Distributed consistency security state estimation method and system
By employing a distributed consensus security state estimation method, utilizing FDIA observers and Kalman filter gains, and collaboratively designing consensus gains, the problem of identifying and defending against DoS and FDI attacks in CPS systems is solved, achieving stable state estimation and system robustness.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-29
- Publication Date
- 2026-04-07
AI Technical Summary
Existing technologies struggle to effectively identify and defend against denial-of-service (DoS) attacks and fictitious data injection (FDI) attacks in CPS systems, especially in hybrid attack scenarios. Furthermore, traditional models cannot adapt to situations where data is partially degraded or lost in clusters in real-world scenarios.
A distributed consensus-based secure state estimation method is designed. By co-designing the FDIA observer, Kalman filter gain, and consensus gain, and combining the Bernoulli sequence characteristics, the method eliminates failure information from DoS attacks, suppresses false information from the communication layer FDI, and uses the upper bound constraint of the error covariance to ensure that the mean square of the state estimation error is bounded.
In complex scenarios where attacks exist simultaneously at both the physical and communication layers, stable state estimation performance is achieved, enhancing the robustness and fault tolerance of the system and ensuring the safe and reliable operation of the CPS system.
Smart Images

Figure CN121814409A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of system security state estimation technology, and specifically relates to a distributed consensus security state estimation method and system. Background Technology
[0002] As a new generation of intelligent system paradigm, Cyber-Physical Systems (CPS) deeply integrates computing resources, communication networks, and physical devices to construct a real-time interactive and closed-loop control system between the information space and the physical space, becoming a core technology carrier for industrial intelligence and digital transformation. CPS achieves a close integration of the physical and information worlds, and its security directly affects the stable operation of numerous industries such as industrial production, transportation, healthcare, and energy, as well as the safety of people's lives and property. However, its distributed structure and strong real-time interactive characteristics make information interaction more flexible and open, but also bring more malicious cybersecurity threats, making CPS security issues particularly important.
[0003] The main network attacks that CPS (Cybersecurity System) suffers from are Denial-of-Service (DoS) attacks and False Data Injection (FDI) attacks, which are also the most typical and prevalent types of network attacks. DoS attacks disrupt the transmission link between control commands and state data through resource overload or channel congestion; FDI attacks, based on reverse engineering of communication protocols, inject forged information by tampering with the content of transmitted data packets, thereby causing system state estimation deviations and controller instability. These two attacks complement each other in their attack mechanisms—DoS attacks disrupt system availability, while FDI attacks threaten data integrity, together constituting a multi-objective optimization challenge for CPS security defense. In addition, in many practical applications, due to sensor aging, intermittent sensor failures, and complex environments, measurement results often experience random information loss and degradation. Currently, there are two main models describing non-ideal measurements: 1) missing measurement models and 2) fading measurement models. However, missing measurement models can only handle completely lost or completely normal binary data states and cannot adapt to situations where data is partially degraded or lost in clusters in practice, thus having significant limitations. Summary of the Invention
[0004] The purpose of this invention is to provide a distributed consistent and secure state estimation method and system to solve the above-mentioned problems.
[0005] To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a distributed consensus security state estimation method, comprising: Set the initial parameters and boundary conditions required for the linear time-invariant discrete system, and set the system running time step to the initial value; Design the gain of the fake data injection attack observer, and use the deviation between this gain and the sensor's measurement output and system state prediction to estimate the observation of malicious attack signals at the physical layer, and update the upper bound of the covariance of the attack signal observation error. Based on the obtained state estimation results, state prediction is performed, and the upper bound of the covariance of the state prediction error is updated. Combining the number of node neighbors, preset parameters, and the updated upper bound of the covariance of the state prediction error, the Kalman filter gain used to adjust the influence of measurement residuals is obtained. By combining the obtained attack signal observations, Kalman filter gain, and consistency gain, the state estimation of the current time step is updated, and then the upper bound of the covariance of the state estimation error is updated. It is then determined whether the current time step has reached the preset maximum time step threshold. If it has not reached the threshold, the time step is updated and the process is repeated. If it has reached the threshold, the entire state estimation process ends.
