A false data injection attack identification method based on adaptive residual weighted PINN

By using an adaptive residual weighted PINN network, combined with the physical topology and operating rules of the industrial control system, data weights are dynamically adjusted to identify and defend against fake data injection attacks. This solves the identification problem in existing technologies and achieves efficient and accurate state estimation and rapid fault location in the absence of attack samples.

CN122027371BActive Publication Date: 2026-07-24NANJING UNIV OF SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NANJING UNIV OF SCI & TECH
Filing Date
2026-04-15
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing industrial control system defenses struggle to identify sophisticated fake data injection attacks, especially when there is a lack of large numbers of attack samples. Furthermore, traditional methods are prone to sacrificing the constraints of physical laws when faced with large-scale fake data injections, leading to inaccurate state estimations.

Method used

An adaptive residual weighted physical information neural network (PINN) is adopted. By constructing an adaptive residual weighted network, the weights of measurement data are dynamically adjusted in combination with the physical topology and operating rules of the industrial control system. The network is trained using the gradient descent algorithm to achieve the identification and defense against false data injection attacks.

Benefits of technology

In the event that multiple sensors have been significantly maliciously tampered with, the system maintains the accuracy of state estimation, lowers the data threshold, does not rely on a large number of historical attack samples, provides good interpretability, quickly locates the attacked device, and shortens the troubleshooting time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122027371B_ABST
    Figure CN122027371B_ABST
Patent Text Reader

Abstract

The application provides a false data injection attack identification method based on an adaptive residual weighted PINN, comprising the following steps: constructing a physical equation describing the running state of a system; constructing an adaptive residual weighted network, wherein the adaptive residual weighted network takes sensor measurement data with noise or attack as input and reconstructed system state as output; training the adaptive residual weighted network by using a gradient descent algorithm; mapping the sensor data into system state meeting physical consistency in real time by using the adaptive residual weighted network; and identifying the false data injection attack through a double criterion mechanism according to the weight coefficient and physical residual information calculated by the adaptive residual weighted network in real time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of industrial control system security technology, specifically a method for identifying spoofed data injection attacks based on adaptive residual weighted PINN. Background Technology

[0002] Industrial Control Systems (ICS) are the core "nerve center" of critical infrastructure such as power, oil and petrochemical, rail transportation, and water utilities. With the deep integration of Industrial Internet and Internet of Things (IoT) technologies, closed industrial control environments are gradually becoming more open, leading to increasingly severe cybersecurity threats to ICS. Among numerous attack methods, spoofed data injection attacks have become the number one threat in the field of industrial security due to their high degree of concealment and destructive power. Attackers often tamper with real-time data collected by sensors (such as voltage, frequency, and flow rate) to mislead the decision-making system in the control center, potentially causing physical damage to equipment or even catastrophic consequences such as large-scale power outages.

[0003] Existing defense methods primarily rely on traditional residual detection-based state estimation methods (such as weighted least squares). However, these methods often struggle to identify carefully constructed intelligent attack vectors that conform to physical topological constraints. Although deep learning techniques have been introduced in recent years to improve detection capabilities, purely data-driven AI models heavily depend on training with massive amounts of attack samples. In contrast, industrial settings often lack real-world attack data, and these models lack interpretability, making them difficult to implement in actual industrial production.

[0004] Physical Information Neural Networks (PINNs), as an emerging method that integrates physical mechanisms with deep learning, offer a new approach to solving the aforementioned problems. However, in practical applications, it has been found that the standard PINN model's loss function is easily "dragged down" by contaminated data when faced with a large amount of spurious data injection. This causes the model to sacrifice the constraints of physical laws in order to forcibly fit the erroneous data, making it unable to accurately distinguish between normal measurement noise and malicious attack data. Summary of the Invention

[0005] This invention proposes a method for identifying spoofed data injection attacks based on adaptive residual weighted PINN.

