A dynamic identity authentication method for a UAV group control communication system

By collecting and analyzing multi-dimensional data on UAV flight trajectories and communication modes, and combining clustering and anomaly detection, the threshold is adaptively adjusted to achieve dynamic identity authentication in the UAV swarm control and communication system. This solves the challenge of identity authentication in dynamic environments and improves the security and reliability of the system.

CN121367916BActive Publication Date: 2026-07-21GUANGZHOU YOUFEI INTELLIGENT EQUIP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GUANGZHOU YOUFEI INTELLIGENT EQUIP CO LTD
Filing Date
2025-12-05
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing drone swarm communication systems struggle to achieve real-time comparison of drone behavior characteristics and dynamic matching of historical identity files in dynamic environments, resulting in the failure to detect identity spoofing risks in a timely manner. Existing methods, which rely on static identifiers, cannot cope with environmental changes and external interference.

Method used

By collecting flight trajectory and communication mode data of drones through sensors, and using timed sampling and noise filtering, combined with clustering algorithms and isolated forest separation, potential deviations are identified; by using anomaly detection and decision tree algorithms, thresholds are adaptively adjusted, and multi-factor comparison and path tracking are performed to achieve dynamic identity authentication.

Benefits of technology

It achieves high-precision verification of UAV identity in complex environments and long-term missions, improves the security and robustness of the swarm control system, can distinguish between external interference and abnormal camouflage, and enhances the anti-forgery and anti-tampering capabilities of the UAV swarm control communication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121367916B_ABST
    Figure CN121367916B_ABST
Patent Text Reader

Abstract

The application discloses a kind of dynamic identity authentication methods for unmanned aerial vehicle group control communication system, it is related to unmanned aerial vehicle group control and information security technical field, including S1, the flight trajectory and communication mode data of unmanned aerial vehicle are collected by sensor, multi-dimensional information is handled using timing sampling method, noise filtering mechanism and real-time stream processing are simultaneously integrated, and real-time behavior characteristic vector is obtained;S2, according to real-time behavior characteristic vector, clustering algorithm is used to group data points, and on the basis of grouping, isolation forest separation is applied to preliminarily identify potential deviation, to determine the current behavior mode classification;S3, if the current behavior mode classification matches the historical record within the preset threshold, obtain the matching degree score, and calculate the difference vector through deviation vector analysis, to obtain the behavior deviation index;The dynamic identity authentication method for unmanned aerial vehicle group control communication system significantly enhances the anti-counterfeiting, tamper-proofing and intelligent management capabilities of the unmanned aerial vehicle group control communication system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of unmanned aerial vehicle (UAV) swarm control and information security technology, specifically to a dynamic identity authentication method for UAV swarm control communication systems. Background Technology

[0002] The widespread application of drone technology in logistics, agriculture, and emergency rescue makes identity management a crucial element in ensuring safety and efficiency. A drone's identity involves not only the unique identifier of the device itself but also the dynamic characteristics of its operational behavior, such as flight trajectory and communication patterns. Ensuring the consistency of this identity information in complex environments and during long-term operation is essential to preventing unauthorized intrusion, tampering, or spoofing.

[0003] However, current research and practice still have significant shortcomings in continuously monitoring the identity behavior of drones, and more sophisticated technical means are urgently needed to address the identity verification challenges in dynamic scenarios. Existing methods typically rely on static identity identifiers, such as device serial numbers or digital certificates. This approach is effective in fixed scenarios, but falls short in dynamic environments. Especially when multiple drones are operating collaboratively or running across regions for extended periods, environmental changes, equipment aging, or external interference can cause behavioral characteristics to deviate from expectations, making it difficult to accurately determine the authenticity of an identity by relying solely on static identifiers. Furthermore, existing solutions often lack continuous analysis of behavioral characteristics, failing to effectively capture the dynamic changes of drones at different times and in different scenarios, thus leading to the failure to detect potential identity spoofing risks in a timely manner. The core technical challenge lies in how to achieve real-time comparison of drone behavioral characteristics and dynamic matching with historical identity files. Real-time comparison of behavioral characteristics requires high-frequency collection and analysis of drone flight trajectories, communication frequencies, sensor data, etc., but the complexity and multidimensionality of this data pose significant challenges to real-time processing. Furthermore, the dynamic changes in behavioral characteristics are influenced by environmental factors, task types, and other factors, making the matching process with historical identity records more complex and difficult to accurately determine whether discrepancies are caused by legitimate factors or potential identity tampering. For example, when a drone flies between high-rise buildings in a city, signal interference may cause abnormal communication patterns, which may be misjudged as identity spoofing, or conversely, genuine spoofing may be ignored as environmental interference. Summary of the Invention

[0004] The purpose of this invention is to provide a dynamic identity authentication method for unmanned aerial vehicle (UAV) swarm control and communication systems, thereby solving the problems existing in the prior art.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a dynamic identity authentication method for a drone swarm communication system, comprising: S1, collecting drone flight trajectory and communication mode data through sensors, processing multi-dimensional information using a timed sampling method, and incorporating noise filtering and real-time stream processing to obtain a real-time behavior feature vector; S2, grouping data points according to the real-time behavior feature vector using a clustering algorithm, and applying isolated forest separation on the basis of grouping to initially identify potential deviations and determine the current behavior pattern classification; S3, if the current behavior pattern classification matches historical records within a preset threshold, obtaining a matching score, and calculating a difference vector through deviation vector analysis to obtain a behavior deviation index; S4, based on the behavior deviation index, employing an anomaly detection algorithm combined with local anomaly factors and... The change quantification index assesses the impact of environmental changes and determines the type of deviation source; S5, if the deviation source type is classified as external interference, similar scenario data is extracted from historical archives, and threshold adaptive adjustment and anomaly score output are incorporated to obtain the adjusted expected feature range; S6, the adjusted expected feature range is compared with the real-time behavioral feature vector, and the comparison results are processed using information gain splitting and multi-factor branching to determine the final consistency level; S7, based on the final consistency level, a decision tree algorithm is used to integrate conditional probability calculation and tree depth constraint processing for multi-factor conditions, while incorporating leaf node decision and pruning optimization processes to obtain the identity verification result; S8, based on the identity verification result, path tracing records are used to trace the deviation source type and the consistency level to determine the final verification reliability level; S4 includes: Through the data acquisition process, behavioral deviation indicators are obtained from environmental changes. The data acquisition process includes real-time capture of behavioral data by sensors and calculation of the difference between the deviation value and the benchmark value to obtain local anomaly factors. Based on local anomaly factors, an anomaly detection algorithm is used in combination with change quantification indicators. The anomaly detection algorithm takes local anomaly factors and quantification indicators as input and outputs an evaluation score. The environmental impact assessment is determined by comparing the calculated score with a preset threshold. Through environmental impact assessment, trend analysis is conducted, which includes tracking the time series of assessment scores and identifying rising or falling patterns to determine the type of source of deviation. The source type of deviation is obtained, and the index fusion method and factor calculation logic are integrated. The index fusion method uses a weighted average of the types and factors, and the factor calculation logic includes multiplying by weight coefficients to obtain the source classification rules. By using source classification rules and combining them with a real-time monitoring mechanism, which includes continuously verifying the matching of rules with new data, the environmental impact of behavioral deviation indicators can be determined.

[0006] Preferably, step S1 includes acquiring flight trajectory and communication mode data from the UAV via sensors, performing preliminary fusion of multi-dimensional information using a timed sampling method to obtain an initial data sequence; incorporating a noise filtering mechanism into the initial data sequence, applying low-pass filtering to remove high-frequency interference from data points to obtain a filtered clean sequence, and determining preliminary real-time behavior characteristics; continuously updating the filtered clean sequence through real-time stream processing, adjusting the sampling interval if the noise level exceeds a preset threshold to obtain a dynamic behavior sequence; performing data fusion quantization on the dynamic behavior sequence by combining path anomaly monitoring and signal strength assessment, merging trajectory deviation and signal fluctuation values ​​through weighted averaging to determine anomaly vector components; extracting trajectory optimization calculation elements from the anomaly vector components, correcting path points through linear interpolation, and obtaining a real-time behavior feature vector.

[0007] Preferably, step S2 includes acquiring behavioral feature vectors through real-time data acquisition, grouping the behavioral feature vectors using a clustering algorithm to obtain data point groups; applying an isolation forest to separate the data point groups, wherein the isolation forest randomly divides the data point groups by constructing multiple isolation trees until a single point is isolated, calculating the isolation path length to identify potential deviations and obtain deviation isolation results; judging behavioral patterns based on deviation isolation results, and determining abnormal behavioral patterns if the deviation exceeds a preset threshold; obtaining pattern classification details from abnormal behavioral patterns to determine the current behavioral pattern classification; and obtaining classification results output through the current behavioral pattern classification to form a behavioral pattern classification.

[0008] Preferably, step S3 includes: acquiring the current behavior pattern classification; retrieving matching items from historical records; evaluating the matching relationship through a preset threshold to obtain a matching score; parsing the deviation vector using the matching score; extracting vector components from the differences between the current pattern acquisition and the record retrieval; calculating the difference vector; quantifying the deviation index using the difference vector; determining the degree of behavior deviation by combining the deviation index quantification with the matching relationship evaluation; mapping the vector space for the degree of behavior deviation; fusing the results of deviation vector parsing from the vector space mapping to obtain a deviation relationship evaluation; generating a behavior deviation index based on the deviation relationship evaluation; and generating integrated details of the current pattern acquisition using the behavior deviation index.

[0009] Preferably, step S5 includes: if the source of the deviation is classified as external interference, extracting similar scene data from historical archives, calculating the arithmetic mean of each deviation item using the similar scene data to obtain an initial threshold range; for the initial threshold range, using a threshold adaptive adjustment method to fuse abnormal score outputs, the threshold adaptive adjustment method determines the dynamic threshold boundary by summing the scores and ranges after applying preset weights; based on the dynamic threshold boundary, obtaining current behavior indicator data, determining whether the data exceeds the boundary, and obtaining a boundary deviation index; and incorporating environmental noise filtering through the boundary deviation index, the environmental noise filtering subtracts a preset noise benchmark value from the current behavior indicator data to obtain the adjusted expected feature range.

[0010] Preferably, step S6 includes: obtaining a real-time behavioral feature vector through the adjusted expected feature range; generating a preliminary deviation value through secondary comparison; determining that the preliminary deviation value exceeds a preset threshold to obtain a comparison result set; calculating the information gain value of each factor using an information gain splitting method for the comparison result set, wherein the information gain splitting method determines the splitting point through an entropy reduction calculation formula to determine a high-gain factor sequence; performing multi-factor branching processing based on the high-gain factor sequence, extracting at least one dominant factor from the sequence, constructing a branch tree structure to obtain a branch decision path; incorporating deviation source type and external interference data into the branch decision path, wherein the deviation source type is extracted from historical archives, and the external interference data is obtained through similar scenario data; calculating a path consistency score, wherein the path consistency score is obtained by summing the path factors after applying weights; determining whether the score meets the final consistency level requirements to determine an intermediate consistency index; obtaining the intermediate consistency index, combining it with similar scenario data extracted from historical archives, wherein the similar scenario data is obtained by adjusting the threshold adaptively and fusing the abnormal score output; adjusting the boundary deviation index to obtain the final consistency level.