[0006] Furthermore, the setting of the initial parameters and boundary conditions required for the linear time-invariant discrete system, and setting the system running time step to its initial value, includes: For a linear time-invariant discrete system, the system equations are:
[0007] in, For state vectors, To inject FDI attack signals into the system's physical layer by a malicious attacker; assuming ,in It is a known positive scalar; Represents a node In the The measurement output at a single instant; For nodes The measured attenuation coefficient is uniformly distributed in the interval. Random variables on; mean and variance They are respectively and . and Are they respectively satisfied? and Uncorrelated Gaussian white noise sequences; A, G, W, and Let A be a known matrix of appropriate dimension, and let A be a stable matrix; initial state ,and and , , They are unrelated.
[0008] Furthermore, the gain of the designed fake data injection attack observer, using the deviation between this gain and the sensor's measurement output and system state prediction, is used to estimate the physical layer malicious attack signal and update the upper bound of the covariance of the attack signal observation error, including: Solving using the FDI attack observer , see the following formula for details:
[0009] in, The FDIAO gain to be determined is determined by the following formula:
[0010] in, and They are observation error covariance and mutual covariance The upper bounds are respectively denoted as:
[0011] , , , , and All are given positive scalars, and
[0012] Furthermore, the attacks include DoS attacks at the physical system layer and FDI attacks launched randomly on the wireless communication channel between neighboring nodes. DoS and FDI attacks are described using random Bernoulli sequences, treating the occurrence of these two attacks as independent random processes.
[0013] This indicates that the attacker successfully entered the channel. Launch an FDI attack, and ; This indicates that no attack was initiated. The false data transmitted to the attacker, and satisfies , For a known positive scalar; similarly, This indicates that the attacker successfully entered the channel. Launch a DoS attack, and ; This indicates that no DoS attack was initiated; further, it is assumed that at any given time, an attacker can only launch one type of attack at the communication channel layer, i.e. ; At any moment, the sensor From the sensor The actual received data packets can be represented as:
[0014] sensor The structure of the distributed state estimator is as follows:
[0015] in, For sensors The one-step state prediction value of the neighbor set nodes; For is a sensor In the Attack signal Observed values; and These represent the filter gain and consistency gain to be designed, respectively.
[0016] Furthermore, based on the obtained state estimation results, state prediction is performed, and the upper bound of the covariance of the state prediction error is updated; combining the number of node neighbors, preset parameters, and the updated upper bound of the covariance of the state prediction error, the Kalman filter gain used to adjust the influence of the measurement residual is obtained, including: It is the first One sensor in The gain matrix at time step is used to adjust the effect of the measurement residuals on the state estimation, as shown in the following formula:
[0017] in, Represents a node The number of neighboring nodes, It is a given positive scalar. and These are the state prediction error covariance. and estimation error covariance The upper bounds are respectively denoted as:
[0018] Furthermore, the consistency gain design: Used to adjust sensor nodes The weighting of neighbor node information when updating its state estimate determines the node's position. How to combine the state predictions of neighboring nodes to correct one's own state estimate is shown in the following formula:
[0019] in, It is a positive scalar constant.
[0020] Furthermore, the upper bound of the covariance of the updated state estimation error is:
[0021] If time step T is not reached, set k = k + 1 and return to re-execute; otherwise, end the loop.
[0022] In a second aspect, the present invention provides a distributed consensus-based secure state estimation system, comprising: The initialization module is used to set the initial parameters and boundary conditions required for the linear time-invariant discrete system and to set the system's running time step to the initial value. The first update module is used to design the gain of the fake data injection attack observer. By using the deviation between this gain and the sensor's measurement output and the system state prediction value, the observation estimate of the physical layer malicious attack signal is obtained, and the upper bound of the covariance of the attack signal observation error is updated. The second update module is used to make state predictions based on the obtained state estimation results and update the upper bound of the covariance of the state prediction error; combined with the number of node neighbors, preset parameters and the updated upper bound of the covariance of the state prediction error, the Kalman filter gain is obtained to adjust the influence of the measurement residual. The output module is used to combine the obtained attack signal observations, Kalman filter gain, and consistency gain to complete the state estimation update for the current time step, and then update the upper bound of the covariance of the state estimation error; it determines whether the current time step has reached the preset maximum time step threshold. If it has not reached the threshold, the time step is updated and the process is repeated; if it has reached the threshold, the entire state estimation process ends.
