Differential privacy-based anti-attack bipartite consistency control method for multi-agent system
By using random labels based on truncated normal distribution and a differentiated noise injection mechanism, the problems of identifying and protecting privacy in multi-agent systems against Sybil attacks and Byzantine attacks are solved, and binary consistency control with fast convergence under malicious attacks is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-22
- Publication Date
- 2026-04-10
AI Technical Summary
When facing malicious attacks and privacy risks, existing technologies struggle to effectively identify Sybil attacks and Byzantine attacks in multi-agent systems, and differential privacy methods negatively impact the system's consistency convergence speed.
A random labeling mechanism based on truncated normal distribution is used to generate non-copyable dynamic labels. A differentiated noise injection mechanism is used to differentiate cooperative and competitive neighbor agents. A differential privacy mechanism is used to filter witch nodes. An attack-resistant binary consistency control input is calculated and the agent state is updated.
Effectively identify and eliminate witch nodes, reduce the impact of Byzantine nodes, flexibly adjust the privacy protection level, and improve the system's convergence speed and robustness under hybrid attacks.
Smart Images

Figure CN121841807A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of multi-agent control technology, and in particular to a binary consensus control method for multi-agent systems based on differential privacy to resist attacks. Background Technology
[0002] Multi-agent systems have been widely applied in fields such as robot collaboration, intelligent transportation, and satellite formation. In real-world networks, agents not only have cooperative relationships but may also compete with each other; such networks are called symbolic graphs, and the corresponding control problem is called the binary consistency problem. However, in practical deployments, multi-agent systems face two major challenges:
[0003] Malicious attacks threaten the system not only with traditional denial-of-service or spoofing attacks, but also with a hybrid threat of Sybil attacks and Byzantine attacks. Sybil attacks allow attackers to forge a large number of false identities, undermining the assumption in traditional defense strategies that the number of malicious nodes is below a certain threshold.
[0004] Privacy risks exist because intelligent agents directly transmit state information during interactions, which can easily lead to the leakage of sensitive data. Although differential privacy is the mainstream protection method, traditional methods can reduce the consistency convergence speed of the system.
[0005] Existing methods for detecting Sybil attacks are mostly based on network topology statistics (such as changes in node degree). The drawback is that the applicability of these methods decreases significantly when the density or number of Sybil nodes is too high. In addition, existing methods rarely consider mixed attack scenarios where Sybil attacks and Byzantine attacks coexist.
[0006] Existing differential privacy typically injects the same distribution of noise into all interacting nodes (whether cooperative or competitive). While this uniform noise injection method protects privacy, it negatively impacts the consistency dynamics of the system, lacks the flexibility to adjust, and negatively affects the convergence speed of the system. Summary of the Invention
[0007] The purpose of this invention is to overcome the shortcomings of the prior art and provide an attack-resistant binary consensus control method for multi-agent systems based on differential privacy. While ensuring differential privacy, the method can adjust the privacy protection level as needed according to different situations, thereby accelerating the convergence speed of binary consensus.
[0008] To achieve the above objectives, the present invention is implemented using the following technical solution:
[0009] On one hand, this invention provides an attack-resistant binary consensus control method for multi-agent systems based on differential privacy, comprising: Based on a random sampling process based on a truncated normal distribution, labels for each agent in a pre-constructed multi-agent system are generated. Based on the cooperative and competitive relationships among agents in a multi-agent system, differentiated noise is injected into the state of each agent to obtain the noise state of each agent. Each agent sends its label and noise state to its neighboring agents. Based on the differential privacy mechanism, neighboring agents with the same label are grouped together for neighboring agent filtering to obtain a set of safe neighboring agents and their noise states. Based on the set of secure neighbor agents, calculate the anti-attack binary consensus control input for each agent; Based on the anti-attack binary consensus control input of each agent, the state of each agent is updated to obtain the anti-attack binary consensus control result.
[0010] Optionally, the construction of the multi-agent system includes: The communication topology of the multi-agent system is constructed as a signed directed topological graph. The signed directed topological graph is a structural equilibrium graph; wherein, Represents a set of intelligent agents; Indicates the number of agents; Represents the set of edges; Represents the adjacency matrix; express A real matrix of order 1; This represents the cooperative and competitive relationship between agents i and j. This indicates that there is a cooperative relationship between agents i and j. This indicates that there is a competitive relationship between agents i and j; Constructing the Laplace matrix of multi-agent agents ;in, ; ;in, This represents the element in the Laplace matrix with agent i as the row and column number; This represents the element in the Laplace matrix with agent i as the row and agent j as the column; Construct a multi-agent system based on a signed directed topological graph and a Laplace matrix.