[0011] Preferably, step S7 includes: obtaining multi-factor conditions based on the final consistency level; extracting conditional probabilities from the multi-factor conditions; integrating the conditional probabilities using a decision tree algorithm, where the input to the decision tree algorithm is the conditional probabilities and the output is the integrated value; obtaining the probability integration value by calculating the joint distribution of the conditional probabilities; incorporating a tree depth constraint into the probability integration value; processing the multi-factor conditions by limiting the maximum level of the tree depth constraint to determine a depth control threshold; constructing leaf node decisions from the depth control threshold; integrating the leaf node decisions; determining whether the integration exceeds a preset threshold to obtain a node decision set; performing a pruning optimization process on the node decision set; extracting optimized pruning paths; determining the verification result basis by removing branches in the optimized pruning paths that contribute less than a preset threshold; obtaining the verification result basis; combining the consistency assessment and the obtained results; incorporating factor processing; the factor processing is derived from the multi-factor conditions; determining whether the factor processing meets the consistency assessment requirements to obtain the identity verification result.

[0012] Preferably, step S8 includes obtaining the deviation source type based on the authentication result, extracting the consistency level association from the deviation source type, using path tracing records to backtrack the consistency level association through layer-by-layer comparison to obtain the backtracked deviation source; for the backtracked deviation source, incorporating source type analysis to construct associated deviation types, and determining the deviation type association set by fusing the associated deviation types and consistency level association through item-by-item matching.

[0013] Preferably, step S8 further includes extracting record tracking paths from the deviation type association set, determining that the record tracking paths meet a preset threshold, and obtaining path tracking records; for the path tracking records, integrating horizontal association judgments, and if the horizontal association judgments exceed the preset threshold, adjusting the deviation source type through source type correction to obtain the adjusted deviation source; obtaining reliability determinations from the adjusted deviation sources, and combining them with the final level judgment to determine the final verification reliability level.

[0014] As can be seen from the above technical solution, the present invention has the following beneficial effects: This dynamic identity authentication method for UAV swarm control communication systems effectively overcomes the shortcomings of existing technologies that rely on static identifiers and cannot cope with identity verification failures in dynamic scenarios. By real-time acquisition, modeling, and comparison of multi-dimensional data on UAV flight trajectories and communication modes, combined with deviation detection, environmental factor assessment, and adaptive feature adjustment, continuous tracking and dynamic verification of UAV behavioral characteristics are achieved. This method not only maintains consistency and reliability of identity recognition in complex environments and long-duration tasks, but also distinguishes between external interference and abnormal spoofing, improving the security and reliability of multi-UAV collaborative operation in swarm control systems. This significantly enhances the anti-counterfeiting, anti-tampering, and intelligent management capabilities of UAV swarm control communication systems. Attached Figure Description

[0015] Figure 1 This is a flowchart of the dynamic identity authentication method for a drone swarm communication system according to the present invention. Detailed Implementation

[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0017] like Figure 1As shown, this invention provides a technical solution: a dynamic identity authentication method for a drone swarm communication system, comprising: S1, collecting drone flight trajectory and communication mode data through sensors, processing multi-dimensional information using a timed sampling method, and incorporating noise filtering and real-time stream processing to obtain a real-time behavior feature vector; S2, grouping data points according to the real-time behavior feature vector using a clustering algorithm, and applying isolated forest separation on the basis of grouping to initially identify potential deviations and determine the current behavior pattern classification; S3, if the current behavior pattern classification matches historical records within a preset threshold, obtaining a matching score, and calculating a difference vector through deviation vector analysis to obtain a behavior deviation index; S4, based on the behavior deviation index, employing an anomaly detection algorithm combined with local anomaly factors and changes... Quantitative indicators are used to assess the impact of environmental changes and determine the type of deviation source; S5. If the deviation source type is classified as external interference, similar scenario data is extracted from historical archives, and threshold adaptive adjustment and anomaly score output are incorporated to obtain the adjusted expected feature range; S6. The adjusted expected feature range is compared with the real-time behavioral feature vector, and the comparison results are processed using information gain splitting and multi-factor branching to determine the final consistency level; S7. Based on the final consistency level, a decision tree algorithm is used to integrate conditional probability calculation and tree depth constraint processing for multi-factor conditions, while incorporating leaf node decision and pruning optimization processes to obtain the identity verification result; S8. Based on the identity verification result, path tracing records are used to trace the deviation source type and the consistency level to determine the final verification reliability level.

[0018] This method constructs a dynamic behavior feature model based on the flight trajectory and communication mode characteristics of UAVs. First, through multi-sensor timed sampling and noise filtering, multi-dimensional feature information of the UAV during flight, such as speed changes, attitude angles, and communication frequency distribution, is extracted to form a real-time behavior feature vector. Then, a clustering algorithm is used to group and analyze the UAV's behavior features, and an isolated forest algorithm is used to detect potential anomalies, thereby identifying individuals exhibiting abnormal or deviating behavior from the group. Next, the system matches the current behavior pattern with historical archive data, calculates the deviation vector to determine the behavior deviation index, and assesses the rationality of individual state changes. Further, the source of deviation is analyzed by combining local anomaly factors and change quantification indicators, such as environmental interference or communication anomalies. When external interference is detected, the system automatically extracts historical similar scene data, adaptively adjusts the threshold, and dynamically updates the expected feature range. Subsequently, the system performs a secondary comparison of real-time data using an information gain splitting strategy to determine the consistency level, and optimizes the classification results and verification decisions by integrating conditional probability and multi-factor conditions through a decision tree model. Finally, combined with a path tracing mechanism, the system backtracks and analyzes the source of deviation and consistency results to determine the reliability level of UAV identity verification.

[0019] This method enables high-precision verification of UAV identities in dynamic environments, achieving real-time identity recognition through behavioral feature modeling, thus improving the security and robustness of the swarm control system. The detection mechanism combining clustering and isolated forests effectively identifies malicious interference or spoofing attacks. An adaptive threshold adjustment mechanism is introduced to maintain high recognition accuracy under various external conditions. The fusion of decision tree algorithms and pruning optimization strategies improves computational efficiency and reduces the probability of false positives. Path tracing and backtracking analysis mechanisms further enhance the system's ability to interpret abnormal events, making the entire authentication process traceable and verifiable.

[0020] S1 includes acquiring flight trajectory and communication mode data from the UAV via sensors, performing preliminary fusion of multi-dimensional information using a timed sampling method to obtain an initial data sequence; incorporating a noise filtering mechanism into the initial data sequence, applying low-pass filtering to remove high-frequency interference to obtain a filtered clean sequence, and determining preliminary real-time behavior characteristics; continuously updating the filtered clean sequence through real-time stream processing, adjusting the sampling interval if the noise level exceeds a preset threshold to obtain a dynamic behavior sequence; performing data fusion and quantization on the dynamic behavior sequence by combining path anomaly monitoring and signal strength assessment, merging trajectory deviation and signal fluctuation values ​​through weighted averaging to identify anomaly vector components; extracting trajectory optimization calculation elements from the anomaly vector components, correcting path points through linear interpolation, and obtaining a real-time behavior feature vector.

[0021] In this embodiment, the baseline acquisition phase first lasts for 10 seconds. The sensor synchronously acquires flight trajectory data and signal strength data in the communication mode at fixed intervals of 50 milliseconds. Each acquisition forms a record, which includes a timestamp, three-dimensional spatial position, straight-line distance from the previous position, instantaneous velocity calculated based on two adjacent positions, heading angle calculated based on three adjacent positions, and current signal strength. All records are arranged in chronological order to form an initial data sequence. Subsequently, a noise filtering mechanism is applied to the initial data sequence, using a moving average with a coverage time of 250 milliseconds as a low-pass filter. Specifically, at any given time, several records from that time and previous times are taken to form a time-covered sequence. Within a 250-millisecond sliding window, the window contains 5 records when the sampling interval is 50 milliseconds, and 10 records when the sampling interval is subsequently adjusted to 25 milliseconds. The arithmetic mean of the three spatial coordinates, the straight-line distance between adjacent positions, instantaneous velocity, heading angle, and signal strength is calculated within their respective windows, and this average is used to replace the original values ​​at the end of the window, thus obtaining a filtered clean sequence and determining preliminary real-time behavioral characteristics. During the baseline acquisition phase, the noise level is calculated in 1-second statistical windows. The noise level is defined as the median absolute difference between each data point within the statistical window and the average value within that window. The arithmetic mean of the three spatial coordinates, the straight-line distance between adjacent positions, the instantaneous velocity, the heading angle, and the signal strength is calculated separately. The system calculates the overall noise level of the statistical window based on the intensity of the noise level indicator. The maximum value among the four parameters is used as the overall noise level of the statistical window. The system sorts the overall noise levels of all baseline statistical windows in ascending order, takes the median, and multiplies it by 3 to determine the noise threshold. Once the threshold is determined, it is written into the configuration of the current run. After entering the formal acquisition phase, real-time stream processing is enabled to continuously update the filtered clean sequence. The system calculates the overall noise level of the most recent second window every 100 milliseconds and compares it with the noise threshold. When the overall noise level is higher than the noise threshold for 10 consecutive checks, the sampling interval is shortened from 50 milliseconds to 25 milliseconds to improve the ability to suppress high-frequency disturbances. When the overall noise level is lower than the noise threshold for 50 consecutive checks, the sampling interval is restored to 50 milliseconds. The above checks and adjustments are performed cyclically during operation to obtain a dynamic behavior sequence. Path anomaly monitoring and signal strength assessment are performed on the dynamic behavior sequence, and data fusion and quantization are completed. Path anomaly monitoring uses each time point and its adjacent time points to form the smallest segment. The change in steering and speed of this segment are calculated. The change in steering is the absolute value of the heading angle at that time point, and the change in speed is the absolute value of the difference between the instantaneous speed at that time point and the average speed of the most recent 1-second window. When the change in steering is not less than 30 degrees and the change in speed is not less than twice the average speed obtained by dividing the average straight-line distance between adjacent positions in the most recent 1-second window by the sampling interval, this time point is marked as a trajectory anomaly point.Signal strength assessment uses the difference between the maximum and minimum signal strength values ​​within the most recent 1-second window at each time point as the signal fluctuation value, while simultaneously recording the average signal strength within that window as the current signal level. A weighted average is used to fuse trajectory anomalies and signal fluctuations. Specifically, the trajectory deviation is obtained by first averaging the changes in steering and speed with equal weights, then summing the trajectory deviation and signal fluctuation values ​​according to their respective weights and dividing by the sum of the weights to obtain the fused value. The weights are set to 60 for trajectory deviation and 40 for signal fluctuation. These two weights are determined through a fixed outdoor calibration flight before deployment. The calibration process involves performing 5 minutes each of stable straight-line flight at a constant speed and fixed-point hovering to collect normal data. The data is then used for three minutes of circling flight with clear turning and acceleration / deceleration, and three minutes of hovering near a strong ground interference source to collect disturbance data. The fusion value distribution of different weight combinations on normal data and on disturbance data is calculated separately. The weight combination with the smallest 95th percentile on normal data and the largest difference between the 95th percentile and the 50th percentile on disturbance data is selected as the final weight and written into the device configuration. The fusion threshold is determined based on the data from the baseline acquisition phase and the set of time points within the first 60 seconds after the start of formal acquisition that are identified as non-trajectory anomalies and whose signal fluctuation values ​​are less than the median of that phase. The fusion values ​​of this set are sorted from smallest to largest, and the 95th percentile is taken as the fusion threshold. The system remains fixed throughout this task. At each time point, the system calculates the fusion value and compares it with a fusion threshold. When the fusion value is greater than or equal to the threshold, that time point is added to the anomaly vector component. The anomaly vector component records the time marker, filtered spatial position, straight-line distance between adjacent positions, instantaneous velocity, heading angle, signal strength, signal fluctuation value, trajectory anomaly marker, and fusion value in chronological order. When the fusion value is less than the threshold, that time point is marked as a normal point. When extracting trajectory optimization calculation elements from the anomaly vector component, consecutive anomaly time points are divided into anomaly segments. The preceding normal time point is determined as the starting anchor point, and the following normal time point as the ending anchor point. The time stamps and spatial locations of the two anchor points are determined, and the number of abnormal time points within the abnormal segment is counted. When performing linear interpolation to correct the path points, the time interval between the start and end anchor points is divided into equal parts, with the number of intermediate time points equal to the number of abnormal time points. The position of the intermediate time point is taken as the proportional position obtained by the time ratio of the line connecting the two anchor points. These positions are used to replace the spatial positions of the corresponding time points within the abnormal segment. At the same time, the straight-line distance and instantaneous velocity of the adjacent positions are updated with the replaced adjacent positions. The average signal strength of the 1-second window in which the abnormal segment is located is used as the signal strength of that time point while keeping the original signal fluctuation value unchanged. After completion, all time points are output in chronological order as a real-time behavior feature vector.In the above process, all parameters and thresholds are determined under fixed and unique rules. Specifically, the initial sampling interval is 50 milliseconds, the shortening value is 25 milliseconds, the shortening trigger condition is that the overall noise level exceeds the threshold for 10 consecutive checks, the recovery condition is that the overall noise level is below the threshold for 50 consecutive checks, the low-pass filter coverage time is 250 milliseconds, the noise threshold is equal to 3 times the median of the overall noise level in the baseline phase, the turning threshold for path anomalies is 30 degrees, the speed change threshold is twice the average speed of the most recent 1-second window, the fusion weight is 60 for trajectory deviation and 40 for signal fluctuation, the fusion threshold is the 95th percentile of the fused value of the normal set, and the number of interpolation points for linear interpolation is equal to the number of abnormal time points within the abnormal segment, with the interpolation position uniquely determined by the time ratio between the start and end anchor points and each intermediate time point.

