Networked control system spoofing attack detection method, equipment and medium
By deploying dual detectors at the remote control center and the controlled object, and combining Kalman filter residuals with chi-square test, dual detection and automatic switching of the networked control system are achieved. This solves the problem that single detection is easily bypassed in existing technologies, and improves the security and stability of the system.
Patent Information
- Application Number
- CN202511568791.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-30
- Publication Date
- 2026-01-09
AI Technical Summary
Existing methods for detecting deception attacks mainly rely on central detectors in remote control centers, which are easily bypassed and lack local detection mechanisms. They cannot form multi-layered defenses and lack effective countermeasures after detection, resulting in insufficient system stability.
A central detector and a local detector are deployed at the remote control center and the controlled object, respectively. Anomaly detection is achieved through Kalman filter residuals and chi-square test. A collaborative alarm and switching mechanism is designed to automatically switch to the control signal generated by the local controller to ensure stable system operation.
It significantly improves the system's ability to defend against deception attacks, ensuring that it immediately switches to local control mode when an attack is detected, preventing continuous damage and ensuring that system performance remains unchanged.
Smart Images

Figure FT_1 
Figure FT_2 
Figure FT_3
Abstract
Description
Technical Field
[0001] This application relates to the field of networked control system deception attack detection, and in particular to a method, device and medium for detecting networked control system deception attacks. Background Technology
[0002] Spoofing attacks are a common form of cyberattack, primarily involving the injection of false data or the replay of historical data to tamper with transmitted information, thereby compromising its integrity. Compared to other attack methods, spoofing attacks are not only more destructive but also more covert, posing a serious threat to the secure operation of networked control systems. Therefore, researching efficient methods for detecting spoofing attacks has significant theoretical and engineering value.
[0003] However, existing methods for detecting deception attacks still have some limitations. First, most detection methods rely primarily on a central detector in a remote control center to identify potential attacks. Once an attacker successfully bypasses the central detector and gains control of the central controller, they can continuously damage the system without the system being able to detect and respond in a timely manner. Second, existing methods lack supplementary mechanisms for local detection on the controlled target, failing to form a multi-layered defense system. Finally, once an attack is detected, existing methods often lack effective countermeasures, failing to guarantee the continued stable operation of the system under attack conditions.
[0004] Therefore, there is an urgent need for a dual detection method that can simultaneously detect at the remote control center and the controlled object, in order to improve the system's resistance to deception attacks and automatically switch to a safe mode after an attack is detected, so as to ensure the continuous and stable operation of the system. Summary of the Invention
[0005] To address the shortcomings of existing technologies, this invention proposes a method, device, and medium for detecting spoofing attacks in networked control systems. First, a residual-based central detector is deployed at a remote control center to monitor received sensor measurement data. Second, a local detector is added at the controlled object, forming a complementary mechanism with the central detector to effectively detect spoofing attacks. Simultaneously, a collaborative alarm and switching mechanism is designed, combining the outputs of the central and local detectors. When either the central or local detector detects an attack, the system automatically switches to the control signal generated by the local controller, achieving closed-loop stable operation solely based on local state estimation.
[0006] The technical solution of the present invention is as follows: A method for detecting deception attacks on networked control systems includes the following steps: S1: In the remote control center, a remote central controller is set up. Based on the received sensor measurement data, the system state is estimated through the remote central state estimator, and a central control signal is generated. S2: Deploy a central detector in a remote control center. The central detector detects anomalies based on Kalman filter residuals and chi-square test. S3: On the physical object side, a local controller is set up to receive the central control signal from the remote control center, perform independent system state estimation based on local sensor measurement data through a local state estimator, and generate a local control signal; S4: Deploy a local detector at the controlled object end. The local detector independently generates residuals using remotely sent control signals and local sensor data, and uses the chi-square test to achieve anomaly detection.
[0007] Specifically, the remote central controller includes: First, the feedback control law of the central controller I is designed as follows: (1) in, The posterior state estimate given by the center Kalman filter, In order to make Stable feedback gain matrix.