[0011] Optionally, labels for each agent in a pre-built multi-agent system are generated based on a random sampling process using a truncated normal distribution, including: In a multi-agent system, each agent has the same sampling range, and each agent in Within the sampling range, generate labels for each agent; The labels of each agent follow a truncated normal distribution function, expressed as: ; ; in, Indicates time The label of agent i; This indicates that agent i follows a truncated normal distribution function as its mean. The variance indicates that agent i follows a truncated normal distribution function; Let represent the minimum and maximum sampled values of agent i, respectively; This represents the truncated normal distribution function; Indicates the number of intelligent agents.
[0012] Optionally, the noise state of each agent is represented as follows: ; ; ; ; in, Indicates time The noise state of agent i; Indicates time The initial state of agent i; Indicates time The cooperative and competitive relationship between agents i and j; Represents the set of unattacked intelligent agents; Indicates time Noise injected by agent i when transmitting state values to competing neighboring agents; Indicates time Noise injected by agent i when transmitting state values to cooperating neighbor agents; Represents a symbolic function; Indicates noise The parameters of the Laplace distribution it follows; noise The parameters of the Laplace distribution it follows; Indicates the Laplace distribution; Represents a constant greater than 0 corresponding to agent i; Indicates time A constant greater than 0 and less than 1 corresponding to agent i; This indicates a demand for expectation; This indicates the calculation of variance.
[0013] Optionally, the differential privacy mechanism includes: The initial first state set of the agent and the initial second state set yes Adjacent, exist , making ;in, express and The maximum permissible difference between individuals in a single state; Let these represent the initial first state and the initial second state of agent i, respectively. Represents the set of unattacked intelligent agents; Represents any intelligent agent; Random mechanism yes Differentially private, for any two Adjacent initial first state set and the initial second state set and , making This leads to a differential privacy mechanism; among which, : , The space representing the initial set of intelligent agents. This represents the space that all intelligent agents can observe. Represents a mapping; Indicates the privacy level; Indicates the number of agents; Represents the probability of a random variable; Represents the set of real numbers; Represents the natural base.
[0014] Optionally, neighboring agents with the same label can be grouped together for neighbor agent filtering to obtain a set of safe neighboring agents and their noise states, including: Agent i receives a tag sent by its neighbor agent j With noise state Then, neighboring agents with the same label are grouped together to obtain all label groups, and the number of label groups is recorded. The set of witch nodes consists of all neighboring agents with the same label. ; like Then remove the witch node set. The remaining neighbor agents are the set of safe neighbor agents. This yields the set of safe neighbor agents and their noise states. like Then calculate the number of remaining possible Byzantine nodes. ,calculate ,Will Divided into and ; like Then from Remove from One maximum value; otherwise, from [the maximum value]. Remove all values from the middle; like Then from Remove from The minimum value; otherwise, from Remove all values from the middle; Will still be The neighbor agents in the data are a set of secure neighbor agents. This yields the set of safe neighbor agents and their noise states. in, Indicates time The label of agent j; Indicates time A set of witch nodes; Indicates time The set of secure neighboring smart agents of agent i; This represents the maximum sum of the local witch node and the Byzantine node; This represents the set of neighbors that transmit state values to agent i. Indicates time After excluding the set of witch nodes, agent i receives the set of all noisy state values; Indicates time The noise state of agent i; Indicates time The initial state of agent i; Indicates in set All ratios A set of state values; Indicates in set All ratios A small set of state values.
[0015] Optionally, the attack-resistant binary consensus control input for each agent is represented as follows: ; in, Indicates time The attack-resistant binary consistency control input for agent i; Indicates controller; Indicates time The set of secure neighboring smart agents of agent i; Indicates time The cooperative and competitive relationship between agents i and j; Indicates time The noise state of agent i; Indicates time The initial state of agent i; Represents a symbolic function.
[0016] Optionally, the state update formula for each agent is as follows: ; in, They represent time. The updated state and the original state of agent i; Indicates controller; Indicates time The set of secure neighboring smart agents of agent i; Indicates time The cooperative and competitive relationship between agents i and j; Represents a symbolic function; Indicates time The noise state of agent i.