[0022] During the baseline acquisition phase, the noise threshold is calculated using a 1-second statistical window to determine the overall noise level. The overall noise levels across all windows are sorted from smallest to largest, and the median is multiplied by 3. This value ensures it is above baseline fluctuations and below abnormal jitter. The sampling interval shortening trigger condition is when the overall noise level exceeds the noise threshold for 10 consecutive checks, and the recovery condition is when the overall noise level falls below the noise threshold for 50 consecutive checks. The check period is fixed at 100 milliseconds. The trigger and recovery counts are determined during ground testing based on a balance between false alarm and false negative rates and are written into the configuration. The abnormal path turning threshold is fixed at 30 degrees. This value is used for both stable straight-line flight and circular turn flight. In the comparative test, the minimum angle that can stably separate normal fine-tuning and sudden turning was selected; the speed change threshold was fixed at twice the average speed of the most recent 1-second window. This multiple was selected in the mixed flight test of constant speed and acceleration / deceleration as the minimum multiple that can reliably eliminate small speed fluctuations and retain abnormal acceleration events; the fusion threshold was determined by taking the 95th percentile of the fusion value of the normal set after sorting it from smallest to largest. The normal set consists of the time points in the baseline stage and the first 60 seconds after the start of formal acquisition where no trajectory abnormalities occurred and the signal fluctuation value was not higher than the median of that stage. This threshold ensures that the pass rate of normal samples reaches 95% and maintains sufficient separation for abnormal samples.

[0023] S2 includes acquiring behavioral feature vectors through real-time data collection, grouping the behavioral feature vectors using a clustering algorithm to obtain data point groups; applying isolation forest separation to the data point groups, where the isolation forest randomly divides the data point groups by constructing multiple isolation trees until a single point is isolated, calculating the isolation path length to identify potential deviations and obtain deviation isolation results; judging behavioral patterns based on deviation isolation results, and determining abnormal behavioral patterns if the deviation exceeds a preset threshold; obtaining pattern classification details from abnormal behavioral patterns to determine the current behavioral pattern classification; and obtaining classification results output through the current behavioral pattern classification to form a behavioral pattern classification.

[0024] In this embodiment, the behavioral feature vectors output from step S1 are continuously received and written into an analysis window of 2 seconds in chronological order, scrolling once every 1 second. Once the window is full, grouping and separation processing is immediately performed within it. The grouping process uses a center-based clustering algorithm, with a fixed number of 4 groups. This number is determined before deployment using historical archives as the data source. The sum of the false positive and false negative rates after linking group sizes from 3 to 8 with subsequent separation steps is compared, and the value with the smallest sum is selected and fixed as 4. For each analysis window, 4 vectors are selected from the window at equal intervals in chronological order as seed centers. Then, up to 10 iterations are performed, each iteration following the process described below. Skip: For each vector within the window, calculate its distance to the four centers and assign it to the group containing the center with the smallest distance. The distance value is obtained by summing the squares of the differences between each component and taking the square root, without any approximation. After completing one full assignment, use the arithmetic mean of the components of all vectors in each group as the new center. If the sum of the absolute differences of all centers across all components is less than 1 after this iteration, terminate the iteration early; otherwise, continue to the next iteration until 10 iterations are reached or the above convergence condition is met, thus obtaining the data point groups and their corresponding centers. Perform isolated forest separation independently within each data point group. The isolated forest contains 100 isolated trees, with a maximum splitting level of 8. The tree is constructed with a sample capacity of 256. When there are fewer than 256 data points in a group, all data points in that group are used. When there are more than 256 data points, 256 samples are drawn from that group without replacement and with equal probability. The tree is constructed layer by layer, and the following steps are performed for each segmentation, and the number of segmentations is recorded as a path length count: One component is uniformly and randomly selected from all components of the feature vector as the current segmentation component. Then, a threshold is uniformly and randomly selected between the minimum and maximum values ​​of this component in the current sample set. Samples less than the threshold are assigned to the left subset, and samples greater than or equal to the threshold are assigned to the right subset. The above process is repeated for each subset until only one sample remains in the subset or the current segmentation layer reaches the target number. Up to step 8, the isolation path length of the samples in this subset on this tree is equal to the number of splits from the root to the current leaf. After all isolation trees are constructed, the arithmetic mean of the isolation path lengths of the same data point on 100 trees is taken to obtain the average isolation path length of the data point. At the same time, the arithmetic mean of the average isolation path lengths of all data points in the same group is taken to obtain the standard path length of the group. Then, the deviation score is calculated for each data point in the group. The deviation score is defined as the difference between the standard path length and the average isolation path length of the data point. When the difference is negative, it is treated as 0. When the difference is non-negative, the difference is retained as the final deviation score and used as the core metric of the deviation isolation result.Behavioral pattern judgment is strictly based on deviation isolation results. Preset thresholds within a group are calculated before deployment using normal samples from historical archives and remain unchanged during the task. The calculation method involves calculating the deviation score for each normal sample in the group offline, sorting them from smallest to largest, and taking the 95th percentile as the preset threshold. During runtime, if the deviation score of a data point is greater than or equal to this threshold, it is determined to be an abnormal behavioral pattern; otherwise, it is determined to be a normal behavioral pattern. The process of obtaining pattern classification details from abnormal behavioral patterns does not introduce new algorithms; only deterministic indicators are extracted from the calculated results. These indicators include the group number to which the data point belongs, the distance from the data point to its group center, the average isolation path length of the data point, the deviation score of the data point, and a path continuity marker indicating whether the deviation scores of the data point at two adjacent time points before and after the time point simultaneously exceed the threshold. These indicators are then processed according to... The pattern classification details are written in a fixed order. The current behavior pattern classification is determined by two deterministic conditions in the pattern classification details, and the rules are unique and unambiguous. When the path continuity is marked as yes and the distance from the data point to the group center is greater than the 90th percentile of the distance from all data points in the same window to the center, it is classified as a continuous anomaly. When the path continuity is marked as no and the deviation score of the data point is between the threshold and twice the threshold, it is classified as a transient anomaly. When the deviation score of the data point is greater than twice the threshold, it is classified as a strong anomaly. If none of the above conditions are met, it is classified as normal. The classification result is output as a record with a fixed structure. The fields are, in order, time stamp, group number, standard path length, average isolation path length, deviation score, preset threshold used, current behavior pattern classification and pattern classification details summary. The record is immediately written to the behavior pattern classification queue for subsequent steps to call. The analysis window length is 2 seconds, the scroll step is 1 second, the number of groups is 4, the maximum number of iterations is 10, the number of isolation trees is 100, the sample size per tree is 256, the maximum number of segmentation layers is 8, the preset threshold is the 95th percentile of the deviation score of normal samples, the path continuity judgment range is 2 time points forward and backward, the distance boundary of continuous anomalies is the 90th percentile of the distance distribution of the group, and the boundary of strong anomalies is twice the preset threshold.

[0025] The preset threshold for deviation is determined by grouping based on the deviation score of normal samples. Specifically, before going live, a grouping and isolation forest process is constructed using behavioral feature vectors marked as normal in historical archives, which is completely consistent with the operational period. The deviation score is obtained point by point, and after sorting from smallest to largest, the 95th percentile is taken as the fixed preset threshold for that group. Once determined, it remains unchanged during the task. The strong anomaly boundary is set to twice the preset threshold. This multiple is selected by evaluating the sum of the false positive rate and the false negative rate of three integer multiples of 2, 3, and 4 on the offline validation set, and then fixing the minimum result as 2. The path continuity threshold for persistent anomalies is set to exceed the preset threshold at two time points both forward and backward. This value is selected by verifying each of the candidates 1, 2, and 3 offline and choosing 2 as the criterion for optimal classification stability. The spatial distance boundary for persistent anomalies is set to the distance to the group to which the anomaly belongs. The distance to the center is calculated offline for each normal sample point in the normal sample group, and the distance to the center is sorted. The 90th percentile is then used as the fixed boundary. The group convergence termination threshold is set to the sum of the absolute differences between the center and all components being less than 1. This value is tested one by one from candidates 1 to 5, and 1 is selected and fixed based on the criterion that the number of iterations does not exceed 10 and the rate of change of allocation is the lowest to ensure group stability. The maximum number of segmentation layers in the isolation forest is set to 8, which is the upper limit threshold for the isolation path length. This value is selected from candidates 6 to 10 after offline evaluation of the sum of false positive rate and false negative rate to balance accuracy and latency. The splitting position used for each segmentation within the isolation tree is determined uniformly between the minimum and maximum values ​​of the current sample set. This splitting position is only used as a random splitting point for tree construction and does not participate in the setting of the anomaly judgment threshold.

[0026] S3 includes: acquiring the current behavior pattern classification; retrieving matching items from historical records; evaluating the matching relationship through a preset threshold to obtain a matching score; parsing the deviation vector using the matching score; extracting vector components from the differences between the current pattern collection and the record retrieval; calculating the difference vector; quantifying the deviation index using the difference vector; determining the degree of behavior deviation by combining the deviation index quantification with the matching relationship evaluation; mapping the vector space for the degree of behavior deviation; fusing the results of deviation vector parsing from the vector space mapping to obtain a deviation relationship evaluation; generating a behavior deviation index based on the deviation relationship evaluation; and generating integrated details from the current pattern collection using the behavior deviation index.

