Denial of service attack strategy making method for consistency control of multi-agent system
By optimizing the DoS attack strategy through a multi-layer cutpoint method, the impact of DoS attacks on consistency in multi-agent systems is resolved, enabling the disruption of system consistency with low energy consumption and improving the identification capability of the defense system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-09
- Publication Date
- 2026-03-13
AI Technical Summary
Existing technologies lack systematic research on network attack strategies for multi-agent systems, which makes it difficult for defense systems to effectively identify attack surfaces and force innovation in defense technologies. The impact of DoS attacks on the state consistency of the system is difficult to achieve with low energy consumption.
A DoS attack strategy formulation method based on multi-level cut points is adopted. Combining the dynamic description of multi-agent systems and the average consensus algorithm, the attack strategy calculation is simplified by optimizing the objective function and using a multi-level cut point set, and an effective attack strategy is formulated to disrupt system consistency.
With limited energy consumption, the attack effectively disrupts the state consistency of multi-agent systems, prolongs the system convergence time, and improves the computational efficiency of the attack strategy and the system security.
Smart Images

Figure CN121664515A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this disclosure relate to the problem of network attacks targeting the consistency of multi-agent systems, specifically to a method for formulating a denial-of-service (DoS) attack strategy based on a multi-layer cutpoint approach. Background Technology
[0002] Multi-agent systems are complex systems comprised of multiple autonomous agents that collaborate in a distributed manner. Their core lies in solving large-scale dynamic problems that a single agent cannot handle through information exchange and task coordination among agents. These systems typically possess high autonomy, dynamic adaptability, and scenario versatility: each agent can independently perceive the environment, process information, and execute decisions, achieving data sharing and collaboration through network protocols; their flexible network structure allows for rapid adaptation to environmental changes, making them widely applicable in fields such as industrial automation, drone swarms, smart grids, and military simulations. In collaborative drone reconnaissance missions, agents adjust their flight paths through real-time information exchange, ultimately achieving full coverage monitoring of the target area, fully demonstrating the collaborative advantages of multi-agent systems in complex scenarios.
[0003] However, the efficient operation of multi-agent systems heavily relies on network communication—agents need to continuously exchange state, instructions, and environmental data to maintain coordination. This characteristic naturally exposes them to network attack risks, becoming a key bottleneck restricting system reliability. The main types of network attacks include spoofing attacks, replay attacks, and DoS attacks. A DoS attack is an attack that consumes system resources; its core objective is to prevent agents or the system from providing normal services, leading to task interruption. In a DoS attack, the attacker sends a large number of meaningless messages to the agent or system, consuming network bandwidth or system resources; or sends a large number of complex requests, exhausting the agent's memory or CPU resources, making it unable to process normal requests; or uses physical or logical means to disrupt the communication links between agents, preventing message transmission.
[0004] Despite the rapid development of cybersecurity defense technologies, a significant gap remains in systematic research on attack strategies. Existing research largely focuses on the design and optimization of defense technologies, lacking in-depth analysis of attacker behavior patterns, tactical choices, and technological evolution paths. By simulating attacker decision-making logic, researchers can identify uncovered attack surfaces in defense systems. Discovering system vulnerabilities from the attacker's perspective, attack strategy research, by simulating attacker behavior, can reveal logical flaws in defense systems. The evolution of attack strategies drives innovation in defense technologies. Attack strategy research provides quantifiable evaluation criteria for defense systems. Studying attack strategies is not only a necessary measure to fill theoretical gaps in cybersecurity but also a core path to building a dynamic security system that promotes defense through offense. By simulating attacker behavior logic, defenders can systematically identify system vulnerabilities and drive the evolution of defense technologies from passive response to proactive immunity. Summary of the Invention
[0005] The embodiments described in this paper are aimed at the consistency control of multi-agent systems and provide a method for formulating DoS attack strategies based on multi-layer cut points, which can effectively affect the state consistency of multi-agent systems while ensuring that the attacker consumes relatively little energy.
[0006] According to the first aspect of this disclosure, a method for formulating an objective function related to a DoS attack strategy for multi-agent consensus is provided. The specific method includes: obtaining the open-loop equation of the system based on its dynamic description and an average consensus algorithm; combining the DoS attack model with the system equation to obtain the form of the system equation under a DoS attack; and finally using the attacker's energy consumption and the system's consensus error as indicators, combining both to obtain a model of the objective function.