[0017] Secondly, this invention provides an attack-resistant binary consensus control system for multi-agent systems based on differential privacy, comprising:
[0018] The label generation module is used to generate labels for each agent in a pre-built multi-agent system based on a random sampling process based on a truncated normal distribution.
[0019] The noise injection module is used to inject differentiated noise into the state of each agent based on the cooperative and competitive relationship between agents in a multi-agent system, so as to obtain the noise state of each agent.
[0020] The differential privacy module is used to: send the labels and noise states of each agent to its neighboring agents; and according to the differential privacy mechanism, group neighboring agents with the same labels into the same group for neighboring agent filtering to obtain a set of safe neighboring agents and their noise states.
[0021] The control calculation module is used to: calculate the anti-attack binary consensus control input for each agent based on the set of secure neighbor agents;
[0022] The control generation module is used to update the state of each agent based on the anti-attack binary consensus control input of each agent, and obtain the anti-attack binary consensus control result.
[0023] Thirdly, the present invention provides a computer-readable storage medium having a computer program / instruction stored thereon, which, when executed by a processor, implements the steps of the attack-resistant binary consensus control method for multi-agent systems based on differential privacy described in the first aspect.
[0024] Compared with the prior art, the beneficial effects achieved by the present invention are as follows:
[0025] This invention generates non-replicable dynamic labels through a random labeling mechanism based on a truncated normal distribution, effectively identifying and eliminating witch nodes. Even when witch nodes are dominant, the system remains resilient, and a filtering mechanism reduces the impact of remaining Byzantine nodes. Through a differentiated noise injection mechanism, Laplace noise with different distributions is injected for cooperative and competitive agents. This allows for flexible customization of the balance between privacy protection level and control performance based on the ratio of cooperative to competitive connections in the actual network. While ensuring differential privacy, the privacy protection level can be adjusted as needed according to different situations, accelerating the convergence speed of binary consensus. Attached Figure Description
[0026] Figure 1 The diagram shown is a flowchart of one embodiment of the attack-resistant binary consensus control method for multi-agent systems based on differential privacy according to the present invention.
[0027] Figure 2 The diagram shown is a structural schematic of the multi-agent system of the present invention in one embodiment;
[0028] Figure 3 The diagram shown is a schematic representation of the structure of the signed directed topological graph of the present invention in one embodiment.
[0029] Figure 4 The figure shown is a schematic diagram of the state trajectory of the intelligent agent under different noise injections in one embodiment of the present invention;
[0030] Figure 5 The figure shown is a schematic diagram of the state trajectory of an agent under the same noise injection in one embodiment of the present invention.
[0031] Figure 6 The diagram shown is a schematic representation of the state trajectory of an agent in one embodiment of the prior art.
[0032] Figure 7 The diagram shown is a schematic representation of the structure of a signed directed topology graph with a high proportion of witch nodes in one embodiment of the present invention.
[0033] Figure 8 The diagram shown is a schematic representation of the state trajectory of an agent with a high proportion of witch nodes in one embodiment of the present invention. Detailed Implementation
[0034] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present invention and the specific features in the embodiments are detailed descriptions of the technical solution of the present invention, rather than limitations thereof. In the absence of conflict, the embodiments of the present invention and the technical features in the embodiments can be combined with each other.
[0035] The term "and / or" simply describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. Additionally, the character " / " generally indicates that the preceding and following related objects have an "or" relationship.
[0036] Example 1
[0037] like Figure 1 As shown in the figure, this embodiment introduces an attack-resistant binary consensus control method for multi-agent systems based on differential privacy, including the following steps:
[0038] Step 1: Construct a multi-agent system, specifically as follows:
[0039] The communication topology of a multi-agent system communication network is constructed as a signed directed topology graph. A signed directed topological graph is a structural equilibrium graph.
[0040] in, This represents a set of intelligent agents, i.e., a set of nodes; Indicates the number of agents; Represents the set of edges; Represents the adjacency matrix; express A real matrix of order 1; This represents the cooperative and competitive relationship between agents i and j. This indicates that there is a cooperative relationship between agents i and j. This indicates that there is a competitive relationship between agents i and j; if and only if hour ,otherwise .
[0041] The in-neighbor set of agent i and neighbors If a signed directed topology graph contains a directed spanning tree, then the graph is said to contain a directed spanning tree.
[0042] Constructing the Laplace matrix of multi-agent agents ;in, ; ;in, This represents the element in the Laplace matrix with agent i as the row and column number; This represents the element in the Laplace matrix with agent i as the row and agent j as the column.