[0023] Thirdly, the present invention provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the distributed consensus security state estimation method.
[0024] Fourthly, the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the distributed consensus security state estimation method.
[0025] Compared with the prior art, the present invention has the following technical effects: This invention utilizes a specially designed FDIA observer (FDIAO) to effectively extract observations of physical layer FDIA attack signals from signals containing noise and measurement attenuation. Furthermore, by constraining the upper bound of the error covariance, it ensures that the observation error remains within a controllable range, providing crucial support for subsequent state estimation to eliminate attack interference and solving the problem of inaccurate identification of attack signals in mixed attack scenarios.
[0026] By coordinating the design of Kalman filter gain and consistency gain, the timeliness of local measurement information is utilized, while effective interaction information from neighboring nodes is rationally integrated. Furthermore, the Bernoulli sequence property is used to eliminate invalid information from DoS attacks and suppress spurious information from communication layer FDIA. Under the constraint of the upper bound of error covariance, the mean square bounded state estimation error is ensured, maintaining stable estimation performance even in complex scenarios where attacks exist simultaneously at the physical and communication layers.
[0027] This invention fully considers the randomness of measuring attenuation coefficient, the interference of Gaussian white noise, and the randomness of attack occurrence. By introducing multiple adjustable positive scalar parameters, it can be flexibly adjusted according to different system parameters and attack intensity to adapt to different node topologies. Attached Figure Description
[0028] Figure 1. Schematic diagram of distributed security state estimation under hybrid attack and fading measurement.
[0029] Figure 2. Continuous stirred tank reactor.
[0030] Figure 3. Topology of the sensor network.
[0031] Figure 4. Comparison of the actual and estimated states of CSTR state 1 based on this paper and existing literature.
[0032] Figure 5. Comparison of root mean square errors of 500 Monte Carlo experiments for CSTR state 1 based on this paper and existing literature.
[0033] Figure 6. Comparison of the actual and estimated states of CSTR state 1 based on the proposed method and the omission attack estimation algorithm.
[0034] Figure 7. Comparison of root mean square errors of 500 Monte Carlo experiments for CSTR state 1 based on the proposed method and the omission attack estimation algorithm.
[0035] Figure 8. Flowchart of distributed consistency security state estimation for a cyber-physical system under hybrid attack and fading measurement. Detailed Implementation
[0036] The present invention will be further described below with reference to the accompanying drawings: Example 1, please refer to Figure 8This invention provides a distributed consensus security state estimation method, comprising: Set the initial parameters and boundary conditions required for the linear time-invariant discrete system, and set the system running time step to the initial value; Design the gain of the fake data injection attack observer, and use the deviation between this gain and the sensor's measurement output and system state prediction to estimate the observation of malicious attack signals at the physical layer, and update the upper bound of the covariance of the attack signal observation error. Based on the obtained state estimation results, state prediction is performed, and the upper bound of the covariance of the state prediction error is updated. Combining the number of node neighbors, preset parameters, and the updated upper bound of the covariance of the state prediction error, the Kalman filter gain used to adjust the influence of measurement residuals is obtained. By combining the obtained attack signal observations, Kalman filter gain, and consistency gain, the state estimation of the current time step is updated, and then the upper bound of the covariance of the state estimation error is updated. It is then determined whether the current time step has reached the preset maximum time step threshold. If it has not reached the threshold, the time step is updated and the process is repeated. If it has reached the threshold, the entire state estimation process ends.
