to 25ms, 50ms, 100ms, 200ms, and 400ms respectively, to evaluate the effect of ω on the detection probability of AOSTL-MV, the deception detection probability results are as follows: Figure 15 As shown.
[0209] Comparative experimental results show that as the sliding window length increases, the fluctuation trend of AOSTL-MV detection probability decreases; however, as ω increases, the real-time performance of the AOSTL-MV algorithm deteriorates. In the AOSTL-MV algorithm, choosing an appropriate window length can improve the probability of spoofing detection while simultaneously detecting spoofing attacks in real time.
[0210] To further analyze the deception detection performance of the detection quantity under arbitrary false alarm probabilities, a Receiver Operating Characteristic (ROC) curve is introduced. In the graph, the horizontal axis represents the false alarm probability, and the vertical axis represents the average detection probability between 110s and 400s. The closer the ROC curve is to the upper left corner, the more accurate the detection. Taking PRN3 as an example, the ROC curves for AOSTL-MV, Delta-MV, Ratio-MV, and ELP-MV are shown below. Figure 16 As shown, Figure 16 This is a diagram illustrating the comparison of ROC curves.
[0211] Depend on Figure 16As can be seen, when the false alarm probability is 10%, the detection probabilities of AOSTL-MV, Ratio-MV, Delta-MV, and ELP-MV are 86.4%, 68.5%, 29.4%, and 20.7%, respectively; AOSTL-MV has a higher detection rate compared to the other algorithms. Under any false alarm probability, the detection probability of AOSTL-MV is consistently higher than that of the other traditional algorithms. The lower the false alarm probability, the closer AOSTL-MV's detection probability is to the top left corner of the ROC plot compared to other algorithms, indicating that AOSTL-MV has the highest detection accuracy.
[0212] Furthermore, this embodiment of the invention also proposes a computer-readable storage medium storing a high-complexity GNSS induced deception detection program, which, when executed by a processor, implements the steps of the high-complexity GNSS induced deception detection method described above.
[0213] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0214] The aforementioned computer-readable storage medium may be included in a high-complexity GNSS deception detection device; or it may exist independently and not be assembled into a high-complexity GNSS deception detection device.
[0215] Furthermore, this invention also proposes a computer program product, including a high-complexity GNSS induced deception detection program, which, when executed by a processor, implements the steps of the high-complexity GNSS induced deception detection method as described above.
[0216] The specific implementation of the computer program product of this invention is basically the same as the embodiments of the above-described high-complexity GNSS induced deception detection method, and will not be repeated here.
[0217] Reference Figure 17 , Figure 17 This is a structural block diagram of the first embodiment of the high-complexity GNSS induced deception detection device of the present invention.
[0218] like Figure 17 As shown, the high-complexity GNSS induced deception detection device proposed in this embodiment of the invention includes:
[0219] The signal tracking and monitoring module 10 is used to call the GNSS receiver to track and monitor multiple GNSS satellite signals with the same frequency and phase.
[0220] The first-level detection quantity construction module 20 is used to construct the AOSTL first-level detection quantity of each GNSS satellite signal based on the absolute value of the output result of the tracking loop of the GNSS receiver. The output result of the tracking loop includes the output results of the instantaneous correlator, the lead correlator, and the lag correlator of the in-phase branch and the quadrature branch. The AOSTL first-level detection quantity is expressed as:
[0221] AOSTL = |I E |+|I P |+|I L |+|Q E |+|Q P |+|Q L |
[0222] Where AOSTL represents the AOSTL Level 1 detection quantity, I P Q represents the output of the instantaneous correlator of the in-phase branch. P I represents the output of the instantaneous correlator of the orthogonal branch. E Q represents the output of the lead correlator in the in-phase branch. E I represents the output of the lead correlator of the orthogonal branch. L Q represents the output of the hysteresis correlator in the in-phase branch. L This represents the output of the hysteresis correlator for the orthogonal branch;
[0223] Gaussian distribution verification module 30 is used to perform Gaussian distribution verification on the AOSTL first-level detection quantity;
[0224] The secondary detection quantity construction module 40 is used to construct the AOSTL-MV secondary detection quantity by performing sliding variance processing on the AOSTL primary detection quantity in response to the fact that the AOSTL primary detection quantity follows a Gaussian distribution.