[0027] In one possible implementation, processing is performed in time using an analysis window consistent with step S2, with a fixed analysis window length of 2 seconds and a fixed scrolling step of 1 second. These values ​​are solidified before deployment based on a trade-off assessment of latency and stability using historical archives. The system first receives the current behavior pattern classification and retrieves samples matching that classification from historical archive records to form a candidate set. Then, it calculates the distance between the real-time behavior feature vector at the current moment and each archive vector in the candidate set. The distance is calculated by squaring the differences in each corresponding dimension, summing the results, and then taking the square root, without approximation or truncation. The system sorts the obtained distances in ascending order and generates matching scores based on the calibration table of distance-to-matching-score established before going online. The calibration table is fixed offline as linear mapping intervals for each category. The lower limit of the interval is equal to the minimum distance of normal sample pairs and corresponds to a matching score of 100. The upper limit of the interval is equal to the 90th percentile distance of the distance distribution of normal sample pairs and corresponds to a matching score of 10. When the distance is greater than the upper limit of the interval, the matching score is fixed at 1. When the distance is less than the lower limit of the interval, the matching score is fixed at 100. The percentile score is calculated linearly within the interval. The minimum distance and the 90th percentile distance are... The distance to each normal sample pair in the historical archive is calculated and sorted. The system sorts the candidate samples from high to low according to their matching scores and selects the top 5 as valid matches. This number is fixed at 5 after offline comparison of the sum of the false positive rate and the false negative rate among 3 to 7 candidates. To obtain a robust control vector, the system performs a weighted average of the corresponding archive vectors with the matching scores of the valid matches as weights to obtain a reference archive vector. The archive vector corresponding to the highest score is used as the baseline archive vector. Then, a consistency check is performed. The check method is to calculate the distance between the reference archive vector and the baseline archive vector. The median of the absolute difference in each dimension is compared with the median of the absolute values ​​of each dimension of the reference file vector. If the ratio is not greater than 5%, the reference file vector is used as the final file comparison; otherwise, the baseline file vector is used as the final file comparison. The system sets a preset threshold for matching relationships to determine strong and weak matches. The preset threshold is fixed by the 10th percentile score of the matching degree scores of the same normal sample pairs in the historical files in ascending order before the system goes online. During the operation period, if the highest matching degree score of the effective matching item is not lower than the preset threshold, it is determined to be a strong match; otherwise, it is determined to be a weak match.Deviation vector analysis obtains the difference sequence by subtracting the final file comparison value in the corresponding dimension from the current real-time behavior feature vector. The sign and absolute difference of the difference are recorded for each dimension. The system calculates the arithmetic mean of the absolute differences of the dimensions related to flight trajectory and those related to communication mode to obtain the trajectory sub-deviation and communication sub-deviation. Then, the two types of sub-deviations are combined into a single deviation index according to fixed weights. The weights are set to 60 for the trajectory sub-deviation and 40 for the communication sub-deviation. These weights are selected and fixed to 60 and 40 based on the labeled samples of historical files before going live, iterating through weight combinations and using the minimum sum of recognition accuracy and false alarm rate as the criterion. The scale for quantifying the deviation index is determined by the historical distribution of similar normal samples. The system sorts the deviation indices of normal samples from smallest to largest and records the 90th and 99th percentiles as mapping reference points. The operational deviation index is linearly mapped to a deviation score of 0 to 100 according to its position within this interval; values ​​below the 90th percentile are mapped to a score less than 10. Values ​​above the 99th percentile are mapped to scores close to 100. Values ​​within the range are converted linearly. The two reference points are calculated and fixed once using historical archives before going online. The system combines the deviation score and the matching score to determine the degree of behavioral deviation. When the matching relationship is strong, the deviation score is the main factor, and the part with the matching score below 90 is penalized on a one-to-one basis to increase the degree of deviation. When the matching relationship is weak, the deviation score and the matching score minus 100 are combined on a one-to-one basis to synthesize the degree of behavioral deviation, and the result is limited to the range of 0 to 100. Vector space mapping is used to give an interpretable expression of the source of deviation. The system constructs a two-dimensional mapping with trajectory-related coordinates and communication-related coordinates. The trajectory sub-deviation and communication sub-deviation are linearly mapped to coordinate values ​​of 0 to 100 according to the reference ranges of the 90th and 99th percentiles of the same normal samples, respectively, and the coordinate pair is output. At the same time, the proportion of the two coordinate values ​​in the sum of the two is calculated, and the one with a proportion of not less than 60 is marked as the dominant source of deviation.The deviation relationship assessment consists of three parts: the numerical value of the degree of behavioral deviation, the two-dimensional mapping coordinates, and the marker of the dominant deviation source. Based on this, the system generates a behavioral deviation index and integrates it with the details collected in the current mode for output. The behavioral deviation index is a structured record with fixed fields including time stamp, current behavioral mode classification, highest matching score, preset threshold, strong and weak matching markers, degree of behavioral deviation, trajectory-related coordinates, communication-related coordinates, dominant deviation source markers, and the identifiers and corresponding score lists of the top 5 matching objects. The analysis window length is 2 seconds, the scrolling step is 1 second, the number of valid matches is 5, the lower limit of the matching degree calibration interval is the minimum distance of similar normal sample pairs with a corresponding score of 100, the upper limit of the interval is the 90th percentile distance of similar normal sample pairs with a corresponding score of 10, the score exceeding the upper limit of the interval is fixed at 1, the preset threshold is the 10th percentile of the matching degree score of similar normal sample pairs, the threshold for the ratio of reference to benchmark consistency check is 5%, the fusion weights of trajectory and communication are 60 and 40, the reference points for deviation scores are the 90th and 99th percentiles of similar normal samples, the penalty trigger point for strong matching is a matching degree score of 90, and the threshold for the proportion of dominant deviation sources is 60%.

[0028] The preset threshold for matching relationships is determined by sorting the matching scores of similar normal sample pairs in historical archives from smallest to largest, and then taking the 10th percentile score. This is used to distinguish between strong and weak matches and remains fixed during the task. The lower and upper limits of the matching degree calibration interval are taken as the minimum distance and the 90th percentile distance of similar normal sample pairs, respectively, and linearly mapped to scores of 100 and 10. Scores exceeding the upper limit are fixed at 1. This interval is used to unify the distance to a percentage system to ensure consistency in data across different batches. The threshold for the consistency kernel comparison value between the reference and the benchmark is set to 5%. This value is determined after offline comparison of the misselection rate and score stability, and is used to determine whether to use the weighted result of the first 5 items as the final archive comparison. The two sub-bias fusion weights of the deviation index are fixed at 60 and 40, respectively. The weights are determined by... Candidate weights are iterated over historically labeled samples and determined based on minimizing the sum of the correct recognition rate and the false alarm rate, ensuring the interpretability and stability of trajectory and communication contributions. The deviation score scale is referenced to the 90th and 99th percentiles of the deviation index of similar normal samples as interval endpoints, used to linearly map the operational deviation index to 0 to 100 and stretch the tail sensitivity. In strong matching scenarios, a penalty is added to the part with a matching degree lower than 90 on a one-to-one basis. The value of 90 is determined based on the stable boundary of historical samples in the high similarity region, used to avoid underestimation of high scores but slight mismatches. The proportion threshold of the dominant deviation source is set to 60, used to determine whether the trajectory or communication is dominant in the two-dimensional mapping. This value is selected from candidates 50, 60, and 70 based on the criteria of optimal classification stability and interpretability.

[0029] S4 includes obtaining behavioral deviation indicators from environmental changes through a data acquisition process. The data acquisition process includes real-time capture of behavioral data by sensors and calculation of the difference between the deviation value and the benchmark value to obtain local anomaly factors. Based on local anomaly factors, an anomaly detection algorithm is used in combination with change quantification indicators. The anomaly detection algorithm takes local anomaly factors and quantification indicators as input and outputs an evaluation score. The environmental impact assessment is determined by comparing the calculated score with a preset threshold. Through environmental impact assessment, trend analysis is conducted, which includes tracking the time series of assessment scores and identifying rising or falling patterns to determine the type of source of deviation. The source type of deviation is obtained, and the index fusion method and factor calculation logic are integrated. The index fusion method uses a weighted average of the types and factors, and the factor calculation logic includes multiplying by weight coefficients to obtain the source classification rules. By using source classification rules and combining them with a real-time monitoring mechanism, which includes continuously verifying the matching of rules with new data, the environmental impact of behavioral deviation indicators can be determined.