[0043] If and only if there is a signed directed topological graph There exists a set of nodes. The set of binary partition nodes This makes for ,have In other cases This is equivalent to the existence of a diagonal matrix. , This makes the transformed Laplace matrix It is positive semidefinite.
[0044] Construct a multi-agent system based on a signed directed topological graph and a Laplace matrix, such as... Figure 2 As shown, each intelligent agent includes sensors, actuators, controllers, and differential privacy devices.
[0045] In a signed directed topological graph middle, If a node, Make Then the non-empty set yes accessible ( ), Represents the number of edges pointing from outside a set to a node inside that set; a signed directed topological graph. It is itself Robust if for any pair of non-empty, disjoint sets , At least one of them is It is accessible.
[0046] In multi-agent systems, data transmission between agents occurs on a shared network, which faces three types of threats: eavesdropping, Sybil attacks, and Byzantine attacks. The specific attack models are described below:
[0047] Eavesdropping aims to secretly extract sensitive system data without interfering with control algorithms. Eavesdroppers can obtain the complete network topology, monitor communication signals between all nodes, and infer the target's state through signal analysis.
[0048] In a Byzantine attack, certain agents are called Byzantine nodes. Byzantine nodes are either compromised by an adversary or are malicious in nature. These nodes deviate from predefined protocols and may send arbitrary forged or false messages to other agents with the aim of disrupting collective coordination and preventing the system from reaching the correct consensus.
[0049] In a Sybil attack, the attacker compromises a vulnerable agent to generate multiple false identities. Even highly secure agents can be manipulated to spread forged identities. The primary goal of a Sybil attack is to maximize the adversary's influence within the target system, ultimately disrupting the system's consensus. For clarity, we refer to the original compromised node as the Sybil parent node, and the forged identities cloned from it as Sybil child nodes. The agent j gains unrestricted access to all incoming and outgoing communications to the damaged node, evades detection by using a replicated identity, establishes communication channels with the damaged node's neighbors and exchanges data, and violates the specified control protocol by transmitting false data to neighboring nodes. The corresponding witch child node of agent j is... .
[0050] In a signed directed topological graph At any given time, the number of Byzantine nodes and witch father nodes adjacent to any node in the graph does not exceed [a certain threshold]. At that time, it happened to be affected Local attacks, signed directed topological graphs It is directional, structurally balanced, and has a spanning tree, to which all attack threats follow. Local attack model; where, This represents the maximum sum of the local witch node and the Byzantine node.
[0051] Step 2: Construct a differential privacy mechanism, specifically as follows:
[0052] In a signed directed topological graph In this context, agents exchange information to achieve binary consensus. However, directly transmitting raw data may lead to significant privacy risks. Differential privacy provides a rigorous framework that mitigates these risks by introducing carefully calibrated noise, typically from a Laplace or Gaussian distribution, into the shared information. This ensures that individual data remains indistinguishable between agents, thereby protecting privacy without hindering the overall consensus process.
[0053] Define a random mechanism : ,in, The space representing the initial set of intelligent agents. This represents the space that all intelligent agents can observe. Representation or mapping.
[0054] Given The initial first state set of the intelligent agent and the initial second state set yes Adjacent, exist , making ;in, express and The maximum permissible difference between individuals in a single state is used to define... Adjacent relationship; Let these represent the initial first state and the initial second state of agent i, respectively. Represents the set of unattacked intelligent agents; Represents agent i0.
[0055] Given random mechanism yes Differentially private, for any two Adjacent initial first state set and the initial second state set and , making This leads to a differential privacy mechanism; among which, Indicates the privacy level; Indicates the number of agents; Represents the probability of a random variable; Represents the set of real numbers; Represents the natural base.
[0056] Consider the following: In a linear discrete-time multi-agent system consisting of *i* agents, the state of agent *i* is represented as:
[0057] ;
[0058] in, They represent time. The updated state and the original state of agent i; Indicates time Anti-attack binary consistency control input for agent i.
[0059] The purpose of this embodiment is to design an attack-resistant binary consensus control input to ensure mean-squared dual consensus among normal nodes, while maintaining stability throughout the entire system. Differential privacy.
[0060] Step 3: Generate labels for each agent in the multi-agent system, specifically:
[0061] To enhance the system's resistance to witch attacks, a random label verification mechanism was developed.