[0225] The detection probability calculation module 50 is used to determine the detection threshold based on the Gaussian distribution characteristics and calculate the detection probability based on the detection threshold.
[0226] The deception decision module 60 is used to perform binary decision on each GNSS satellite signal based on the detection probability and the AOSTL-MV secondary detection quantity, and obtain a binary decision result. The binary decision result is used to determine whether there is deception interference in the GNSS satellite signal.
[0227] This embodiment tracks and monitors multiple in-phase and in-frequency GNSS satellite signals using a GNSS receiver. Based on the absolute values of the tracking loop outputs of the GNSS receiver, AOSTL Level 1 detection parameters for each GNSS satellite signal are constructed. The tracking loop outputs include the instantaneous correlator outputs, lead correlator outputs, and lag correlator outputs of the in-phase and quadrature branches. The AOSTL Level 1 detection parameters are verified using a Gaussian distribution. Since the AOSTL Level 1 detection parameters follow a Gaussian distribution, a detection threshold is determined based on the Gaussian distribution characteristics. The detection probability is calculated based on the detection threshold. A binary decision is then made on each GNSS satellite signal based on the detection probability and the AOSTL-MV secondary detection quantity to obtain a binary decision result. This binary decision result is used to determine whether GNSS satellite signals exhibit deception interference. Since this invention constructs the detection quantity based on the absolute values of the correlator outputs of the in-phase and quadrature branches of the tracking loop, it ensures that the detection quantity is not affected by carrier synchronization, thereby improving the detection sensitivity of deception signals and enabling accurate detection of deception signals that are in phase and frequency with the real signal, thus improving the performance of covert deception detection.
[0228] The high-complexity GNSS induced deception detection device provided in this application, employing the high-complexity GNSS induced deception detection method described in the above embodiments, can solve the technical problem of high-complexity GNSS induced deception detection. Compared with the prior art, the beneficial effects of the high-complexity GNSS induced deception detection device provided in this application are the same as those of the high-complexity GNSS induced deception detection method described in the above embodiments, and other technical features in the high-complexity GNSS induced deception detection device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.
[0229] It should be understood that the above are merely illustrative examples and do not constitute any limitation on the technical solutions of the present invention. In specific applications, those skilled in the art can make settings as needed, and the present invention does not impose any restrictions on this.
[0230] It should be noted that the workflow described above is merely illustrative and does not limit the scope of protection of this invention. In practical applications, those skilled in the art can select some or all of the workflow to achieve the purpose of this embodiment according to actual needs, and no restrictions are imposed here.
[0231] In addition, for technical details not described in detail in this embodiment, please refer to the high-complexity GNSS induced deception detection method provided in any embodiment of the present invention, which will not be repeated here.
[0232] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.
[0233] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0234] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as read-only memory / random access memory, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0235] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.