[0037] Distributed security state estimation, as an important defense mechanism, achieves accurate estimation of the physical dynamic state through the cooperation of distributed nodes (such as sensors and controllers), while resisting security threats such as data tampering. CPS's distributed consensus security state estimation uses distributed filtering (such as distributed variants of Kalman filtering) and consensus algorithms (such as average consensus and maximum consensus) to enable multiple nodes to gradually converge to a globally consistent state estimate based on local observations and neighbor communication. This solves the state coordination problem among multiple nodes, resulting in stronger attack resistance and fault tolerance, making its importance self-evident. On the one hand, the CPS architecture is complex, containing numerous distributed components, and these components need to maintain state consistency to ensure the overall coordinated operation of the system. Security state estimation enables it to accurately infer the true state of the system when facing potential security threats such as network attacks, data tampering, and sensor failures, providing reliable state information and ensuring the normal functioning of the system. On the other hand, as the scale of CPS continues to expand, traditional single-input single-output system state assessment algorithms can no longer meet current needs. Distributed consensus secure state estimation, by utilizing the local information of each distributed node for collaborative processing, can enhance the robustness and fault tolerance of the system while ensuring the accuracy of state estimation, effectively addressing complex security challenges, and effectively ensuring the safe, reliable and efficient operation of CPS.
[0038] Example 2: This invention provides a distributed consensus security state estimation method, comprising: Step 1: Initialize parameters , , , , , ,set up , , and system time Set to 1; Step 2: Calculate the FDIAO gain based on equation (9); Step 3: Develop attack signals based on equation (8) estimate; Step 4: Perform state prediction based on equations (5)-(6); Step 5: Update the upper bound of the covariance of the attack signal observation error based on equation (10). ; Step 6: Update the upper bound of the state prediction error covariance based on equation (16) ; Step 7: Calculate the filter gain matrix based on equation (15); Step 8: Calculate the consistency gain matrix based on equation (18); Step 9: Perform state estimation based on equation (7); Step 10: Update the upper bound of the state estimation error covariance based on equation (17) ; Step 11: If the time step has not been reached Then let If the condition is met, return to step 2; otherwise, end the loop.
[0039] exist Figure 1 Based on the aforementioned network topology, consider a linear time-invariant discrete system, whose system equations are:
[0040] in, For state vectors, This allows malicious attackers to inject FDI attack signals into the system's physical layer. Assume... ,in It is a known positive scalar. Represents a node In the The measurement output at a given moment. For nodes The measured attenuation coefficient is uniformly distributed in the interval. Random variables on. mean and variance They are respectively and . and Are they respectively satisfied? and An uncorrelated Gaussian white noise sequence. A, G, W, and Given a known matrix of appropriate dimension, and A is a stable matrix. Initial state. ,and and , , They are unrelated. Let's assume another... It is observable. It is controllable.
[0041] Besides attacks at the physical system layer, attackers can also randomly launch two types of network attacks on the wireless communication channels between adjacent nodes: DoS attacks and FDI attacks. Here, we use random Bernoulli sequences to describe DoS and FDI attacks, treating their occurrence as independent random processes:
[0042] This indicates that the attacker successfully entered the channel. Launch an FDI attack, and ; This indicates that no attack was initiated. The false data transmitted to the attacker, and satisfies , It is a known positive scalar. Similarly, This indicates that the attacker successfully entered the channel. Launch a DoS attack, and ; This indicates that no DoS attack was initiated. It is further assumed that at any given time, an attacker can only launch one type of attack at the communication channel layer, i.e. .therefore, At any moment, the sensor From the sensor The actual received data packets can be represented as:
[0043] sensor The structure of the distributed state estimator is as follows:
[0044] in, For sensors The neighbor set of nodes (excluding nodes) The one-step state prediction value. For is a sensor In the Attack signal The observed values. and These represent the filter gain and consistency gain to be designed, respectively.