[0007] In some embodiments of this disclosure, the multi-agent system is configured as a discrete linear time-invariant system composed of N isomorphic agents, and the specific dynamic description of a single agent is as follows:
[0008] x i (k+1)=Ax i (k)+Bu i (k), i = 1, 2, ..., N
[0009] Where x i (k) and u i Let x(k) = (x1(k)) / (x2(k)). T , x2(k) T , ..., x N (k) T ) TThen the overall system dynamic equation can be written as:
[0010]
[0011] Where i N Describes an N-order identity matrix. It represents the Kronecker product.
[0012] In some embodiments of this disclosure, the system employs an average consensus protocol, and the control input is determined by the state values of the agent's neighbors. The control protocol is described as follows:
[0013]
[0014] Where K is the control gain matrix, a ij These are the elements of the system's topological adjacency matrix. The system achieves state consistency under the action of a consensus protocol; the achievement of consistency can be described as follows:
[0015]
[0016] In some embodiments of this disclosure, consistency error is used to measure the degree of disruption to the system's consistency. A larger consistency error indicates a greater degree of disruption after an attack. The consistency error is determined by the average of the current state values of all agents in the system. The consistency error of agent i is denoted as δ. i (k), described as:
[0017]
[0018] Let δ(k) = (δ1(k)) T ,δ2(k) T , …, δ N (k) T ) T Substituting the control protocol into the system equations and combining it with the description of consistency error, we obtain the system's error closed-loop equation:
[0019]
[0020] Where L is the Laplace matrix of the system topology, which can be obtained by subtracting the adjacency matrix and degree matrix of the system topology, let The system equation can then be simplified to δ(k+1)=Ωδ(k).
[0021] In some embodiments of this disclosure, the system's communication topology is configured to include a spanning tree to ensure graph connectivity. The consistency control protocol enables the system to achieve consistency only when the system topology is connected. Simultaneously, the spectral radius of the matrix Ω needs to be less than 1, and an appropriate control gain matrix K is set to enable the system to achieve consistency.
[0022] In some embodiments of this disclosure, a DoS attack can freely select nodes to attack. When an agent is attacked, its communication links with its neighboring nodes are disconnected. When the attack on that node stops, the communication links between that node and its neighbors are restored. The attack node set at step k. μ a (k) represents the number of nodes in the attack node set and the safe node set. The number of secure nodes is μ s (k)=N-μ a (k). Describe the DoS attack signal as:
[0023]
[0024] Here, the attack signal is integrated into the control protocol, which is then modified as follows:
[0025]
[0026] Therefore, the closed-loop error equation of the system under a DoS attack can be obtained:
[0027]
[0028] Where L(k) represents the Laplace matrix of the communication topology of the system after a DoS attack, which can be understood as the element a of the adjacency matrix of the original communication topology of the system. ij Multiply by the attack signal σ i (k) yields the adjacency matrix of the system affected by the attack, which in turn yields the Laplace matrix affected by the attack. Let... The open-loop error equation can then be written as δ(k+1)=Ω(k)δ(k).
[0029] In some embodiments of this disclosure, DoS attacks are constrained by the number of nodes that can be attacked simultaneously and by the total attack energy. At any system time step, the attacker disables the communication capability of one agent in the system through an attack, consuming one unit of attack energy. Since this is set as a homogeneous multi-agent system, it is assumed here that the energy consumption of any agent in the attack system is the same. The attacker's energy constraint can be given by the following two inequalities:
[0030]
[0031] in This indicates the maximum number of agents that can be used in a single attack. This indicates the maximum total attack energy.