Claims
1. A highly complex GNSS induced deception detection method, characterized in that, The highly complex GNSS induced deception detection method includes: The GNSS receiver is used to track and monitor multiple GNSS satellite signals that are in the same frequency and phase. The AOSTL first-order detection quantity for each GNSS satellite signal is constructed based on the absolute value of the output of the tracking loop of the GNSS receiver. The output of the tracking loop includes the output of the instantaneous correlator, the output of the lead correlator, and the output of the lag correlator for the in-phase and quadrature branches. The AOSTL first-order detection quantity is expressed as follows: in, This indicates the AOSTL Level 1 detection capacity. This represents the output of the instantaneous correlator for the in-phase branch. This represents the output of the instantaneous correlator of the orthogonal branch. This represents the output of the lead correlator in the in-phase branch. This represents the output of the lead correlator in the orthogonal branch. This represents the output of the hysteresis correlator in the in-phase branch. This represents the output of the hysteresis correlator for the orthogonal branch; The Gaussian distribution of the AOSTL primary detection quantity was verified. In response to the fact that the AOSTL primary detection quantity follows a Gaussian distribution, the AOSTL primary detection quantity is processed by sliding variance to construct the AOSTL-MV secondary detection quantity; The detection threshold is determined based on the Gaussian distribution characteristics, and the detection probability is calculated based on the detection threshold. Based on the detection probability and the AOSTL-MV secondary detection quantity, a binary decision is made on each GNSS satellite signal to obtain a binary decision result. The binary decision result is used to determine whether the GNSS satellite signal is being spoofed or interfered with. The step of performing sliding variance processing on the AOSTL primary detection quantity to construct the AOSTL-MV secondary detection quantity includes: The AOSTL primary detection quantity is processed using sliding variance to construct the AOSTL-MV secondary detection quantity, which is expressed as follows: in, Indicates the length of the moving average window. Indicates the number of sliding windows. Indicates the sliding interval. This represents the th after processing with sliding variance. The AOSTL-MV secondary detection quantity corresponding to each sliding window Indicates the sliding window index. This represents the AOSTL Level 1 detection volume index.
2. The high-complexity GNSS induced deception detection method as described in claim 1, characterized in that, The Gaussian distribution verification of the AOSTL first-level detection quantity includes: A skewness function is constructed, and the sample skewness of the AOSTL Level 1 detection quantity is determined based on the skewness function. The skewness function is expressed as follows: in, Indicates sample skewness. Indicates the number of sample points. Indicates the first Sample values of AOSTL Level 1 detection quantity. Indicates sample The mean; The symmetry of the probability density function of the AOSTL first-level detection quantity is verified based on the sample skewness. Construct an excess kurtosis function, and determine the sample excess kurtosis of the AOSTL Level 1 detection quantity based on the excess kurtosis function. The excess kurtosis function is expressed as: in, Indicates the excess kurtosis of the sample; The tail thickness of the probability density function of the AOSTL Level 1 detection quantity is quantified based on the excess peak of the sample. Gaussian distribution verification was performed based on the symmetry of the probability density function and the tail thickness of the AOSTL first-level detection quantity.
3. The high-complexity GNSS induced deception detection method as described in claim 2, characterized in that, The determination of the detection threshold based on Gaussian distribution features includes: The probability density function of the AOSTL first-level detection quantity is constructed based on the Gaussian distribution characteristics: in, This represents the probability density function of the AOSTL Level 1 detection quantity. and Let represent the mean and variance of the AOSTL Level 1 detections, respectively, indicating that they follow a Gaussian distribution, and let represent the exponential function. Auxiliary variables representing the AOSTL primary detection quantity; The detection threshold is determined based on the probability density function following a Gaussian distribution and the preset false alarm probability of the AOSTL Level 1 detection quantity. The detection threshold includes an upper detection limit and a lower detection limit, and is expressed as follows: in, Indicates the upper limit of detection. Indicates the lower limit of detection. Represents the inverse Gaussian function. Indicates the detection threshold relative to the mean. The offset, The standard deviation represents the distribution following a Gaussian distribution. This represents the preset false alarm probability of AOSTL Level 1 detection.
4. The high-complexity GNSS induced deception detection method as described in claim 3, characterized in that, The calculation of the detection probability based on the detection threshold includes: A dual-threshold detection function is constructed based on the probability density function of the AOSTL first-level detection quantity following a Gaussian distribution. The dual-threshold detection function is expressed as follows: Wherein, represents the detection probability of AOSTL Level 1 detection quantity. Represents the probability density function. This indicates that there was no deception or interference. This indicates deception and interference. This represents the probability density function without deception. This represents the probability density function when deception occurs. Auxiliary variables representing the AOSTL primary detection quantity; The AOSTL first-level detection quantity is detected based on the detection threshold and the dual-threshold detection function, and the detection probability is calculated.