[0030] In one possible implementation, data is processed within an analysis window of 2 seconds in length and 1 second in scrolling step. The window and step size are fixed in the configuration before going live based on a trade-off assessment of detection latency and stability from historical archives. At each time point, the data acquisition process synchronously acquires the real-time behavior data output by the sensor and the baseline value obtained in step S3. The difference between the real-time behavior data and the baseline value is calculated dimension by dimension and the absolute value is taken. Then, the arithmetic mean of the absolute differences belonging to the flight trajectory dimension is obtained to get the trajectory difference average, and the arithmetic mean of the absolute differences belonging to the communication mode dimension is obtained to get the communication difference average. The absolute median of trajectory differences and the absolute median of communication differences, statistically analyzed during the offline phase for samples resembling normal data, are used as scaling factors. The local trajectory anomaly factor is obtained by dividing the average trajectory difference by its corresponding median, and the local communication anomaly factor is obtained by dividing the average communication difference by its corresponding median. The arithmetic mean of these two factors is used as the comprehensive local anomaly factor. Simultaneously, the local trajectory anomaly factor, the local communication anomaly factor, and the comprehensive local anomaly factor are saved for each time point within the current window. Subsequently, two change quantification indicators are calculated for input to the anomaly detection algorithm. The first is the short-term change rate, defined as the comprehensive local anomaly factor at the current time point. The first term is the change obtained by subtracting the comprehensive local anomaly factor at the same position in the previous second and dividing by 1 second. The second term is the short-term fluctuation amplitude, defined as the amplitude obtained by subtracting the minimum value from the maximum value of the comprehensive local anomaly factor in the last 2 seconds. The anomaly detection algorithm obtains a percentage evaluation score by linear scaling after weighted summation. The comprehensive local anomaly factor has a weight of 60, the short-term change rate has a weight of 25, and the short-term fluctuation amplitude has a weight of 15. Before going live, the three weights are determined and fixed by traversing candidate weights based on labeled normal and environmental interference samples, with the minimum sum of false positive and false negative rates as the criterion. To obtain a stable percentage scale... The system uses the 1st and 99th percentiles of the weighted sum of the original values ​​of normal and environmentally disturbed samples in historical archives as the endpoints of the linear calibration interval. The weighted sum is mapped to an evaluation score from 0 to 100. Scores below the 1st percentile are mapped to 0, and scores above the 99th percentile are mapped to 100. Scores within the interval are converted linearly. Environmental impact assessment is determined by a preset threshold. The preset threshold is determined by sorting the evaluation scores of normal samples of the same category from smallest to largest and taking the 95th percentile. During operation, when the evaluation score is not lower than the threshold, it is recorded as being affected by the environment; when the evaluation score is lower than the threshold, it is recorded as not being affected by the environment.After completing the environmental impact assessment, a trend analysis is performed. The system continuously tracks the time series of assessment scores and calculates the score difference between the previous second and the current second for the most recent 3 seconds. The median of the three differences is taken as the trend measure and compared with the pre-fixed rising and falling thresholds. The rising threshold is taken as the 90th percentile of the score difference distribution of similar normal samples, and the falling threshold is taken as the absolute value of the 10th percentile of the score difference distribution of similar normal samples, with the comparison taken in the negative direction. When the median is not lower than the rising threshold, it is determined to be an rising pattern; when the median is not higher than the negative falling threshold, it is determined to be a falling pattern; otherwise, it is a stable pattern. Based on this, the system determines the type of deviation source. If the rising pattern is valid and the average value of the trajectory local anomaly factor in the most recent 2 seconds is not less than 1.5 times the communication local anomaly factor, it is classified as a trajectory-related source. If the rising pattern is valid and the average value of the communication local anomaly factor in the most recent 2 seconds is not less than 1.5 times the trajectory local anomaly factor, it is classified as a communication-related source. If neither of these conditions is met, the deviation is classified as a stable pattern. If the estimated score is not lower than the preset threshold for three consecutive seconds, it is classified as a composite source. After obtaining the source type of deviation, the system executes the index fusion method and factor calculation logic to output the source classification rule. The index fusion method performs a weighted average of the three factors corresponding to the source type. The three factors are fixed as comprehensive local anomaly factor, short-term change rate, and short-term fluctuation amplitude. The factor calculation logic is to multiply each factor by the weight coefficient corresponding to the source type, sum them, and then linearly map them to a percentage source score. The three coefficients for trajectory-related sources are 60, 25, and 15, respectively; the three coefficients for communication-related sources are 60, 25, and 15, respectively; and the three coefficients for composite sources are 33, 33, and 33, respectively. The above coefficients and anomaly detection weights adopt the same offline evaluation process and are fixed once with the minimum sum of false positive rate and false negative rate as the criterion. The output of the source classification rule includes the source score and source label. The source label is selected from three categories: trajectory-related, communication-related, and composite, and is consistent with the aforementioned source type.Finally, the system uses source classification rules combined with a real-time monitoring mechanism to determine the environmental impact of behavioral deviation indicators. The real-time monitoring mechanism includes two parts: continuous verification rules and new data matching. The continuous verification rule confirms the existence of environmental changes when the source score is not lower than the preset threshold for three consecutive times. When any two subsequent source scores are lower than the preset threshold, the confirmation is revoked and the system is put into observation mode. The new data matching method counts the number of times the source label matches the previous confirmation conclusion within the last 5 seconds and calculates the consistency rate. When the consistency rate is not lower than 70%, the conclusion is maintained. When the consistency rate is lower than 70%, a review is triggered and the entire calculation process of this section is repeated. The analysis window length is 2 seconds, the scrolling step is 1 second, the three weights are 60, 25, and 15, the endpoints of the linear calibration interval are the 1st and 99th percentiles of the weighted sum of historical archives, the preset threshold for environmental impact is the 95th percentile of the normal sample evaluation score, the rising threshold is the 90th percentile of the difference in normal sample scores, the falling threshold is the absolute value of the 10th percentile of the difference in normal sample scores (in the negative direction), the source type ratio boundary is 1.5, the weighting coefficients for composite sources are 33, 33, and 33, the number of confirmations for continuous verification is 3, the number of withdrawals is 2, the consistency rate threshold for new data matching is 70%, and the matching statistics duration is 5 seconds.

[0031] The preset thresholds for evaluation scores are determined by sorting the evaluation scores of similar normal samples in historical archives from smallest to largest and taking the 95th percentile. This is used to determine if the evaluation score during operation is not lower than this value, indicating environmental influence. The rising threshold for trend analysis is taken as the 90th percentile of the distribution of the difference in evaluation scores per second among similar normal samples, and the falling threshold is taken as the absolute value of the 10th percentile of the distribution of the difference in evaluation scores per second among similar normal samples, with a negative boundary used for comparison. These two thresholds are used to determine if the median difference in the most recent 3 seconds is not lower than the rising threshold as an rising pattern, and not higher than the negative falling threshold as a falling pattern. The ratio boundary for deviation source types is fixed at 1.5. When the average value of the local anomaly factor in the trajectory in the most recent 2 seconds is not lower than 1.5 times the average value of the local anomaly factor in communication, it is classified as a trajectory-related source; conversely, when the average value of the local anomaly factor in communication is not lower than 1.5 times the average value of the local anomaly factor in trajectory, it is classified as a communication-related source. The ratio boundary is determined by historical... The system uses a grid search to select integer and half-integer candidates from the labeled normal and environmental interference samples in the archives, and determines the candidates based on the minimum sum of false positive and false negative rates. The continuous verification threshold in the real-time monitoring mechanism is set to confirm the presence of environmental changes if the source score is not lower than the preset threshold for three consecutive times. The cancellation threshold is set to cancel the confirmation if any two subsequent source scores are lower than the preset threshold. The number of such confirmations is selected after offline evaluation of the response latency and false positive rate of candidate values ​​2, 3, and 4. The consistency rate threshold for new data matching is fixed at 70%, with the most recent 5 seconds as the statistical duration. If the consistency rate between the source label and the previous confirmation conclusion is not lower than 70% within this duration, the conclusion is maintained; otherwise, a review is triggered. This value is determined by comparing the stability and recovery speed among the candidates 60, 70, and 80. The linear calibration endpoint threshold for the evaluation score is taken from the 1st and 99th percentiles of the weighted sum of similar normal and environmental interference samples, used to map the weighted sum to a percentage system from 0 to 100 and suppress the influence of extreme tail values.

[0032] S5 includes extracting similar scenario data from historical archives if the source of the deviation is classified as external interference, and obtaining the arithmetic mean of each deviation item through the similar scenario data to obtain the initial threshold range. For the initial threshold range, an adaptive threshold adjustment method is used to fuse abnormal score outputs. The adaptive threshold adjustment method determines the dynamic threshold boundary by summing the scores and ranges after applying preset weights. Based on the dynamic threshold boundary, obtain the current behavior indicator data, determine whether the data exceeds the boundary, and obtain the boundary deviation indicator. By incorporating the boundary deviation index into environmental noise filtering, the environmental noise filtering subtracts the preset noise benchmark value from the current behavioral index data to obtain the adjusted expected characteristic range.

[0033] In one possible implementation, the system first performs similar scenario data extraction and initial threshold range construction: The system uses the current behavior pattern as the search key in historical archives, limiting the search to the same platform, the same task type, and dates no more than 7 days apart. If the number of records meeting these conditions is not less than 300, these records are used as the similar scenario dataset. If the number is insufficient, all available records are used, and a data insufficiency flag is issued if the number of records is less than 100, but the same calculation steps are still performed. The system takes the values ​​of trajectory sub-deviation and communication sub-deviation from the similar scenario dataset one by one and calculates the arithmetic mean of these two items to obtain the scenario mean. Then, an initial threshold range is constructed at a fixed ratio. The initial lower bound of both trajectory sub-deviation and communication sub-deviation is equal to the corresponding scenario mean multiplied by 0.8, and the initial upper bound is equal to the corresponding scenario mean multiplied by 1.2. The two ratios mentioned above were fixed after offline evaluation using historical archives before going online. The candidate lower bound ratio was iterated from 0.7 to 0.9 in increments of 0.05, and the candidate upper bound ratio was iterated from 1.1 to 1.3 in increments of 0.05. The combination with the smallest sum of false positive and false negative rates for the two indicators of recovery speed of external interference samples and stability of normal samples was selected and fixed as 0.8 and 1.2. Subsequently, the threshold adaptive adjustment was performed and the abnormal score output was fused to determine the dynamic threshold boundary. The abnormal score was the evaluation score output in step S4 and the range was fixed from 0 to 100. The system first calculated the initial range width of each item, which was equal to the initial upper bound minus the initial lower bound. Then, the abnormal score was divided by 100 to obtain the extended ratio. The initial range and the extended ratio were weighted according to preset weights. The range weight was fixed at 0.7 and the extended weight was fixed at 0.3. Before going live, these two weights are performed using a grid search with the objective function of boundary adaptive stability and response delay of external interference samples, and are fixed with the criterion of minimizing the sum of false positive and false negative rates. The calculation process of the dynamic lower bound is to expand downward based on the initial lower bound, with the expansion amount equal to the initial range width multiplied by the expansion weight and then multiplied by the expansion ratio. The calculation process of the dynamic upper bound is to expand upward based on the initial upper bound, with the expansion amount consistent with the dynamic lower bound, thus obtaining a dynamic threshold boundary that expands symmetrically at both ends and changes monotonically with the anomaly score. Then, the system acquires the behavioral index data at the current moment and calculates the boundary deviation index. The data is fixed as two items: trajectory sub-deviation and communication sub-deviation at the same time. The judgment rule is as follows: when a certain data is not lower than the lower limit of the dynamic range and not higher than the upper limit of the dynamic range, the boundary deviation index of the variable is set to 0; when a certain data is higher than the upper limit of the dynamic range, the boundary deviation index of the variable is set to the ratio of the excess amount of the variable data minus the upper limit of the dynamic range to the initial range width of the variable, multiplied by 100, and truncated to 100 if the result is greater than 100; when a certain data is lower than the lower limit of the dynamic range, the boundary deviation index of the variable is set to the ratio of the deficiency amount of the variable data minus the lower limit of the dynamic range to the initial range width of the variable, multiplied by 100, and truncated to 100 if the result is greater than 100. If the value is greater than 100, it is truncated to 100. All ratios and multiplications are performed with full precision without approximation or truncation. Subsequently, the system incorporates environmental noise filtering into the boundary deviation index to generate the adjusted expected feature range. The environmental noise baseline value is calculated once by category using the absolute median of the corresponding behavioral indicator data from normal samples of the same category, and is fixed before going live. During operation, the system first subtracts the corresponding environmental noise baseline value from each current behavioral indicator data to obtain the noise correction value. Then, the arithmetic mean of the noise correction values ​​is taken in the analysis window of the most recent 2 seconds as the correction center, while maintaining the width of the dynamic threshold boundary. The range is reconstructed using the correction center as the center of symmetry. Specifically, the lower bound is obtained by shifting the correction center downwards by half a width and is limited to a value not less than 0. The upper bound is obtained by shifting the correction center upwards by half a width, thus forming the adjusted expected feature range that eliminates fixed noise offset while retaining boundary sensitivity. In the above process, data from similar scenarios are used in contiguous periods of no more than 7 days, with a minimum sample size of 300, an initial lower bound ratio of 0.8, an initial upper bound ratio of 1.2, a range weight of 0.7, an expansion weight of 0.3, an anomaly score range of 0 to 100, a boundary deviation index maximum of 100%, and an analysis window length of 2 seconds.