[0032] In some embodiments of this disclosure, a preliminary model of the objective function is obtained by combining the consistency error model and the attacker's energy consumption model given above:
[0033] J(k)=μ a (k)-||δ(k)||
[0034] Where J(k) is the value of the objective function at the k-th time step, and ||·|| represents the Euclidean norm. For vector calculations, the following method can be used: Optimizing the objective function to obtain its minimum value means maximizing the system's consistency error within a limited attack energy. However, due to the difference in the dimensions of the two indicators, direct addition may lead to one indicator completely dominating. Therefore, normalization is considered to ensure that the ranges of variation for the two indicators are within similar intervals. The specific process of normalizing the two indicators is given by the following formula:
[0035]
[0036] Where δ min (k) and δ max (k) represent the minimum and maximum values in the vector δ(k), respectively. The normalized consistency error vector is δ norm (k)=(δ 1,norm (k) T δ 2,norm (k) T , …, δ N,norm (k) T ) T To facilitate adjustment of the destructive tendency of the attack strategy, an adjustment parameter α is added. α is a constant parameter greater than 0 that can be adjusted. The resulting objective function is:
[0037] J(k)=μ a,norm (k)-α||δ norm (k)||
[0038] In some embodiments of this disclosure, the objective function is optimized at each system step while satisfying attack energy constraints. Ensuring the attack strategy is globally optimal would be computationally intensive. Therefore, a greedy algorithm is employed to optimize the objective function at each system step, obtaining the attack strategy corresponding to the current optimal solution. After solving, the total DoS attack sequence is obtained. The optimization problem can be written in the following form:
[0039] min J(k)=μ a,norm (k)-α||δ norm (k)||
[0040]
[0041] According to another aspect of this disclosure, a method based on multi-layer cut points to compress the attacker's action space is provided to improve the efficiency of attack strategy solving. The specific method includes: calculating a multi-layer cut point set of the system topology according to a given algorithm; using the multi-layer cut point set as the attacker's action space, calculating the optimal value of the objective function at each system step as the attack strategy, and obtaining the overall attack sequence.
[0042] In an undirected connected graph G = (V, E), if deleting a vertex v and all its associated edges increases the number of connected components, then v is called a cut vertex of graph G. In other words, a cut vertex is a node in the graph whose deletion causes a previously connected region to split into multiple independent parts. For a system to achieve consensus under a consensus control protocol, the system topology must be connected. If a cut vertex is found and attacked, the consensus protocol can be directly prevented from achieving its control objective. However, since attackers are limited by their resources and cannot keep the system under attack indefinitely, this paper proposes a multi-layer cut vertex method to quickly disrupt the connectivity of the system topology, and then selects an appropriate attack strategy based on the attacker's needs.
[0043] In some embodiments of this disclosure, a multi-level cut vertex is defined as follows: In a graph with several cut vertices, the original graph is denoted as the first-level graph, and the set of cut vertices in the original graph is denoted as the first-level cut vertices. After deleting one of the cut vertices, the number of connected components in the graph increases, resulting in a second-level graph. The second-level graph is a graph containing several connected subgraphs, and the cut vertices in these connected subgraphs are denoted as the second-level cut vertices, and so on. It should be noted that the cut vertices deleted in each level of the graph are different, resulting in different next-level graphs and potentially different cut vertices; and multi-level cut vertex segmentation... Figure 1 We can continue until we find that there are no cut vertices in the graph. When there are no cut vertices in the original graph, the set of multiple cut vertices is empty.
[0044] In some embodiments of this disclosure, the attacker's attack strategy action space is constrained by the number of nodes N in the system and the number of nodes in a single attack. The decision is made. Nodes attacked at the same system time step can be considered to be attacked simultaneously. Therefore, finding the attacker's action space can be viewed as a problem of finding a subset of a set: the set contains N elements, and the goal is to find all elements in the set whose total number of elements is less than or equal to... A subset of. Therefore, we can obtain the potential of the action space as... The potential range of the action space exhibits an exponential growth trend when N and When the action space is large, the action space also becomes extremely large, which is very detrimental to the optimization of the objective function. However, using the multi-layer cut points proposed in this disclosure as the action space can simplify the optimization of the objective function while ensuring the attack effect, thus greatly improving the efficiency of computing the attack strategy. Attached Figure Description
[0045] To more clearly illustrate the technical solution of the invention, the accompanying drawings of the invention will be briefly described below:
[0046] Figure 1 This is a flowchart of the present disclosure;
[0047] Figure 2 To obtain the pseudocode for the multi-level cut point algorithm;
[0048] Figure 3 This is an exemplary network topology diagram for a multi-agent system;
[0049] Figure 4 An exemplary network topology diagram of a multi-agent system under a DoS attack;
[0050] Figure 5 The consistency error response of a multi-agent system that converges according to the control protocol when it is not under attack;
[0051] Figure 6 This is a diagram of the DoS attack signal obtained in the first set of simulations without replacing the attack action space.