[0045] First, we estimate the attack signal. We solve this using the False Data Injection Attack Observer (FDIAO). , see the following formula for details:
[0046] in, The FDIAO gain to be determined is given by the following formula:
[0047] in, and They are observation error covariance and mutual covariance The upper bounds are respectively denoted as:
[0048] , , , , and All are given positive scalars, and
[0049] Next, the Kalman filter gain is calculated. It is the first One sensor in The gain matrix at time step is primarily used to adjust the impact of measurement residuals (the difference between observed and predicted values) on state estimation. Its core function is to balance local measurements and neighbor node information under mixed attacks by optimizing the gain, ensuring the mean-square boundedness of the estimation error. See the following equation for details:
[0050] in, Represents a node The number of neighboring nodes, It is a given positive scalar. and These are the state prediction error covariance. and estimation error covariance The upper bounds are respectively denoted as:
[0051] Finally, we design the consistency gain. Mainly used for adjusting sensor nodes The filter assigns weights to neighbor node information when updating its state estimate. This ensures that the filter can still effectively estimate the system state even under complex cooperative attacks. Specifically, it determines the node's... How to combine the state predictions of neighboring nodes to correct one's own state estimate? See the following formula for details:
[0052] in, It is a positive scalar constant, usually taken as wait.
[0053] consider Figure 2 The control system of the continuous stirred tank reactor (CSTR) shown is illustrated. The system comprises a constant-volume continuous stirred tank reactor with a single inflow feed stream connected to two different source streams via a selector valve. Assuming constant liquid volume, negligible heat loss, thorough mixing, and that reactant A undergoes a first-order reaction, the proposed consensus-based distributed safety state estimation algorithm is applied to subsystem 1 of the CSTR. The system model is determined by (1), with the following parameters:
[0054]
[0055] Set initial state Initial covariance . and It is a zero-mean Gaussian sequence with covariances of... and Sensor networks, such as Figure 3 As shown, its network topology consists of It is represented that the set of nodes is edge set And the adjacent elements associated with the edges of the graph are . In the interval Uniformly distributed on top, other adjustable parameters are selected as follows: , , , ,in The simulation time is T=6s. Additionally, the attack occurrence time is set to 2.5s to 4.5s, and the probabilities of DoS attacks and FDI attacks on the communication channel are 0.2 and 0.3 respectively. , .
[0056] To demonstrate the effectiveness of the algorithm presented in this paper, two algorithms are selected for comparison: an algorithm from existing literature and an algorithm that ignores the attack estimation module. Detailed results of the comparative experiments are as follows: Figure 4 As shown.
[0057] Figure 4 The paper presents the estimation results of our proposed algorithm and existing algorithms for state 1, demonstrating that our proposed algorithm achieves better estimation performance. To further prove the effectiveness of the proposed algorithm, 500 Monte Carlo experiments were conducted, and the corresponding mean square error (MSE) was calculated, as follows: Figure 5 As shown, it is clear that the MSE of our proposed algorithm is much lower than that of algorithms in existing literature. (Comparison) Figure 4 and Figure 5 When the communication channel is subjected to DoS or FDI attacks, the estimation performance of existing algorithms is significantly lower than that of our algorithm, which proves the effectiveness of our proposed algorithm.
[0058] Figure 6 The proposed algorithm and the algorithm omitting the attack estimation module are presented as estimation results for state 1. It can be observed that the method using the attack estimation module has superior estimation performance. As shown in Figure 7, to further demonstrate the effectiveness of the proposed algorithm, 500 Monte Carlo experiments were conducted, and the corresponding MSEs were calculated. It is clear that our proposed algorithm has a lower MSE. Combined with... Figure 6 and Figure 7 Comparative analysis further demonstrates the effectiveness of the proposed algorithm and the necessity of the attack signal estimation module. These results show that even under attack, the algorithm can still achieve effective system state estimation while maintaining a low estimation error level, thus confirming its effectiveness.