[0034] For similar scenario data, the time proximity threshold is set to 7 days and the minimum sample size threshold is set to 300 to ensure the timeliness and statistical stability of the samples. These two values ​​are fixed after comprehensively comparing the false positive and false negative rates of different time windows and sample sizes in historical archives. The initial threshold range is obtained by taking the arithmetic mean of each deviation item of similar scenario data to form the scenario mean and expanding it proportionally. The lower bound proportional threshold is fixed at 0.8 and the upper bound proportional threshold is fixed at 1.2. This ratio is selected by performing offline grid search on all candidate combinations in the ranges of 0.7 to 0.9 and 1.1 to 1.3, and the criterion is to minimize the sum of the false positive and false negative rates under the trade-off between recovery speed and stability. The threshold adaptive adjustment adopts a range weight threshold of 0.7 and an expansion weight threshold of 0.3 to merge the evaluation score and the initial range into a dynamic threshold boundary. The two weights are adjusted on historical external interference samples to define the boundary. The jitter amplitude and response delay are jointly minimized and then fixed. The boundary judgment threshold is directly derived from the dynamic lower and upper bounds. Any current behavior indicator data that is below the dynamic lower bound or above the dynamic upper bound is judged as out of bounds. This out-of-bounds amount is further converted into a percentage boundary deviation index and an upper limit threshold of 100 is set to limit the impact of extreme values ​​on subsequent decisions. This upper limit value is fixed after offline comparison of percentage interpretability and tail stability of abnormal distribution. The noise benchmark threshold for environmental noise filtering adopts the absolute median of the data of the same normal sample to enhance robustness to outliers and eliminate fixed bias. This threshold is calculated once before going online and remains unchanged. When reconstructing the range, a constraint threshold of not less than 0 is set for the lower bound to avoid negative values ​​and keep the width of the dynamic threshold boundary constant. This constraint is established after evaluating the minimum reachable range of historical data.

[0035] S6 includes obtaining real-time behavioral feature vectors through the adjusted expected feature range, applying secondary comparison to generate preliminary deviation values, determining whether the preliminary deviation values ​​exceed a preset threshold, and obtaining a comparison result set; For the comparison result set, the information gain value of each factor is calculated using the information gain splitting method. The information gain splitting method determines the splitting point and the high-gain factor sequence through the entropy reduction calculation formula. Based on the high-gain factor sequence, multi-factor branching is performed. Multi-factor branching extracts at least one dominant factor from the sequence, constructs a branch tree structure, and obtains the branch decision path. From the branch decision path, deviation source type and external interference data are incorporated. Deviation source type is obtained from historical archives, and external interference data is obtained from similar scenario data. The path consistency score is calculated by summing the path factors after applying weights. It is then determined whether the score meets the final consistency level requirements and intermediate consistency indicators are determined. Intermediate consistency metrics are obtained, combined with similar scenario data extracted from historical archives. The similar scenario data is obtained by adaptively adjusting the threshold and fusing the anomaly score output. The boundary deviation metrics are then adjusted to obtain the final consistency level.

[0036] In one possible implementation, this step takes the adjusted expected feature range output from step S5 as input. First, a secondary comparison is performed. The system reads the current value of the real-time behavior feature vector and the corresponding lower and upper bounds of each dimension one by one. Half the difference between the upper and lower bounds is calculated as the half-width and used only for scale normalization of this dimension. If the current value is between the lower and upper bounds, the initial deviation value for that dimension is set to 0. If the current value is higher than the upper bound, the excess is divided by the half-width and multiplied by 100 to obtain the initial deviation value for that dimension, and the result is truncated to 100 if it is greater than 100. If the current value is lower than the lower bound, the insufficient amount is divided by the half-width and multiplied by 100 to obtain the initial deviation value for that dimension, and the result is truncated to 100 if it is greater than 100. The system will then consider the trajectory-related dimensions... The initial deviation values ​​of the degree are averaged to obtain the initial value of the trajectory sub-deviation. The initial deviation values ​​of the communication-related dimensions are averaged to obtain the initial value of the communication sub-deviation. Simultaneously, the trajectory boundary deviation index and communication boundary deviation index generated in step S5 are read and combined with the above two to form a comparison result set. To form an out-of-bounds label, before going live, the system sorts the dimensional deviation values ​​of similar normal samples in ascending order and uses the 95th percentile as a preset threshold for secondary comparison. During operation, if the initial deviation value of any dimension is not lower than this threshold or any boundary deviation index is not lower than this threshold, the current time point is marked as out of bounds; otherwise, it is marked as not out of bounds. This label is used for subsequent gain calculation. Subsequently, the information gain splitting method is performed on the comparison result set to select candidate factors. The system is fixed on five factors: preliminary value of trajectory sub-deviation, preliminary value of communication sub-deviation, trajectory boundary deviation index, communication boundary deviation index, and deviation source type. The first four factors are continuous factors, and the last factor is a three-category discrete factor. For continuous factors, nine candidate split points are selected within the current analysis window at equal intervals between the minimum and maximum values. For discrete factors, the candidate splitting method involves merging each category with the remaining categories to form a binary set. For each candidate, the system first calculates the overall uncertainty using "out of bounds" and "not out of bounds" as binary labels, then calculates the uncertainties on both sides after splitting and weights them proportionally according to the sample size. The difference between these two values ​​is used as the information gain value for that candidate. The candidate with the largest gain among those factors is selected as the optimal splitting point for that factor. The optimal gain values ​​of the factors are sorted in descending order to obtain a high-gain factor sequence. If there is a tie in gain, the factors are selected in a fixed priority order: preliminary value of trajectory sub-deviation, preliminary value of communication sub-deviation, trajectory boundary deviation index, communication boundary deviation index, and deviation source type. Then, the multi-factor branching process is entered. Up to three dominant factors are extracted from the sequence to construct a branch tree structure. The root node is split into two branches using the optimal split of the first factor. The second and third factors are split in the same way in their respective parent nodes. The branch depth is capped at 3 and the splitting stops when the number of samples in any node is less than 30. The above depth and sample number thresholds are fixed before the system goes live by a trade-off between delay and stability.The system generates a branch decision path based on the current time point's movement within the branch tree and calculates a path consistency score. Specifically, the first, second, and third nodes on the path are weighted sequentially with 50, 30, and 20 respectively. The node consistency determination rule compares the node's splitting direction with the deviation source type given in step S4 and the direction of factors statistically analyzed from similar external interference scenarios in historical archives that categorize the current behavior pattern. If the node's movement aligns with both, it receives full weight; if it aligns with only one, it receives half the node's weight; if it aligns with neither, it receives 0. The scores of the three nodes are summed to obtain the path consistency score, which is limited to the range of 0 to 100. The path consistency threshold is fixed. The intermediate consistency index is set at 70 and determined through grid evaluation before going live, using the distinction between normal samples and external interference samples in historical archives as the target. When the path consistency score is not lower than 70, the intermediate consistency index is marked as passed and its value is recorded as the path consistency score; otherwise, it is marked as failed and its value is recorded as the path consistency score. After obtaining the intermediate consistency index, the system adjusts the boundary deviation index by combining it with similar scenario data extracted from historical archives. The similar scenario data outputs the dynamic threshold boundary and noise correction center according to the threshold adaptive adjustment process in step S5. The system calculates the trajectory and communication instantaneous deviation values ​​around the noise correction center at the current time point according to the same rules as the second comparison and compares the original boundary deviation index with the instantaneous deviation index. The deviation values ​​are weighted according to a fixed fusion weight to obtain new boundary deviation values, where the original boundary deviation weight is 60 and the instantaneous deviation weight is 40. These values ​​are fixed before deployment based on minimizing the sum of the false alarm rate and the missed alarm rate and remain unchanged during runtime. The final consistency level is jointly determined by the path consistency score and the inverse scores of the two new boundary deviation values ​​(track and communication). The inverse score is calculated by subtracting the corresponding new boundary deviation value from 100 and limiting it to the range of 0 to 100. The system uses a fixed ratio to sum the path consistency score, track inverse score, and communication inverse score at a weight of 50, 25, and 25, and linearly maps this sum to a final consistency level of 0 to 100. This ratio is jointly minimized before deployment to minimize decision jitter and errors. Rate calibration and solidification; to output directly usable grade results, the system sets the final consistency level grade boundaries as follows: high consistency no less than 80, medium consistency between 50 and 80, and low consistency less than 50. These three boundaries are determined once in the historical archive using the curve inflection point method and written to the read-only configuration. In this step, the preset thresholds for the secondary comparison are: the 95th percentile of the dimensional deviation of normal samples of the same type; the number of candidate split points for continuous factors is 9; the upper limit of branch depth is 3; the minimum number of samples is 30; the path node weights are 50, 30, and 20; the path consistency threshold is 70; the boundary deviation fusion weights are 60 and 40; the final consistency weighting ratio is 50, 25, and 25; and the grade boundaries are 80 and 50.

[0037] The pre-set threshold for boundary violations in the secondary alignment is the 95th percentile of the preliminary deviation values ​​of the dimensions obtained from the secondary alignment process consistent with the runtime of normal samples of the same type before going live, and is fixed to determine whether any dimension or any boundary deviation index has exceeded the limit. The upper limit of the preliminary deviation truncation is fixed at 100 to limit the deviation value after conversion of the half-width ratio to the percentage range. This upper limit is determined and fixed through stability evaluation of the extreme values ​​at the tail of the historical archives. The stopping threshold for information gain splitting includes the upper limit of branch depth of 3 and the minimum number of samples per node of 30. These two are determined and fixed after grid evaluation within the range of candidate depth 2 to 5 and candidate sample number 20 to 50 with the goal of jointly minimizing latency and stability before going live, to prevent overfitting and amplification of noise from small samples. High gain factor The threshold for the number of factors selected is fixed at 3, meaning that only the top 3 factors with the best gain value are used as inputs for branch construction. If there are fewer than 3 positive gain factors, all factors are selected. This threshold is determined by comparing the comprehensive indicators of classification stability and computational latency for different selection numbers. The path consistency threshold is fixed at 70. Before going live, the discrimination and false alarm rate of candidate thresholds from 60 to 80 are evaluated one by one using normal samples and external interference samples as controls, and the point with the best comprehensive indicator is selected to determine whether the intermediate consistency is passed. The final consistency level boundary is fixed at 80 and 50, where not lower than 80 is considered high consistency, between 50 and 80 is considered medium consistency, and lower than 50 is considered low consistency. The two boundaries are determined and fixed by calculating the receiver operating characteristic curve on the historical archives and taking the inflection point and risk equilibrium point.

[0038] S7 includes obtaining multi-factor conditions based on the final consistency level, extracting conditional probabilities from the multi-factor conditions, integrating the conditional probabilities using a decision tree algorithm (the input of the decision tree algorithm is the conditional probability, and the output is the integrated value), and obtaining the probability integration value by calculating the joint distribution of the conditional probabilities; for the probability integration value, incorporating a tree depth limit to process the multi-factor conditions, and determining a depth control threshold by limiting the maximum level of the tree depth limit; constructing leaf node decisions from the depth control threshold, integrating the leaf node decisions, and determining whether the integration exceeds a preset threshold to obtain a node decision set; performing a pruning optimization process on the node decision set, extracting optimized pruning paths, and determining the basis of the verification results by removing branches in the optimized pruning paths that contribute less than a preset threshold; obtaining the basis of the verification results, combining the consistency assessment and the obtained results, integrating factor processing, which is obtained from the multi-factor conditions, and determining whether the factor processing meets the consistency assessment requirements to obtain the identity verification result.