[0052] Figure 7 For the first group of simulations Figure 6 The system consistency error response affected by the attack signal shown;
[0053] Figure 8 The image shows the DoS attack signal obtained after replacing the attack action space with a multi-layer cut point set in the second set of simulations.
[0054] Figure 9 For the second group of simulations Figure 8 The system consistency error response affected by the attack signal shown; Detailed Implementation
[0055] To make the objectives, technical solutions, and advantages of this disclosure clearer, further explanation and description will be provided below in conjunction with the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. All other embodiments obtained by those skilled in the art based on the described embodiments without inventive effort are also within the scope of protection of this disclosure.
[0056] Unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.
[0057] The embodiments described in this disclosure are geared towards consistency control in multi-agent systems, and provide a DoS attack strategy formulation method based on multi-layer cutpoints, which effectively affects the state consistency of multi-agent systems while ensuring that the attacker consumes relatively little energy. Figure 1 This is a flowchart illustrating the method for developing a DoS attack strategy based on multi-layer cutpoints as proposed in this disclosure.
[0058] In the embodiments of this disclosure, the multi-agent system is modeled based on a discrete state-space model, and the dynamic description of a single agent is as follows:
[0059] x i (k+1)=Ax i (k)+Bu i (k), i = 1, 2, ..., N
[0060] Here, all agents are assumed to be homogeneous. The consensus control protocol used is the average consensus control protocol.
[0061]
[0062] In the embodiments of this disclosure, the attacker is allowed to freely choose nodes in the system to launch a DoS attack, and there are constraints on the number of nodes attacked in a single attack and the total energy of the attack, as described by the following formula:
[0063]
[0064] DoS attack signals are described as follows:
[0065]
[0066] The consistency error of the system is described by the following formula:
[0067]
[0068] The integrated error open-loop equation of the system under control protocol and DoS attack is as follows:
[0069]
[0070] In the embodiments of this disclosure, an objective function is formulated based on the foregoing definition. The objective function includes normalized attacker energy consumption and normalized system consistency error, and is given by the following formula:
[0071] J(k)=μ a,norn (k)-α||δ norm (k)||
[0072] in Solving the optimization problem at each system step yields the attack strategy for that system step, which is then combined to obtain the overall attack sequence.
[0073] In the embodiments of this disclosure, a multi-layer cut point set is used as the attacker's action space in order to simplify the action space and reduce the computational cost of optimizing the objective function. Figure 2Pseudocode for an algorithm to find multi-level cut vertex sets is provided. The method for finding cut vertices at each level is the same, so a recursive approach can be used to find multi-level cut vertex sets.
[0074] In the embodiments of this disclosure, the MATLAB platform was used for numerical simulation. First, the relevant parameters of the system were set. The system contains eight agents, and the communication structure is as follows: Figure 3 As shown. The system's matrix parameters are set as follows:
[0075] K = [1 1.5]
[0076] The initial state of the system is:
[0077] x(0)=[-4.5,-0.5,-4,-1,-3.6,-1.2,-3,-2,4.6,1,4,1.5,3.6,0.5,2,2]
[0078] Set the upper limit for a single attack by the attacker. Total attack energy And the weighting coefficient of the objective function is α = 0.2.
[0079] Figure 4 This is a diagram illustrating what happens when the system is under attack. Figure 4 If node 2 is attacked, it will lose its communication capability and will be unable to exchange information with its neighboring nodes. Figure 5 This is the consistency error curve when the system reaches consistency normally under the control protocol. Here, the moment when the maximum absolute value of the elements in the system consistency error vector is less than or equal to 0.01 is defined as the system convergence time. The convergence time of the system under no-attack conditions is 7.37 seconds.
[0080] Simulation experiments were conducted using two sets of attack strategies. The simulation results for the first set were obtained from... Figure 6 Figure 7 As shown, Figure 6 This is the DoS attack sequence obtained without replacing the attacker's action space. Figure 7 In order to be in Figure 6 The system's consistency error curve is shown under the attack signal, where the convergence time is delayed by 12.69 seconds. The simulation results for the first group are... Figure 8 Figure 9 As shown, Figure 8 This is the attack sequence obtained when using a multi-layered cut point set as the action space. Figure 9 In order to be in Figure 8The consistency error curve of the system under the attack signal shown is displayed, and the convergence time of the system is 13.68 seconds. These two sets of experiments demonstrate that the attack strategy selection method based on objective function optimization can effectively degrade system performance and extend the system convergence time with limited attack energy. In comparison, replacing the original action space with a multi-layer cut point set does not show any difference in the quality of the attack strategy, but the efficiency of the computational strategy is improved.