[0008] Secondly, in order to track the reference signal The integral control law design for central controller II is as follows: (2) in, The system outputs tracking error. This is the integral gain matrix.
[0009] The control signals of the remote control center are (3) Specifically, the remote central state estimator includes: Construct the following Kalman filter: (4) in, This represents the prior state estimate of the system. The Kalman filter gain matrix represents the posterior state estimate of the system. The following Riccati equation is obtained by solving: (5) Specifically, the central detector includes: Based on the Kalman filter, the system residuals can be obtained: (6) It follows a mean of 0 and a covariance of The Gaussian distribution is used to establish the detection variables: (7) when If the detection threshold is exceeded, the detector will issue an alarm.
[0010] Specifically, the local controller includes: Local control signals are designed as (8) in, This provides the posterior state estimate for the local Kalman filter. Local control signal. With remote distribution Addition, as the actual input of the physical object ,Right now (9) Under normal circumstances, The system performance remains unchanged.
[0011] Specifically, the local state estimator includes: Build a local state estimator: (10) in, and These represent the prior and posterior state estimates of the system given by the local Kalman filter, respectively.
[0012] Specifically, local detectors include: Using control signals issued by the remote center Compared with locally collected sensor data Construct the following local residual Generator: (11) in, and These represent the intermediate variables of the residual generator. Under normal circumstances, Local residuals It follows a mean of 0 and a covariance of The Gaussian distribution is used to establish the detection variables: (12) when If the detection threshold is exceeded, the detector will issue an alarm.
[0013] Specifically, linear discrete objects include: (13) in, Indicates the state of the controlled object. Indicates control input, Indicates the sensor measurement output; The system process noise is represented by a value of 0 and a covariance of . Gaussian distribution; The sensor measurement noise is represented by a mean of 0 and a covariance of . Gaussian distribution; parameters and noise covariance matrix Set as .
[0014] The beneficial effects of this invention are as follows: By forming a complementary mechanism of remote central detection and local detection, even if an attacker bypasses the central detector, the local detector can still detect the attack, significantly improving system security; in the absence of an attack, the control signals of the central controller and the local controller are consistent, ensuring that system performance remains unchanged; when an attack occurs, the residuals of both the central detector and the local detector are related to the attack injection signal in the control channel, thereby achieving effective detection; once an attack is detected, the system immediately disconnects the remote channel, relying solely on the local controller to maintain stable operation, preventing the attack from continuously damaging the system; through the dual detection structure, the defense capability of the networked control system against deception attacks is significantly improved, solving the security vulnerability of the single detection mechanism in the prior art, which is easily bypassed. Attached Figure Description
[0015] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0016] Figure 1 A schematic diagram of a dual detection method for deception attacks on a networked control system; Figure 2 This is the system output response diagram when the dual-detection scheme is not used; Figure 3 The response diagram of the central detector when the dual-detection scheme is not used; Figure 4 The response diagram of the central detector when using a dual-detection scheme; Figure 5 This is a graph showing the response of the local detector when using a dual-detection scheme. Figure 6 This is the system output response diagram when using a dual-detection scheme. Detailed Implementation
[0017] The specific simulation environment for this invention is: Windows 11 (64-bit) and Matlab R2020b. In this simulation, we consider the following linear discrete-time controlled object:
[0018] in, Indicates the state of the controlled object. Indicates control input, Indicates the sensor measurement output; The system process noise is represented by a value of 0 and a covariance of . Gaussian distribution; The sensor measurement noise is represented by a mean of 0 and a covariance of . Gaussian distribution; parameters and noise covariance matrix Set as
[0019] According to formula (6), the Kalman filter gain matrix is calculated as follows:
[0020] Controller gain matrix and Set as
[0021] The simulation time interval is set to Reference input signal Set as
[0022] Injecting attack signals into the control channel and Set as and Injecting attack signals into the sensor channel. Set as
[0023] in, This is an intermediate variable. The attack initiation range is set as follows: .