[0039] In one possible implementation, this step takes the final consistency level output from step S6 as input. First, it obtains multi-factor conditions and extracts conditional probabilities from historical archives. The multi-factor conditions include five items: final consistency level, path consistency score, trajectory reverse score, communication reverse score, and deviation source type. The scores for the four items range from 0 to 100, and the deviation source type takes three values: trajectory-related, communication-related, or a combination thereof. To ensure the stability of the conditional probability estimation, the system discretizes the four scores and solidifies the segment boundaries once before going live, ensuring the final consistency level is no less than 8. A score of 0 is assigned to the high zone, 50-80 to the medium zone, and below 50 to the low zone. A path consistency score of 70 or higher is assigned to the high zone, 50-70 to the medium zone, and below 50 to the low zone. Trajectory reverse score and communication reverse score of 80 or higher are assigned to the high zone, 60-80 to the medium zone, and below 60 to the low zone, respectively. The above boundaries inherit the levels and thresholds from step S6 and use the same historical archive to complete a one-time calibration. Subsequently, the system counts the number of passing samples and the total number of samples for each discrete combination of the five conditions in the historical archive and calculates the passing probability. For sparse combinations of samples... To avoid zero probability, a smooth count is used, incrementing both the number of samples and the number of failed samples by 1. This smooth count is set to 1 and fixed before the system goes live. Next, a decision tree algorithm is used to integrate conditional probabilities. During tree construction, the reduction in uncertainty is used as the splitting criterion for each node. Candidate splits are drawn from the discretized set of values. At each node, the system selects the split that maximizes the reduction in uncertainty, generating two child nodes and continuing to grow until a depth control threshold is reached. The depth control threshold is fixed at 3 and determined before going live based on minimizing both delay and stability among candidates 2 to 5. After the tree growth is complete, the system... The conditional probabilities corresponding to the previous time point are integrated along the root to leaf order. The integration rule is to multiply the pass probability of each node's corresponding combination in the path order and then normalize it to a percentage to obtain the integrated probability value, which is limited to the range of 0 to 100. In order to handle the impact of multi-factor conditions on reliability at different depths, the system incorporates tree depth limit information into the integrated probability value and reduces the credibility level by level. The root layer does not reduce the credibility, the second layer reduces it by 10, and the third layer reduces it by another 10. This reduction level is fixed as 10 for each level before going online after comparing the candidates 0, 10 and 20 with the receiver operating characteristic curve.Subsequently, leaf node decisions are constructed and fused under depth control threshold constraints. The leaf node decision fuses the pass probability of the leaf node coverage combination with the integrated probability value after depth correction. The fusion weight is fixed at 60% for the leaf node pass probability and 40% for the integrated value. These weights are determined and fixed by minimizing the sum of the false positive rate and false negative rate from historical archives. The fusion result is compared with a preset threshold to generate a leaf node output. The preset threshold is fixed at 70 and determined by a trade-off between discrimination and stability in the candidate range of 60 to 80. When the fusion result is not lower than 70, the leaf node output passes; when it is lower than 70, the output fails. The output sets of all leaf nodes constitute the node decision set. The system then performs pruning optimization on the node decision set to remove branches with insufficient contribution. The pruning contribution is measured by the increase in pass rate relative to the parent node on the validation set and the percentage of covered samples. The increase threshold is fixed at 2, and the coverage threshold is fixed at 5, meaning that the branch is retained only if the increase is not less than 2 percentage points and the covered samples are not less than 5 of the validation set. The above two thresholds are fixed after grid evaluation of candidates 1 to 3 and candidates 3 to 10 before going live. After pruning, the validation results are obtained and the retained leaves are recorded. Node set; After obtaining the verification results, the system and consistency assessment jointly provide a final judgment and incorporate factor processing. Factor processing selects the three most important factors from multiple factors based on information contribution ranking and calculates factor processing scores with weights of 50, 30, and 20, outputting a percentage result. These three weights are directly mapped and fixed using the gain ranking of historical archives before going live; Consistency assessment requires a final consistency level of no less than 50 and a path consistency score of no less than 50. These two boundaries inherit the level boundaries of step S6 and are calibrated on the same dataset; the generation of the final identity verification result... The process follows a unique decision rule: if the verification result is passed, both boundaries of the consistency assessment are met, and the factor processing score is not less than 60, the verification result is passed; otherwise, the result is failed. In this step, the following parameters are used: score discretization boundaries (80, 50, 70, 60), smoothing count (1), tree depth control threshold (3), level reduction rate (10 per level), leaf node fusion weights (60, 40), leaf node preset threshold (70), pruning enhancement threshold (2), pruning coverage threshold (5), factor processing weights (50, 30, 20), factor processing pass score (60), and consistency assessment boundary (50).

[0040] The discretization boundaries of the four scores are calibrated once according to historical archives and consistent with the criteria of step S6. A final consistency level of at least 80 is classified as high, 50-80 as medium, and below 50 as low. Path consistency scores of at least 70 are classified as high, 50-70 as medium, and below 50 as low. Trajectory reverse scores and communication reverse scores of at least 80 are classified as high, 60-80 as medium, and below 60 as low, respectively. These boundaries are determined and solidified by jointly minimizing the pass rate and false alarm rate of similar task samples. The smoothing count for conditional probability estimation is set to 1 to eliminate zero-frequency problems; this value is determined among candidates 0, 1, and 2 based on the criterion of optimal stability for extreme combinations on the validation set. The depth control threshold for the decision tree is set to 3, determined within the range of candidates 2 to 5 based on the criterion of jointly minimizing latency and stability. The level reduction for depth correction is set to decrease by 10 for each level decrease. The optimal discrimination of the receiver operating characteristic curve is determined among 0, 10, and 20. The fusion weight of the leaf node decision is determined by the leaf node pass probability weight of 60 and the integration value weight of 40, based on minimizing the sum of false positive and false negative rates in the historical archive. The preset threshold of the leaf node is 70, determined by a trade-off between discrimination and stability among candidates 60 to 80. In the pruning optimization, the pass rate improvement threshold relative to the parent node is 2, and the coverage threshold is 5, which are fixed after grid evaluation in the candidate 1 to 3 and candidate 3 to 10 ranges, respectively, to ensure the deletion of branches that do not contribute enough to the overall judgment. The three weights of factor processing are 50, 30, and 20, which are directly mapped according to the information gain ranking and fixed in the historical archive. The factor processing pass score is 60, determined by minimizing the overall error rate. The two boundaries of the consistency evaluation are a final consistency level of not less than 50 and a path consistency score of not less than 50, which are based on the statistical inflection point of step S6 and calibrated on the same dataset.

[0041] S8 includes: obtaining the deviation source type based on the authentication result; extracting the consistency level association from the deviation source type; using path tracing records to backtrack the consistency level association through layer-by-layer comparison to obtain the backtracked deviation source; for the backtracked deviation source, incorporating source type analysis to construct associated deviation types; fusing the associated deviation types and consistency level associations through item-by-item matching to determine the deviation type association set; extracting the record tracking path from the deviation type association set; determining whether the record tracking path meets a preset threshold to obtain the path tracking record; for the path tracking record, fusing the level association judgment; if the level association judgment exceeds the preset threshold, adjusting the deviation source type through source type correction to obtain the adjusted deviation source; obtaining the reliability determination from the adjusted deviation source; and combining it with the final level judgment to determine the final verification reliability level.

[0042] In one possible implementation, this step takes the authentication result and final consistency level output in step S7 as input and completes all calculations in a unique order at each time point, with the source and value of all parameters and thresholds fixed and clear: The system first reads the authentication result and the type of deviation source, and extracts the consistency level association from the branch decision path and path consistency score retained in step 6. Specifically, the final consistency level is divided into high zone if it is not lower than 80, medium zone if it is between 50 and 80, and low zone if it is lower than 50, and recorded as consistency level association label; then, a layer-by-layer path tracing backtracking is performed, and the branch decision path is split into layer 1, layer 2, and layer 3. The system uses three layers and three nodes, weighted 50, 30, and 20 respectively. At each layer, the system compares the path direction with the deviation source type and the direction of the consistency level association label. If both match, the entire weight of that layer is counted; if only one matches, half the weight is counted; if neither matches, zero weight is counted. The weights of the three layers are summed and limited to a range of 0 to 100 to obtain the backtracking path score. The system determines the backtracking deviation source based on a backtracking path score of at least 70 and the consistency level association label direction being consistent with the deviation source type. This source type analysis then performs item-by-item matching between the current deviation source type and the backtracking deviation source. The system identifies entries that are completely identical as strongly consistent, those that are opposite in direction as strongly inconsistent, and all others as weakly consistent. Using the most recent 5 seconds as the statistical duration, the system backtracks similar records at each time point and generates consistency tags for each entry, forming a deviation type association set. From this set, it extracts the record tracking path and calculates the path consistency rate, which is the percentage of strongly consistent entries out of the total number of entries in the most recent 5 seconds. If the path consistency rate is not less than 60% and the backtracked path score is not less than 70%, the record tracking path is considered to meet a preset threshold and a path tracking record is generated; otherwise, it is marked as an observation state and not proceeds to subsequent correction. For the generated path tracking records, the system integrates horizontal association judgments to determine whether to correct the deviation source type. Specifically, the backtracking path score is adjusted by adding or subtracting a label based on the consistency level range. When the consistency level is high, 10 is added to the backtracking path score; when it is medium, nothing is added or subtracted; and when it is low, 10 is subtracted. The adjustment result is limited to the range of 0 to 100 and compared with the horizontal correlation threshold. The horizontal correlation threshold is fixed at 75 and is determined before going live by minimizing the discrimination and false alarm rate among candidates 70, 75, and 80 through historical archives. When the adjusted horizontal correlation score is not lower than 75 and the current deviation source type is marked as strongly inconsistent with the backtracking deviation source, source type correction is performed, replacing the current deviation source type with the backtracking deviation source; otherwise, no change is made.After source type correction is completed, the system determines reliability and outputs the final verified reliability level. The reliability score is composed of three parts weighted in a fixed ratio: a percentage value of the final consistency level, a backtracking path score from the path tracing record, and a source consistency score. The source consistency score is given according to a three-level value rule: 100 for strong consistency, 70 for weak consistency, and 40 for strong inconsistency. The weights of the three parts are 40, 40, and 20, respectively. These weights are determined before going live using a historical archive grid search and based on the criterion of minimizing the overall error rate and volatility, and are written into the read-only configuration. The weighted sum of the three parts yields a reliability score from 0 to 100. The system uses the reliability score level boundary to give the final verified reliability. The reliability level is determined by a fixed boundary: a score of 80 or higher indicates high reliability; a score between 50 and 80 indicates medium reliability; and a score below 50 indicates low reliability. These three boundaries are determined and solidified before deployment based on the same historical data using the inflection point of the subject's operating characteristic curve and the risk equilibrium point. All parameters and thresholds are uniquely set and determined and remain unchanged throughout the task. Specifically, these include: consistency level discrete boundaries of 80 and 50; path node weights of 50, 30, and 20; path consistency rate threshold of 60; backtracking path score threshold of 70; horizontal association threshold of 75; nearest neighbor statistics duration of 5 seconds; source consistency score of 100, 70, and 40; reliability weighting ratio of 40, 40, and 20; and reliability level boundaries of 80 and 50.