[0081] Therefore, the method proposed in this disclosure enables attackers to effectively disrupt system consistency under energy constraints, and the proposed multi-layer cutpoint algorithm can effectively improve the efficiency of attack strategy formulation. The essence of attack research is to improve system security performance; the method proposed in this disclosure can serve as a step in testing system security, helping to identify shortcomings in system defenses.
Claims
1. A method for formulating a denial-of-service attack strategy for consensus control in a multi-agent system, wherein the multi-agent system is a discrete homogeneous time-invariant multi-agent system, the consensus control uses an average consensus control protocol, and the method for formulating the denial-of-service attack strategy includes: Modeling the dynamic description of multi-agent systems; Use the average consistency control protocol to control the consistency of the system; Model the DoS attack signals and constraints; This yields a dynamic description of the system consistency error. The objective function is modeled by combining the attacker's energy consumption and the degree of system damage; Obtain the multi-layer cut point set of the system communication topology; Use the obtained multi-layered cut point set as the attacker's action space; The objective function is optimized to obtain the DoS attack strategy.
2. The method according to claim 1, wherein, A multi-agent system is defined as a discrete linear time-invariant system consisting of N isomorphic agents. The specific dynamic description of a single agent is as follows: x i (k+1)=Ax i (k)+Bu i (k),i=1,2,...,N Where x i (k) and u i Let x(k) = (x1(k)) / (x2(k)). T , x2(k) T , ..., x N (k) T ) T Then the overall system dynamic equation can be written as: Where IN represents the N-order identity matrix, It represents the Kronecker product.
3. The method according to claim 1, wherein, The definition of system consistency is described as follows: The average consistency control protocol used is described as follows: Where K is the control gain matrix, a ij These are the elements of the system's topological adjacency matrix.
4. The method according to claim 1, wherein, DoS attack signals are described as follows: in This represents the set of attack nodes at step k. For a secure node set. The control protocol has been modified as follows: The consensus error of agent i is denoted as δ. i (k), described as: The following description of the system consistency error can be obtained: The attacker's energy constraint can be given by the following two inequalities: in This indicates the maximum number of agents that can be used in a single attack. This indicates the maximum total attack energy.
5. The method according to claim 1, wherein, The objective function includes two metrics: the attacker's energy consumption and the attacking force's energy consumption. μa The two indicators, δ(k) and the degree of system damage, are normalized in the following way: Where δ min (k) and δ max (k) represent the minimum and maximum values in the vector δ(k), respectively. The normalized consistency error vector is δ norm (k)=(δ 1,norm (k) T δ 2,norm (k) T , …, δ N,norm (k) T ) T . To facilitate adjustment of the destructive tendency of the attack strategy, an adjustment parameter α is added. α is a constant parameter greater than 0 that can be adjusted. The resulting objective function is: J(k)=μ a,norm (k)-a||d norm (k)|| The optimization problem can be written in the following form: minJ(k)=μ a,norm (k)-a||d norm (k)|| 6. The method according to claim 1, wherein, A multi-level cut vertex is defined as follows: In a graph with several cut vertices, the original graph is denoted as the first-level graph, and the set of cut vertices in the original graph is denoted as the first-level cut vertices. After deleting one of the cut vertices, the number of connected components in the graph increases, resulting in a second-level graph, which is a graph containing several connected subgraphs. The cut vertices in these connected subgraphs are denoted as the second-level cut vertices, and so on. It is important to note that the cut vertices deleted in each level of the graph will result in different levels of graphs, and the cut vertex sets in the next level may also be different. Furthermore, multi-level cut vertex partitioning continues until no cut vertices remain in the graph. When the original graph has no cut vertices, the multi-level cut vertex set is empty. The method for finding the cut vertices at each level is the same, so a recursive method can be used to find the set of cut vertices at multiple levels.
7. After obtaining the multi-layer cut point set of the system topology using the method described in claim 6, this set is used as the action space for objective function optimization. At each system step, the optimization problem described in claim 5 is solved to obtain the attack strategy for the current system step, and these strategies are combined to obtain the overall DoS attack sequence.