[0024] Figures 2-3 This shows the system response when the dual-detection scheme is not used. From... Figure 2 It can be seen that under normal circumstances, the system output can track the reference signal, but when an attack occurs, the system output diverges, and the tracking performance is compromised. From... Figure 3 As can be seen from the central testing indicators The difficulty in distinguishing system anomalies means that such attacks can successfully bypass the central detector. Therefore, without a detection solution, this attack will severely damage system performance.
[0025] Figures 4-5 The performance of the developed dual detection method is demonstrated. Clearly, under attack conditions, the detection metrics of the central detector and the local detector are significantly improved. and The results are significantly higher than those under normal conditions. These results directly confirm that the developed dual detection method enables both the central detector and the local detector to successfully detect the attack. Furthermore, Figure 6 The system output is shown when the network is disconnected after an attack is detected. It is clear that the local controller ensures system stability.
[0026] A networked control device includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps of the dual detection method for spoofing attacks in a networked control system as described in Embodiment 1.
[0027] This networked control device can be installed at a remote control center or on the controlled object to perform dual detection and defense against spoofing attacks. The processor in the device can be a general-purpose CPU, DSP, or application-specific integrated circuit, and the memory can include ROM, RAM, flash memory, etc., to store the computer program required to implement the dual detection method.
[0028] When the device is installed in a remote control center, the processor executes a computer program to implement the remote control center functions described in Embodiment 1, including center state estimation, center control signal generation, and anomaly detection functions of the center detector.
[0029] When the device is installed on the controlled object, the processor executes a computer program to implement the local control functions described in Embodiment 1, including local state estimation, local control signal generation, and anomaly detection functions of the local detector.
[0030] The networked control device also includes a communication interface for data transmission between the remote control center and the controlled object. Under normal circumstances, the device transmits control signals and sensor data through this communication interface; upon detecting an attack, the device can automatically disconnect the remote channel and switch to local control mode.
[0031] In a preferred embodiment, the device is also equipped with a real-time monitoring module that visually displays the system's operating status and detection indicators, facilitating operators to monitor the system's safety status in real time.
[0032] This networked control device implements the dual detection method described in Example 1 through hardware. Compared with the pure software implementation, it has higher real-time performance and reliability, and can more effectively deal with the threat of deception attacks in networked control systems.
[0033] This embodiment provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of a dual detection method for spoofing attacks in a networked control system.
[0034] Computer-readable storage media can be any usable medium accessible to a computer, or a data storage device such as a server or data center that integrates one or more usable media. Usable media can be magnetic media (such as hard disks, floppy disks, and magnetic tapes), optical media (such as DVDs, CD-ROMs, and optical discs), electronic media (such as solid-state drives, flash drives, and memory cards), etc. The computer program stored on the storage medium can be a set of instructions or code that, when executed on a processor, causes the processor to perform the steps of the dual detection method for spoofing attacks in a networked control system described in Embodiment 1.
[0035] When executed by the processor, the computer program implements steps S1 to S7 of the dual detection method for deception attacks in a networked control system described in Embodiment 1. These steps include: estimating the system state based on sensor measurement data and generating a central control signal at the remote control center; deploying a central detector based on Kalman filter residuals and chi-square test; performing independent system state estimation based on local sensor measurement data and generating a local control signal at the physical object side; deploying a local detector; maintaining consistency between the control signals generated by the central controller and the local controller under normal conditions; detecting deception attacks through the detection indicators of the central detector and the local detector when an attack occurs; and switching to local control mode to disconnect the remote channel when an attack is detected.
[0036] The computer program also includes all the algorithms and computational processes for implementing the linear discrete-time controlled object model, remote central controller design, remote state estimator design, central detector design, local controller design, local state estimator design, local detector design, deception attack modeling, and attack detection and defense described in Embodiment 1.