[0062] Random labels are generated for each agent in a multi-agent system using a random sampling process based on a truncated normal distribution. The total length of all random sampling labels for each agent is 1, and each agent has the same sampling range. The minimum value of the sampled data of agent i Maximum sampling value In other words, in time Label of agent i satisfy .
[0063] To avoid different nodes generating the same label value, each agent... Within the sampling range, labels are generated for each agent; the labels of each agent follow a truncated normal distribution function, expressed as:
[0064] ;
[0065] in, This indicates that agent i follows a truncated normal distribution function, representing the mean of the label or its center position; The variance represents the variance of agent i following a truncated normal distribution function, quantifying the degree of dispersion of the label value around the mean; This represents the truncated normal distribution function.
[0066] Step 4: Differentiated privacy noise injection of agent state, specifically as follows:
[0067] Different noise parameters are injected into cooperative and competitive neighbors. Based on the cooperative and competitive relationships among agents in a multi-agent system, differentiated noise is injected into the state of each agent, defining... For the set of all unattacked agents, in time any noise status Represented as:
[0068] ;
[0069] in:
[0070] ;
[0071] ;
[0072] ;
[0073] in, Indicates time The noise state of agent i; Indicates time The initial state of agent i; Indicates time The cooperative and competitive relationship between agents i and j; Represents the set of unattacked intelligent agents; Indicates time Noise injected by agent i when transmitting state values to competing neighboring agents; Indicates time Noise injected by agent i when transmitting state values to cooperating neighbor agents; Represents a symbolic function; Indicates noise The parameters of the Laplace distribution it follows; noise The parameters of the Laplace distribution it follows; Indicates the Laplace distribution; Represents a constant greater than 0 corresponding to agent i; Indicates time A constant greater than 0 and less than 1 corresponding to agent i; This indicates a demand for expectation; This indicates the calculation of variance.
[0074] In time Label of agent i With noise state It is sent to its neighboring intelligent agents, i.e., external neighbors.
[0075] Step 5: Filter neighbor agents to obtain a set of safe neighbor agents, specifically:
[0076] In time Agent i receives the label from agent j. With noise state Then, neighboring agents with the same label are grouped together, considered as originating from the same parent node's Sybil attack, thus obtaining all label groups and recording the number of label groups. The set of witch nodes consists of all neighboring agents with the same label. ;
[0077] like Then remove the witch node set. The remaining neighbor agents are the set of safe neighbor agents. This yields the set of safe neighbor agents and their noise states.
[0078] like Then calculate the number of remaining possible Byzantine nodes. ,calculate ,Will Divided into and ;
[0079] like Then from Remove from One maximum value; otherwise, from [the maximum value]. Remove all values from the middle;
[0080] like Then from Remove from The minimum value; otherwise, from Remove all values from the middle;
[0081] Will still be The neighbor agents in the data are a set of secure neighbor agents. This yields the set of safe neighbor agents and their noise states.
[0082] in, Indicates time A set of witch nodes; Indicates time The set of secure neighboring smart agents of agent i; This represents the maximum sum of the local witch node and the Byzantine node; This represents the set of neighbors that transmit state values to agent i. Indicates time After excluding the set of witch nodes, agent i receives the set of all noisy state values; Indicates in set All ratios A large set of state values; Indicates in set All ratios A small set of state values.
[0083] Step Six: Calculate the attack-resistant binary consensus control input for the agent, specifically:
[0084] Based on the filtered set of secure neighbor agents Calculate the attack-resistant binary consistency control input for each agent, in time... Attack-resistant binary consistency control input for agent i Represented as:
[0085] ;
[0086] in, The controller is represented by a constant. Indicates time The cooperative and competitive relationship between agents i and j; Represents a symbolic function.
[0087] Step 7: Update the agent's state to implement attack-resistant binary consensus control, specifically as follows:
[0088] For each unattacked agent, based on the anti-attack binary consensus control input, update the state of each agent to obtain the anti-attack binary consensus control result, in time... The formula for updating the state of agent i is:
[0089] .
[0090] The process of selecting effective neighbors involves retaining only a subset of neighbor values for state updates. Specifically, in time... From the initial signed directed topology Remove certain edges from the graph. The resulting signed directed topology is denoted as . .
[0091] Example 2
[0092] Based on Example 1, this example presents an experimental example of an attack-resistant binary consensus control method for multi-agent systems based on differential privacy:
[0093] This embodiment constructs a multi-agent system containing 10 agents for simulation experiments.