[0006] The technical solution to achieve the purpose of this invention is: a method for identifying spoofed data injection attacks based on adaptive residual weighted PINN, comprising:

[0007] Step 1: Determine the connection relationships and line parameters between nodes based on the network topology file of the industrial control system, and construct observation equations describing the system's operating status;

[0008] Step 2: Construct an adaptive residual weighted network, which takes sensor measurement data with noise or attacks as input and the reconstructed system state as output;

[0009] Step 3: Train the adaptive residual weighted network using the gradient descent algorithm. Training is complete when the change in the total loss function for a set number of consecutive iterations is less than the set convergence threshold, or when the preset maximum number of training rounds is reached.

[0010] Step 4: Use an adaptive residual weighted network to map the sensor data to a system state that satisfies physical consistency in real time;

[0011] Step 5: Based on the weight coefficients and physical residual information calculated in real time by the adaptive residual weighted network, identify fake data injection attacks through a dual criterion mechanism.

[0012] Compared with existing technologies, this invention has the following significant advantages: First, by introducing an adaptive residual weighting mechanism into the loss function of the physical information neural network, this invention can dynamically adjust the weights of each measurement data according to the magnitude of the physical residual, greatly enhancing the robustness of the system. Even when multiple sensors are simultaneously subjected to significant malicious tampering, the accuracy of state estimation can still be maintained, and it will not be "biased" by the attack data. Second, by constructing the physical topology and operating rules of the industrial control system into a mathematical mechanism model and using it as the constraint benchmark of the neural network, this invention lowers the data threshold and no longer relies on massive historical attack samples. It can achieve defense against new and unknown attacks based solely on normal operating data and physical rules. This invention provides good interpretability; maintenance personnel can directly locate the attacked equipment by observing changes in weights, significantly shortening the time for fault diagnosis and emergency response.

[0013] The present invention will now be described in further detail with reference to the accompanying drawings. Attached Figure Description

[0014] Figure 1 This is a flowchart of a method for identifying fake data injection attacks based on adaptive residual weighted PINN.

[0015] Figure 2 This is a schematic diagram of an adaptive residual weighted network structure. Detailed Implementation

[0016] A method for identifying spoofed data injection attacks based on adaptive residual weighted PINN, the specific steps of which are as follows:

[0017] Step 1: Determine the connection relationships and line parameters between nodes based on the network topology file of the industrial control system, and construct observation equations describing the system's operating status;

[0018] When the industrial control system is a power control system, the connection relationships between nodes and the line parameters are determined, based on the voltage amplitude of the nodes in the power control system. and voltage phase angle As the vector of state variables to be estimated Select the active power collected by the sensor reactive power etc. as measurement vectors Based on Kirchhoff's laws and line parameters, nonlinear physical equations are constructed. Specifically, for any node The active power it injects and reactive power Nonlinear physical equations The (current flow equation) is expressed as:

[0019]

[0020] In the formula, Represents a node The amount of active power injected comes from real-time sensor measurements or calculations based on physical equations. Represents a node The amount of reactive power injected comes from real-time sensor measurements or calculations based on physical equations. Representing nodes respectively voltage amplitude, and nodes Connected nodes The voltage amplitude is the estimated state quantity that the neural network needs to output. Represents nodes The set of all neighboring nodes that are directly electrically connected, which is determined by the physical topology of the power grid (fixed and known). Indicates the connection node and nodes The line conductance is a fixed constant derived from the power grid's line parameter database. In a per-unit system, its value typically ranges from 0.5 to 10 pu (depending on the line's resistance to reactance ratio). Indicates the connection node and nodes The line susceptance is a fixed constant derived from the power grid's line parameter database. In a per-unit system, its value typically ranges from -20 to -1 pu. Represents a node With nodes The voltage phase angle difference between them, i.e. ,in and These are nodes With nodes Voltage phase angle state quantity.

[0021] The system of equations The physical constraints of the system are defined, namely, that under normal operation, voltage and power must satisfy the above equation.