[0037] The computer program can be written in any suitable programming language, such as C, C++, Java, Python, etc., and can be distributed as a standalone software product or integrated into the control software of a networked control system as part of other software products. The computer program can be installed on the server at the remote control center and on the local controller on the physical object side, respectively executing the corresponding functional modules.
[0038] In a preferred embodiment, the computer-readable storage medium may be a cloud storage server, and the computer program is distributed to a remote control center and a local controller via a network to enable remote updates and maintenance of the system.
[0039] In another preferred embodiment, the computer-readable storage medium can be integrated into the programmable logic controller (PLC) or distributed control system (DCS) of the industrial control system as a core component for system security protection.
[0040] When executed, this computer program can automatically adjust the Kalman filter parameters and detection thresholds according to the characteristics of different networked control systems, thereby improving detection accuracy and system adaptability.
Claims
1. A method for detecting deception attacks on networked control systems, characterized in that, Includes the following steps: S1: In the remote control center, a remote central controller is set up. Based on the received sensor measurement data, the system state is estimated through the remote central state estimator, and a central control signal is generated. S2: Deploy a central detector in a remote control center. The central detector detects anomalies based on Kalman filter residuals and chi-square test. S3: On the physical object side, a local controller is set up to receive the central control signal from the remote control center, perform independent system state estimation based on local sensor measurement data through a local state estimator, and generate a local control signal to control the linear discrete object. S4: Deploy a local detector at the controlled object end. The local detector independently generates residuals using remotely sent control signals and local sensor data, and uses the chi-square test to achieve anomaly detection.
2. The method for detecting deception attacks on networked control systems according to claim 1, characterized in that: Remote central controller, including: First, the feedback control law of the central controller I is designed as follows: ; in, The posterior state estimate given by the center Kalman filter, In order to make A stable feedback gain matrix; Secondly, in order to track the reference signal The integral control law design for central controller II is as follows: ; in, The system outputs tracking error. This is the integral gain matrix; The control signals of the remote control center are 。 3. The method for detecting deception attacks on networked control systems according to claim 1, characterized in that: The remote central state estimator includes: Construct the following Kalman filter: ; in, This represents the prior state estimate of the system. The Kalman filter gain matrix represents the posterior state estimate of the system. The following Riccati equation is obtained by solving: 。 4. The method for detecting deception attacks on networked control systems according to claim 1, characterized in that: The central detector includes: Based on the Kalman filter, the system residuals can be obtained: ; It follows a mean of 0 and a covariance of The Gaussian distribution is used to establish the detection variables: ; when If the detection threshold is exceeded, the detector will issue an alarm.
5. The method for detecting deception attacks on networked control systems according to claim 1, characterized in that: Local controller, including: Local control signals are designed as ; in, The posterior state estimate given by the local Kalman filter, and the local control signal. With remote distribution Addition, as the actual input of the physical object ,Right now ; Under normal circumstances, The system performance remains unchanged.
6. The method for detecting deception attacks on networked control systems according to claim 1, characterized in that: The local state estimator includes: Build a local state estimator: ; in, and These represent the prior and posterior state estimates of the system given by the local Kalman filter, respectively.
7. The method for detecting deception attacks on networked control systems according to claim 1, characterized in that: Local detectors, including: Using control signals issued by the remote center Compared with locally collected sensor data Construct the following local residual Generator: ; in, and These represent the intermediate variables of the residual generator. Under normal circumstances, Local residuals It follows a mean of 0 and a covariance of The Gaussian distribution is used to establish the detection variables: ; when If the detection threshold is exceeded, the detector will issue an alarm.
8. The method for detecting deception attacks on networked control systems according to claim 1, characterized in that, Linear discrete objects: ; in, Indicates the state of the controlled object. Indicates control input, Indicates the sensor measurement output; The system process noise is represented by a value of 0 and a covariance of . Gaussian distribution; The sensor measurement noise is represented by a mean of 0 and a covariance of . Gaussian distribution; parameters and noise covariance matrix Set as 。 9. A networked control device, comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method as described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 7.