[0094] General simulation environment settings:
[0095] Signed directed topological graphs such as Figure 3 As shown, the system consists of 10 nodes, numbered 1 to 10.
[0096] The nodes are grouped, and the network structure is balanced, divided into two camps: Camp 1 Faction 2 There are cooperative relationships between nodes within the faction (such as...) Figure 3 The blue solid line indicates a positive weight, and there is competition between factions (e.g., ...). Figure 3 The red dashed line is shown, with a negative weight.
[0097] Adjacency Matrix .
[0098] The signed directed topological graph satisfies the 3 robustness conditions, and the attack model is set to the 1 local attack model.
[0099] Unattacked intelligent systems may introduce noise to protect their privacy information, namely the noise injected in this paper.
[0100] Byzantine agents, by definition, are malicious nodes that do not follow established update rules and can arbitrarily modify their behavior to disrupt system consensus. The purpose of these malicious nodes introducing noise is to interfere with the consensus process, test the system's robustness, and simulate non-cooperative behavior in real-world scenarios. In real-world systems, these malicious nodes may: use different noise distributions, dynamically adjust noise parameters, or even send forged values without adding any noise at all. Therefore, setting inconsistent noise parameters in instances better reflects real-world attack scenarios and is more conducive to evaluating the algorithm's defense capabilities.
[0101] The witch node typically replicates an unattacked agent and transmits extreme values to the normal agent by forging child nodes, thereby disrupting the consistency of the system.
[0102] In one specific embodiment, the system is defended against hybrid attacks (coexistence of Sybil and Byzantine attacks) to verify its resilient and consistent convergence performance when subjected to both Sybil and Byzantine attacks simultaneously.
[0103] Attack scenario setup:
[0104] The witch attack: The attacker duplicates node 9's identity to create a witch child node (labeled node 11). Node 11 uses the same random label as node 9. and send a constant error status value to the neighbor. ;in, Indicates time The label for Agent 9; Indicates time The noise state of agent 11.
[0105] Byzantine attack: Node 10 is configured as a Byzantine node, which does not follow state update rules but instead sends time-varying attack data to its neighbors. ;in, Indicates time The noise state of agent 10; This represents the noise injected by Byzantine agent 10.
[0106] Among them, the noise injected by the Byzantine agents ,set up , ;in, This represents the noise injected by the Byzantine-style intelligent agent j; This represents a positive constant corresponding to the Byzantine agent j; Indicates time A constant greater than 0 and less than 1 corresponding to the Byzantine agent j.
[0107] System initialization parameters: Initial state vector .
[0108] Controller and Privacy Parameters: Controller Competition channel noise parameters Collaborative channel noise parameters Noise attenuation factor .
[0109] like Figure 4 As shown, despite the deception of node 11 and the malicious interference of node 10, the state trajectories of normal nodes (1-9) eventually converge to two values with equal magnitude but opposite signs (i.e., achieving binary consensus). (Comparison) Figure 5 The results show that the differentiated noise injection strategy (i.e., cooperative channel) adopted in this embodiment is effective. Less than the competition channel Its convergence speed is significantly faster than the traditional method of uniformly injecting large noise. (Comparison) Figure 6 The results demonstrate the effectiveness of this embodiment in resisting hybrid attacks.
[0110] In another specific embodiment, the system's effectiveness is verified in extreme cases where the number of witch nodes is extremely large (even exceeding the number of normal neighbors) to defend against high-intensity Sybil attacks (where the number of witch nodes is dominant):
[0111] Attack scenario setup:
[0112] Topological transformations of signed directed topological graphs: such as Figure 7 As shown, the attack intensity has increased.
[0113] The Sybil attack on node 9: The attacker generated three Sybil child nodes (9a, 9b, 9c) based on node 9, and the constant attack values they sent were as follows: , , .
[0114] The Sybil attack on node 10: The attacker generated three Sybil child nodes (10a, 10b, 10c) based on node 10, and the constant attack values they sent were as follows: , ,
[0115] System initialization parameters: Initial state vector .
[0116] Other parameters: Controller Competition channel noise parameters Collaborative channel noise parameters Noise attenuation factor .
[0117] like Figure 8 As shown, using this random label verification mechanism, normal nodes can successfully identify and eliminate all witch nodes by detecting identical labels (e.g., nodes 9a, 9b, and 9c all carry the same label as node 9). The system ultimately achieves binary consensus, proving the robustness of the algorithm in scenarios with high witch node density.