[0059] In another embodiment of the present invention, a distributed consistency security state estimation system is provided, which can be used to implement the above-described distributed consistency security state estimation method. Specifically, the system includes: The initialization module is used to set the initial parameters and boundary conditions required for the linear time-invariant discrete system and to set the system's running time step to the initial value. The first update module is used to design the gain of the fake data injection attack observer. By using the deviation between this gain and the sensor's measurement output and the system state prediction value, the observation estimate of the physical layer malicious attack signal is obtained, and the upper bound of the covariance of the attack signal observation error is updated. The second update module is used to make state predictions based on the obtained state estimation results and update the upper bound of the covariance of the state prediction error; combined with the number of node neighbors, preset parameters and the updated upper bound of the covariance of the state prediction error, the Kalman filter gain is obtained to adjust the influence of the measurement residual. The output module is used to combine the obtained attack signal observations, Kalman filter gain, and consistency gain to complete the state estimation update for the current time step, and then update the upper bound of the covariance of the state estimation error; it determines whether the current time step has reached the preset maximum time step threshold. If it has not reached the threshold, the time step is updated and the process is repeated; if it has reached the threshold, the entire state estimation process ends.
[0060] The module division in this embodiment of the invention is illustrative and represents only one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the various embodiments of the invention can be integrated into a single processor, exist as separate physical entities, or be integrated into a single module. The integrated modules described above can be implemented in hardware or as software functional modules.
[0061] In another embodiment of the present invention, a computer device is provided, comprising a processor and a memory. The memory stores a computer program, which includes program instructions. The processor executes the program instructions stored in the computer storage medium. The processor may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing and control core of the terminal, suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions from the computer storage medium to achieve a corresponding method flow or corresponding function. The processor described in this embodiment of the present invention can be used for the operation of a distributed consensus security state estimation method.
[0062] In another embodiment of the present invention, a storage medium is provided, specifically a computer-readable storage medium (Memory), which is a memory device in a computer device used to store programs and data. It is understood that the computer-readable storage medium here can include both the built-in storage medium in the computer device and extended storage media supported by the computer device. The computer-readable storage medium provides storage space that stores the terminal's operating system. Furthermore, the storage space also stores one or more instructions suitable for loading and execution by a processor. These instructions can be one or more computer programs (including program code). It should be noted that the computer-readable storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device. The processor can load and execute one or more instructions stored in the computer-readable storage medium to implement the corresponding steps of the distributed consensus security state estimation method in the above embodiments.
[0063] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0064] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0065] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0066] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0067] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. A distributed consensus security state estimation method, characterized in that, include: Set the initial parameters and boundary conditions required for the linear time-invariant discrete system, and set the system running time step to the initial value; Design the gain of the fake data injection attack observer, and use the deviation between this gain and the sensor's measurement output and system state prediction to estimate the observation of malicious attack signals at the physical layer, and update the upper bound of the covariance of the attack signal observation error. Based on the obtained state estimation results, state prediction is performed, and the upper bound of the covariance of the state prediction error is updated. Combining the number of node neighbors, preset parameters, and the updated upper bound of the covariance of the state prediction error, the Kalman filter gain used to adjust the influence of measurement residuals is obtained. By combining the obtained attack signal observations, Kalman filter gain, and consistency gain, the state estimation of the current time step is updated, and then the upper bound of the covariance of the state estimation error is updated. It is then determined whether the current time step has reached the preset maximum time step threshold. If it has not reached the threshold, the time step is updated and the process is repeated. If it has reached the threshold, the entire state estimation process ends.
2. The distributed consensus security state estimation method according to claim 1, characterized in that, The process of setting the initial parameters and boundary conditions required for the linear time-invariant discrete system, and setting the system's running time step to its initial value, includes: For a linear time-invariant discrete system, the system equations are: in, For state vectors, To inject FDI attack signals into the system's physical layer by a malicious attacker; assuming ,in It is a known positive scalar; Represents a node In the The measurement output at a single instant; For nodes The measured attenuation coefficient is uniformly distributed in the interval. Random variables on; mean and variance They are respectively and ; and Are they respectively satisfied? and Uncorrelated Gaussian white noise sequences; A, G, W, and Let A be a known matrix of appropriate dimension, and let A be a stable matrix; initial state ,and and , , They are unrelated.