[0022] If the industrial control system is a fluid pipeline system (such as a natural gas transmission and distribution pipeline or a water supply pipeline system), then the fluid pressure (or head) at each junction in the pipeline network is selected as the state variable vector to be estimated. Real-time pressure and flow data collected by pressure sensors and flow meters deployed at key nodes or on pipelines are selected as measurement vectors. At this point, its nonlinear physical equations It is then constructed from the laws of mass conservation (such as the nodal flow continuity equation) and energy conservation (such as the pipe resistance equation) in fluid mechanics.

[0023] For any network node Based on node pressure (or head) As state variables, traffic is injected into nodes. For the measurement quantity, a nonlinear physical equation is constructed based on the law of conservation of mass and the characteristics of pipe resistance. Represented as:

[0024]

[0025] In the formula, Represents nodes The set of directly connected adjacent nodes; , They are nodes and nodes Estimated pressure state quantities; For connecting nodes With nodes The physical impedance characteristic coefficient of the pipeline (determined by pipe diameter, pipe length and pipe roughness). It is a symbolic function used to characterize the physical direction of fluid flow from the high-pressure side to the low-pressure side.

[0026] If the industrial control system is a thermal or chemical reaction system, then the actual temperature and substance concentration inside the reaction vessel are selected as the state variable vector to be estimated. Real-time monitoring data collected by external temperature transmitters, level gauges, pressure sensors, etc., are selected as measurement vectors. At this point, its nonlinear physical equations It is then constructed based on the laws of thermodynamics and the equilibrium equations of reaction kinetics.

[0027] In summary, the specific mathematical expressions of the nonlinear physical equations of different industrial control systems vary, but they can all be uniformly abstracted into higher-level observation equations:

[0028]

[0029] In the formula, For theoretical measurement vectors; This represents a nonlinear mapping function determined by the specific physical mechanisms of the target industrial control system (such as Kirchhoff's laws, fluid dynamics conservation laws, thermodynamic laws, etc.) and the spatial topological connections of the equipment. Mathematically, this function constructs the invisible state space to be estimated within the system. ) to the measurement space observable by external sensors ( The strong physical mechanism constraint relationship between them.

[0030] Step 2: Construct an adaptive residual weighted network, such as Figure 2 As shown, the adaptive residual weighting network uses sensor measurement data with noise or attacks. As input, the reconstructed system state The output is the adaptive residual weighted network, which includes a physical information neural network, a physical constraint module, and an adaptive weight module.

[0031] 1. Set up the network infrastructure:

[0032] Construct a fully connected Physical Information Neural Network (PINN) with the following structure:

[0033] Input layer: The number of nodes is consistent with the dimension of the sensor measurement vector, and it is used to receive real-time measurement data.

[0034] Hidden layers: It is preferable to set 3 to 5 hidden layers, each containing 50 to 100 neurons.

[0035] Output layer: Number of nodes and estimated state vector The dimensions are consistent and are used to output the estimated state vector of the system.

[0036] The actual sensor measurement data collected (Potentially containing fake data injected by hackers) is input into the physical information neural network. After linear transformation and nonlinear activation in the hidden layer, the data signal outputs a preliminary estimated state vector of the system at the current moment in the output layer. (i.e., the predicted node voltage magnitude and phase angle).

[0037] 2. Introduce a physical constraint module to calculate physical residuals:

[0038] Obtain the estimated state from the forward propagation output. Then, substitute it into the nonlinear physical equations constructed in step 1. In this process, the theoretical measured value is calculated. Subsequently, the absolute deviation between the actual measured value and the theoretical measured value is calculated to obtain the physical residual. :

[0039]

[0040] In the formula, This represents the physical residual vector, reflecting the degree to which the current estimated state violates the laws of physics. This represents the measurement data vector actually collected by the sensor and after being standardized, which may contain fake data injected by hackers. This represents the estimated state vector (i.e., the predicted voltage magnitude and phase angle) output by the neural network during its current forward propagation. This represents a function of a nonlinear physical equation. When an attack occurs, the attacked node's... It can be tampered with, resulting in Significantly increased.