[0043] The discrete boundaries for consistency level are set at 80 and 50, determined once from the inflection point and risk equilibrium point of the receiver operating characteristic curve in historical records. These boundaries are used to classify the final consistency level into high, medium, and low levels, and remain fixed during the task. The node weights for path tracing layer-by-layer comparison are set at 50, 30, and 20, derived from a joint evaluation of discrimination and decision delay, determined according to the principle that the first layer has the greatest impact, followed by the second layer, and then the third layer. The backtracking path score threshold is set at 70, determined by grid search within the candidate range of 60 to 80, based on the criterion of maximizing discrimination and minimizing the sum of false positive and false negative rates, serving as a hard boundary to confirm the source of backtracking bias. The path consistency rate threshold is set at 60, with a fixed statistical window of 5 seconds. These two values ​​are determined after joint evaluation of the candidate window length and candidate threshold set to ensure a balance between stability and response speed under short-term fluctuations. The horizontal association threshold is set at 75. The minimum error cost and optimal stability of the source type correction were selected from 70, 75, and 80 to determine whether to trigger it. The triggering condition for source type correction is that the horizontal correlation score is not lower than 75 and the current source type of the deviation is strongly inconsistent with the backtracking source of the deviation. Replacement is only performed if both conditions are met. The source consistency score adopts three levels: 100, 70, and 40. The separability of the three categories of strong consistency, weak consistency, and strong inconsistency is labeled according to manually labeled samples to ensure that the score corresponds monotonically to the strength of consistency. The weighting ratio of the reliability score is 40, 40, and 20, which are assigned to the final consistency level, backtracking path score, and source consistency score, respectively. The weights are fixed after minimizing the overall error rate and result jitter on the validation set through grid search. The final validation reliability level boundary is 80 and 50. The statistical inflection point of the consistency level is used and verified on the same dataset to ensure consistent interpretation of the level.

[0044] The initial input of this method is the raw data stream of the UAV flight trajectory collected in real time by sensors, historical archive records for comparison and learning, and similar scene data that can be retrieved from them. After completing the processing of steps S1 to S7 and the path tracking and reliability integration in step S8, the final output is the identity verification result (pass or fail) and the final verification reliability level (high, medium or low). At the same time, a structured record for traceability and review is generated. The record includes the final consistency level, path consistency score, source of backtracking deviation, path tracking record, and behavior deviation index to ensure that the judgment is traceable and reproducible.

[0045] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A dynamic identity authentication method for a drone swarm control communication system, characterized in that, include: S1. Collect flight trajectory and communication mode data of the UAV through sensors, process multi-dimensional information using a timed sampling method, and incorporate noise filtering mechanism and real-time stream processing to obtain real-time behavior feature vectors; S2. Based on the real-time behavior feature vector, a clustering algorithm is used to group the data points, and an isolation forest is applied to separate the groups to initially identify potential biases and determine the current behavior pattern classification. S3. Obtain the current behavior pattern classification, retrieve matching items from historical records, evaluate the matching relationship by comparing with a preset threshold, obtain the matching degree score, analyze the deviation vector through the matching degree score, and calculate the difference vector through the deviation vector analysis to obtain the behavior deviation index. S4. Based on the behavioral deviation index, use an anomaly detection algorithm combined with local anomaly factors and change quantification indicators to assess the impact of environmental changes and determine the type of deviation source. S5. If the source of the deviation is classified as external interference, similar scenario data is extracted from historical archives, and threshold adaptive adjustment and abnormal score output are incorporated to obtain the adjusted expected feature range. S6. By comparing the adjusted expected feature range with the real-time behavioral feature vector, the information gain split and multi-factor branching processing of the comparison results are applied to determine the final consistency level. S7. Based on the final consistency level, the decision tree algorithm is used to integrate conditional probability calculation and tree depth constraint to handle multiple factors, while incorporating leaf node decision and pruning optimization processes to obtain the identity verification result. S8. Based on the authentication results, use path tracing to record the source type of backtracking deviation and correlate it with the consistency level to determine the final authentication reliability level; S4 includes: Through the data acquisition process, behavioral deviation indicators are obtained from environmental changes. The data acquisition process includes real-time capture of behavioral data by sensors and calculation of the difference between the deviation value and the benchmark value to obtain local anomaly factors. Based on local anomaly factors, an anomaly detection algorithm is used in combination with change quantification indicators. The anomaly detection algorithm takes local anomaly factors and quantification indicators as input and outputs an evaluation score. The environmental impact assessment is determined by comparing the calculated score with a preset threshold. Through environmental impact assessment, trend analysis is conducted, which includes tracking the time series of assessment scores and identifying rising or falling patterns to determine the type of source of deviation. The source type of deviation is obtained, and the index fusion method and factor calculation logic are integrated. The index fusion method uses a weighted average of the types and factors, and the factor calculation logic includes multiplying by weight coefficients to obtain the source classification rules. By using source classification rules and combining them with a real-time monitoring mechanism, which includes continuously verifying the matching of rules with new data, the environmental impact of behavioral deviation indicators can be determined.

2. The dynamic identity authentication method for a drone swarm communication system according to claim 1, characterized in that: S1 includes: By acquiring flight trajectory and communication mode data from the UAV through sensors, and using a timed sampling method to initially fuse the multidimensional information, an initial data sequence is obtained. Based on the initial data sequence, a noise filtering mechanism is incorporated. By applying low-pass filtering to the data points to remove high-frequency interference, a clean filtered sequence is obtained, and preliminary characteristics of real-time behavior are determined. The filtered clean sequence is continuously updated through real-time stream processing. If the noise level exceeds a preset threshold, the sampling interval is adjusted to obtain a dynamic behavior sequence. For dynamic behavior sequences, combined with path anomaly monitoring and signal strength assessment, data fusion and quantification are performed. By merging trajectory deviation and signal fluctuation values ​​through weighted averaging, anomaly vector components are identified. Trajectory optimization calculation elements are extracted from the anomaly vector component, and path points are corrected through linear interpolation to obtain real-time behavior feature vectors.

3. The dynamic identity authentication method for a drone swarm communication system according to claim 1, characterized in that: S2 includes: Behavioral feature vectors are acquired through real-time data collection, and clustering algorithms are used to group the behavioral feature vectors to obtain data point groups. Isolation forest separation is applied to grouped data points. Isolation forest randomly divides grouped data points by constructing multiple isolation trees until a single point is isolated. The isolation path length is calculated to identify potential biases and obtain the bias isolation result. The behavior pattern is determined based on the deviation isolation results. If the deviation exceeds the preset threshold, the abnormal behavior pattern is identified. Obtain pattern classification details from abnormal behavior patterns to determine the current behavior pattern classification; The classification results are obtained by classifying the current behavior pattern, thus forming a behavior pattern classification.

4. The dynamic identity authentication method for a drone swarm communication system according to claim 1, characterized in that: S3 includes: Obtain the current behavior pattern category, retrieve matching items from historical records, evaluate the matching relationship by comparing with a preset threshold, and obtain a matching score; By analyzing the deviation vector through the matching score, vector components are extracted from the differences between the current pattern collection and the archive record retrieval, and the difference vector is calculated. By employing a difference vector to quantify deviation indicators, and combining the quantification of deviation indicators with the assessment of matching relationships, the degree of behavioral deviation can be determined. To determine the degree of behavioral deviation, a vector space is mapped, and the results of deviation vector analysis are fused from the vector space mapping to obtain an assessment of the deviation relationship. Based on the deviation relationship assessment, behavioral deviation indicators are generated, and details collected from the current pattern are generated by integrating the behavioral deviation indicators.

5. The dynamic identity authentication method for a drone swarm communication system according to claim 1, characterized in that: S5 includes: If the source of the deviation is classified as external interference, similar scenario data is extracted from historical archives, and the arithmetic mean of each deviation item is calculated using the similar scenario data to construct an initial threshold range with a fixed proportion. For the initial threshold range, an adaptive threshold adjustment method is used to fuse the abnormal score output to determine the dynamic threshold boundary; Based on the dynamic threshold boundary, obtain the current behavior indicator data, determine whether the data exceeds the boundary, and obtain the boundary deviation indicator. By incorporating the boundary deviation index into environmental noise filtering, the environmental noise filtering subtracts the preset noise benchmark value from the current behavioral index data to obtain the adjusted expected characteristic range.

6. The dynamic identity authentication method for a drone swarm communication system according to claim 1, characterized in that: S6 includes: By adjusting the expected feature range, the real-time behavior feature vector is obtained, a secondary comparison is applied to generate a preliminary deviation value, and it is determined that the preliminary deviation value exceeds the preset threshold to obtain the comparison result set. For the comparison result set, the information gain value of each factor is calculated using the information gain splitting method. The information gain splitting method determines the splitting point and the high-gain factor sequence through the entropy reduction calculation formula. Based on the high-gain factor sequence, multi-factor branching is performed. Multi-factor branching extracts at least one dominant factor from the sequence, constructs a branch tree structure, and obtains the branch decision path. From the branch decision path, deviation source type and external interference data are incorporated. Deviation source type is obtained from historical archives, and external interference data is obtained from similar scenario data. The path consistency score is calculated by summing the path factors after applying weights. It is then determined whether the score meets the final consistency level requirements and intermediate consistency indicators are determined. Intermediate consistency metrics are obtained, combined with similar scenario data extracted from historical archives. The similar scenario data is obtained by adaptively adjusting the threshold and fusing the anomaly score output. The boundary deviation metrics are then adjusted to obtain the final consistency level.

7. The dynamic identity authentication method for a drone swarm communication system according to claim 1, characterized in that: S7 includes: Based on the final consistency level, multi-factor conditions are obtained, conditional probabilities are extracted from the multi-factor conditions, and the conditional probabilities are integrated using a decision tree algorithm. The input of the decision tree algorithm is the conditional probability, and the output of the decision tree algorithm is the integrated value. The integrated probability value is obtained by calculating the joint distribution of the conditional probabilities. For probability integration values, tree depth constraints are incorporated to handle multi-factor conditions. The depth control threshold is determined by limiting the maximum level of the tree depth constraint. From the depth control threshold, construct leaf node decisions, fuse leaf node decisions, determine whether the fusion exceeds the preset threshold, and obtain the node decision set; For the node decision set, a pruning optimization process is performed to extract the optimized pruning path. The basis for the verification results is determined by removing branches with contributions below a preset threshold from the optimized pruning path. Based on the obtained verification results, combined with the consistency assessment and results, factor processing is incorporated. Factor processing is derived from multiple factors and conditions. It is determined that the factor processing meets the consistency assessment requirements, and the identity verification results are obtained.

8. The dynamic identity authentication method for a drone swarm communication system according to claim 1, characterized in that: S8 includes: Based on the authentication results, obtain the deviation source type, extract the consistency level association from the deviation source type, and use path tracing records to backtrack the consistency level association through layer-by-layer comparison to obtain the backtracked deviation source; To identify the sources of deviations, source type analysis is incorporated to construct associated deviation types. By matching each type with the consistency level, the association set of deviation types is determined.

9. A dynamic identity authentication method for a drone swarm communication system according to claim 8, characterized in that: S8 further includes: Extract the record tracking path from the deviation type association set, determine whether the record tracking path meets the preset threshold, and obtain the path tracking record; For path tracking records, horizontal correlation judgment is integrated. If the horizontal correlation judgment exceeds the preset threshold, the source type of the deviation is adjusted by source type correction to obtain the adjusted source of deviation. The reliability determination is obtained from the adjusted sources of deviation, and the final verification reliability level is determined by combining the final level assessment.