5. The high-complexity GNSS induced deception detection method as described in claim 4, characterized in that, The step of detecting the AOSTL first-level detection quantity based on the detection threshold and the dual-threshold detection function, and calculating the detection probability, includes: Construct a statistical function, and based on the statistical function, the detection threshold, and the dual-threshold detection function, perform detection on the AOSTL first-level detection quantity, and calculate the detection probability, referring to the following formula: in, This indicates the total number of samples in the window. This represents a statistical function.
6. The high-complexity GNSS induced deception detection method as described in claim 1, characterized in that, The calculation of the detection probability based on the detection threshold also includes: Obtain the preset false alarm probability of the AOSTL-MV secondary detection quantity, and determine the detection threshold based on the preset false alarm probability. The function relating the preset false alarm probability and the detection threshold is expressed as: in, This represents the total number of samples for AOSTL-MV secondary detection when there is no interference. This indicates the detection threshold for the secondary detection quantity of AOSTL-MV. Represents a statistical function. This represents the preset false alarm probability of the AOSTL-MV secondary detection quantity; The AOSTL-MV secondary detection quantity is detected based on the aforementioned detection threshold to obtain the detection probability: in, This represents the detection probability of the AOSTL-MV secondary detection quantity. This represents the number of samples within the sliding window.
7. A high-complexity GNSS induced deception detection device applying the high-complexity GNSS induced deception detection method as described in any one of claims 1 to 6, characterized in that, The highly complex GNSS-induced deception detection device includes: The signal tracking and monitoring module is used to call the GNSS receiver to track and monitor multiple GNSS satellite signals of the same frequency and phase. The first-level detection quantity construction module is used to construct the AOSTL first-level detection quantities of each GNSS satellite signal based on the absolute value of the output result of the tracking loop of the GNSS receiver. The output result of the tracking loop includes the output results of the instantaneous correlator, the lead correlator, and the lag correlator of the in-phase branch and the quadrature branch. The AOSTL first-level detection quantity is expressed as: in, This indicates the AOSTL Level 1 detection capacity. This represents the output of the instantaneous correlator for the in-phase branch. This represents the output of the instantaneous correlator of the orthogonal branch. This represents the output of the lead correlator in the in-phase branch. This represents the output of the lead correlator in the orthogonal branch. This represents the output of the hysteresis correlator in the in-phase branch. This represents the output of the hysteresis correlator for the orthogonal branch; A Gaussian distribution verification module is used to perform Gaussian distribution verification on the AOSTL first-level detection quantity; The secondary detection quantity construction module is used to construct the AOSTL-MV secondary detection quantity by performing sliding variance processing on the AOSTL primary detection quantity in response to the fact that the AOSTL primary detection quantity follows a Gaussian distribution. The detection probability calculation module is used to determine the detection threshold based on the Gaussian distribution characteristics, and to calculate the detection probability based on the detection threshold. The deception decision module is used to perform binary decision on each GNSS satellite signal based on the detection probability and the AOSTL-MV secondary detection quantity, and obtain a binary decision result. The binary decision result is used to determine whether there is deception interference in the GNSS satellite signal.
8. A highly complex GNSS-induced deception detection device, characterized in that, The high-complexity GNSS induced deception detection device includes: a memory, a processor, and a high-complexity GNSS induced deception detection program stored in the memory. The processor is used to run the high-complexity GNSS induced deception detection program, which is configured to implement the high-complexity GNSS induced deception detection method as described in any one of claims 1 to 5.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a high-complexity GNSS induced deception detection program, which, when executed by a processor, implements the high-complexity GNSS induced deception detection method as described in any one of claims 1 to 5.