[0118] Example 3
[0119] This embodiment introduces an attack-resistant binary consensus control system based on multi-agent differential privacy, including:
[0120] The label generation module is used to generate labels for each agent in a pre-built multi-agent system based on a random sampling process based on a truncated normal distribution.
[0121] The noise injection module is used to inject differentiated noise into the state of each agent based on the cooperative and competitive relationship between agents in a multi-agent system, so as to obtain the noise state of each agent.
[0122] The differential privacy module is used to: send the labels and noise states of each agent to its neighboring agents; and according to the differential privacy mechanism, group neighboring agents with the same labels into the same group for neighboring agent filtering to obtain a set of safe neighboring agents and their noise states.
[0123] The control calculation module is used to: calculate the anti-attack binary consensus control input for each agent based on the set of secure neighbor agents;
[0124] The control generation module is used to update the state of each agent based on the anti-attack binary consensus control input of each agent, and obtain the anti-attack binary consensus control result.
[0125] The specific functions of each module described above are explained in the relevant content of Embodiment 1 or 2, and will not be repeated here.
[0126] Example 4
[0127] This embodiment introduces a computer-readable storage medium storing a computer program / instruction thereon. When the computer program / instruction is executed by a processor, it implements the steps of the attack-resistant binary consensus control method for multi-agent systems based on differential privacy as described in Embodiment 1 or 2.
[0128] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0129] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0130] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0131] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0132] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of the present invention without departing from the spirit and scope of the claims. All of these forms are within the protection scope of the present invention.
Claims
1. A binary consensus control method for multi-agent systems based on differential privacy, characterized in that, include: Based on a random sampling process based on a truncated normal distribution, labels for each agent in a pre-constructed multi-agent system are generated. Based on the cooperative and competitive relationships among agents in a multi-agent system, differentiated noise is injected into the state of each agent to obtain the noise state of each agent. Each agent sends its label and noise state to its neighboring agents. Based on the differential privacy mechanism, neighboring agents with the same label are grouped together for neighboring agent filtering to obtain a set of safe neighboring agents and their noise states. Based on the set of secure neighbor agents, calculate the anti-attack binary consensus control input for each agent; Based on the anti-attack binary consensus control input of each agent, the state of each agent is updated to obtain the anti-attack binary consensus control result.
2. The attack-resistant binary consensus control method for multi-agent systems based on differential privacy according to claim 1, characterized in that, The construction of the multi-agent system includes: The communication topology of the multi-agent system is constructed as a signed directed topological graph. The signed directed topological graph is a structural equilibrium graph; wherein, Represents a set of intelligent agents; Indicates the number of agents; Represents the set of edges; Represents the adjacency matrix; express A real matrix of order 1; This represents the cooperative and competitive relationship between agents i and j. This indicates that there is a cooperative relationship between agents i and j. This indicates that there is a competitive relationship between agents i and j; Constructing the Laplace matrix of multi-agent agents ;in, ; ;in, This represents the element in the Laplace matrix with agent i as the row and column number; This represents the element in the Laplace matrix with agent i as the row and agent j as the column; Construct a multi-agent system based on a signed directed topological graph and a Laplace matrix.
3. The attack-resistant binary consensus control method for multi-agent systems based on differential privacy according to claim 1, characterized in that, Based on a random sampling process using a truncated normal distribution, labels for each agent in a pre-built multi-agent system are generated, including: In a multi-agent system, each agent has the same sampling range, and each agent in Within the sampling range, generate labels for each agent; The labels of each agent follow a truncated normal distribution function, expressed as: ; ; in, Indicates time The label of agent i; This indicates that agent i follows a truncated normal distribution function as its mean. The variance of agent i indicates that it follows a truncated normal distribution function; Let represent the minimum and maximum sampled values of agent i, respectively; This represents the truncated normal distribution function; Indicates the number of intelligent agents.
4. The attack-resistant binary consensus control method for multi-agent systems based on differential privacy according to claim 1, characterized in that, The noise state of each agent is represented as follows: ; ; ; ; in, Indicates time The noise state of agent i; Indicates time The initial state of agent i; Indicates time The cooperative and competitive relationship between agents i and j; Represents the set of unattacked intelligent agents; Indicates time Noise injected by agent i when transmitting state values to competing neighboring agents; Indicates time Noise injected by agent i when transmitting state values to cooperating neighbor agents; Represents a symbolic function; Indicates noise The parameters of the Laplace distribution it follows; noise The parameters of the Laplace distribution it follows; Indicates the Laplace distribution; Represents a constant greater than 0 corresponding to agent i; Indicates time A constant greater than 0 and less than 1 corresponding to agent i; This indicates a demand for expectation; This indicates the calculation of variance.