3. The distributed consensus security state estimation method according to claim 2, characterized in that, The gain of the designed fake data injection attack observer is used to estimate the physical layer malicious attack signal by using the deviation between this gain and the sensor's measurement output and system state prediction value, and to update the upper bound of the covariance of the attack signal observation error, including: Solving using the FDI attack observer , see the following formula for details: in, The FDIAO gain to be determined is given by the following formula: in, and They are observation error covariance and mutual covariance The upper bounds are respectively denoted as: , , , , and All are given positive scalars, and 。 4. The distributed consensus security state estimation method according to claim 3, characterized in that, The attacks include physical system-level attacks (DoS) and randomly initiated attacks (FDI) on wireless communication channels between neighboring nodes. DoS and FDI attacks are described using random Bernoulli sequences, treating their occurrence as independent random processes. This indicates that the attacker successfully entered the channel. Launch an FDI attack, and ; This indicates that no attack was initiated. The false data transmitted by the attacker, and satisfies , For a known positive scalar; similarly, This indicates that the attacker successfully entered the channel. Launch a DoS attack, and ; This indicates that no DoS attack was initiated; further, it is assumed that at any given time, an attacker can only launch one type of attack at the communication channel layer, i.e. ; At any moment, the sensor From the sensor The actual received data packets can be represented as: sensor The structure of the distributed state estimator is as follows: in, For sensors The one-step state prediction value of the neighbor set nodes; For is a sensor In the Attack signal Observed values; and These represent the filter gain and consistency gain to be designed, respectively.
5. The distributed consensus security state estimation method according to claim 4, characterized in that, The state prediction is performed based on the obtained state estimation results, and the upper bound of the covariance of the state prediction error is updated. By combining the number of node neighbors, preset parameters, and the upper bound of the updated state prediction error covariance, the Kalman filter gain used to adjust the influence of measurement residuals is obtained, including: It is the first One sensor in The gain matrix at time step is used to adjust the effect of the measurement residuals on the state estimation, as shown in the following formula: in, Represents a node The number of neighboring nodes, It is a given positive scalar. and These are the state prediction error covariance. and estimation error covariance The upper bounds are respectively denoted as: 。 6. The distributed consensus security state estimation method according to claim 1, characterized in that, The consistency gain design: Used to adjust sensor nodes The weighting of neighbor node information when updating its state estimate determines the node's position. How to combine the state predictions of neighboring nodes to correct one's own state estimate is shown in the following formula: in, It is a positive scalar constant.
7. The distributed consensus security state estimation method according to claim 1, characterized in that, The upper bound of the updated state estimation error covariance: If time step T is not reached, set k = k + 1 and return to re-execute; otherwise, end the loop.
8. A distributed consensus-based secure state estimation system, characterized in that, include: The initialization module is used to set the initial parameters and boundary conditions required for the linear time-invariant discrete system and to set the system's running time step to the initial value. The first update module is used to design the gain of the fake data injection attack observer. By using the deviation between this gain and the sensor's measurement output and the system state prediction value, the observation estimate of the physical layer malicious attack signal is obtained, and the upper bound of the covariance of the attack signal observation error is updated. The second update module is used to make state predictions based on the obtained state estimation results and update the upper bound of the covariance of the state prediction error; combined with the number of node neighbors, preset parameters and the updated upper bound of the covariance of the state prediction error, the Kalman filter gain is obtained to adjust the influence of the measurement residual. The output module is used to combine the obtained attack signal observations, Kalman filter gain, and consistency gain to complete the state estimation update for the current time step, and then update the upper bound of the covariance of the state estimation error; it determines whether the current time step has reached the preset maximum time step threshold. If it has not reached the threshold, the time step is updated and the process is repeated; if it has reached the threshold, the entire state estimation process ends.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the distributed consensus security state estimation method as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the distributed consensus security state estimation method as described in any one of claims 1 to 7.