5. The attack-resistant binary consensus control method for multi-agent systems based on differential privacy according to claim 1, characterized in that, The differential privacy mechanism includes: The initial first state set of the agent and the initial second state set yes Adjacent, exist , making ;in, express and The maximum permissible difference between individuals in a single state; Let these represent the initial first state and the initial second state of agent i, respectively. Represents the set of unattacked intelligent agents; Represents any intelligent agent; Random mechanism yes Differentially private, for any two Adjacent initial first state set and the initial second state set and , making This leads to a differential privacy mechanism; among which, : , The space representing the initial set of intelligent agents. This represents the space that all intelligent agents can observe. Represents a mapping; Indicates the privacy level; Indicates the number of agents; Represents the probability of a random variable; Represents the set of real numbers; Represents the natural base.
6. The attack-resistant binary consensus control method for multi-agent systems based on differential privacy according to claim 1, characterized in that, Among the various agents, neighboring agents with the same label are grouped together for neighbor agent filtering, resulting in a set of safe neighbor agents and their noise states, including: Agent i receives a tag sent by its neighbor agent j With noise status Then, neighboring agents with the same label are grouped together to obtain all label groups, and the number of label groups is recorded. The set of witch nodes consists of all neighboring agents with the same label. ; like Then remove the witch node set. The remaining neighbor agents are the set of safe neighbor agents. This yields the set of safe neighbor agents and their noise states. like Then calculate the number of remaining possible Byzantine nodes. ,calculate ,Will Divided into and ; like Then from Remove from One maximum value; otherwise, from [the maximum value]. Remove all values from the middle; like Then from Remove from The minimum value; otherwise, from Remove all values from the middle; Will still be The neighbor agents in the data are a set of secure neighbor agents. This yields the set of safe neighbor agents and their noise states. in, Indicates time The label of agent j; Indicates time A set of witch nodes; Indicates time The set of secure neighboring smart agents of agent i; This represents the maximum sum of the local witch node and the Byzantine node; This represents the set of neighbors that transmit state values to agent i. Indicates time After excluding the set of witch nodes, agent i receives the set of all noisy state values; Indicates time The noise state of agent i; Indicates time The initial state of agent i; Indicates in set All ratios A set of state values; Indicates in set All ratios A small set of state values.
7. The attack-resistant binary consensus control method for multi-agent systems based on differential privacy according to claim 1, characterized in that, The attack-resistant binary consensus control input for each agent is represented as follows: ; in, Indicates time The attack-resistant binary consistency control input for agent i; Indicates controller; Indicates time The set of secure neighboring smart agents of agent i; Indicates time The cooperative and competitive relationship between agents i and j; Indicates time The noise state of agent i; Indicates time The initial state of agent i; Represents a symbolic function.
8. The attack-resistant binary consensus control method for multi-agent systems based on differential privacy according to claim 1, characterized in that, The state update formula for each agent is as follows: ; in, They represent time. The updated state and the original state of agent i; Indicates controller; Indicates time The set of secure neighboring smart agents of agent i; Indicates time The cooperative and competitive relationship between agents i and j; Represents a symbolic function; Indicates time The noise state of agent i.
9. A multi-agent system attack-resistant binary consensus control system based on differential privacy, characterized in that, include: The label generation module is used to generate labels for each agent in a pre-built multi-agent system based on a random sampling process based on a truncated normal distribution. The noise injection module is used to inject differentiated noise into the state of each agent based on the cooperative and competitive relationship between agents in a multi-agent system, so as to obtain the noise state of each agent. The differential privacy module is used to: send the labels and noise states of each agent to its neighboring agents; and according to the differential privacy mechanism, group neighboring agents with the same labels into the same group for neighboring agent filtering to obtain a set of safe neighboring agents and their noise states. The control calculation module is used to: calculate the anti-attack binary consensus control input for each agent based on the set of secure neighbor agents; The control generation module is used to update the state of each agent based on the anti-attack binary consensus control input of each agent, and obtain the anti-attack binary consensus control result.
10. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instruction is executed by the processor, it implements the steps of the attack-resistant binary consensus control method for multi-agent systems based on differential privacy as described in any one of claims 1 to 8.