[0041] 3. Introduce an adaptive weighting module to calculate weights:

[0042] Based on the above physical residuals, for each measurement data point Calculate a dynamic weight The larger the residual of a data point, the greater the degree to which it violates the laws of physics. The network automatically reduces the number of measurement data points using the following formula. Weight:

[0043]

[0044] In the formula, Indicates the first The weighting coefficients of each sensor data point in the loss function range from (0, 1). The smaller the value, the less the model trusts the data. This represents the sensitivity coefficient (hyperparameter), used to control how sensitive the weights are to the residuals. This value needs to be preset and is typically a positive real number between 10 and 100. The larger the value, the stronger the model's ability to suppress large residual data. Indicates the first The physical residual value corresponding to each sensor data point is calculated using the residual formula described above.

[0045] When the physical residual of a certain sensor data When it is extremely large (indicating an attack), its weight Approaching 0.

[0046] Step 3: Train the adaptive residual weighted network

[0047] After clarifying the network structure and forward data processing, this step defines a specific loss function and uses the gradient descent algorithm to backpropagate and update the internal parameters (weights and biases) of the neural network until the network converges. Specifically, it includes the following steps:

[0048] 1. Construct the total loss function

[0049] Combining the estimated state output from step 2 with the adaptive weights, calculate the total loss value of the network in the current iteration. The loss function consists of two parts: a "weighted data fitting error term" and a "weight regularization term," and its formula is as follows:

[0050]

[0051] In the formula, This represents the total loss value during neural network training, and the training objective is to minimize this value. Represents the total number of sensors in the system (integer). This indicates the sensor's index number. Indicates the first The adaptive weights of each sensor data point are calculated using the weighting formula described above. Indicates the first The actual measurement value of each sensor. This indicates that the state vector is estimated based on the neural network. The first one derived from the physical equation Theoretical measurements at each location. This represents the regularization coefficient (hyperparameter). It's used to balance the fitting error and weight distribution, and is usually taken as a small value, such as 0.01 or 0.001. 1: Represents a vector consisting entirely of 1s, with dimensions equal to... The same means that all data are reliable under ideal circumstances (weight 1). The set of vectors representing the weights of all sensors. This represents the L2 norm (Euclidean norm), used to constrain the weight vector from deviating excessively from 1, preventing the model from excessively reducing the weights when there is no attack.

[0052] 2. Analysis of the mechanism of action of the loss function:

[0053] Anti-attack mechanism (first item): Error term The previous step was multiplied by adaptive weights. When encountering a data injection attack, the physical residual of the abnormal data is extremely large, leading to... It approaches 0. Therefore, the huge error caused by outliers accounts for a significant portion of the total error. The proportion of error is extremely compressed, and the network will not forcibly distort the system state to reduce this part of the error. This achieves "immunity" to attack data.

[0054] Preventing weight collapse (second term): Regularization term Its function is to constrain the entire weight vector. Avoid excessive deviation from the all-1 state. This ensures that the network will not unnecessarily reduce the weights of normal data when it is not under attack (the residuals are normal noise), thus ensuring the physical fidelity of the model.

[0055] 3. Backpropagation and parameter optimization:

[0056] Calculate the total loss value for the current round. Then, a deep learning optimization algorithm is used to calculate... The gradients of all learnable parameters within the neural network are calculated. Based on the calculated gradient directions, the network parameters are backpropagated and updated, ensuring that the gradients calculated in the next forward propagation iteration are consistent with the calculated gradients. Gradually decrease.

[0057] 4. Iterative convergence and training completion:

[0058] The forward propagation in step 2 and the backward propagation in step 3 are executed repeatedly. The termination condition for training is set as the total loss function. The network training is complete when the change over several consecutive iterations is less than the set minimum convergence threshold or the preset maximum number of training rounds is reached. The network's internal parameters are then fixed, and the neural network at this point possesses the ability to accurately reproduce the true physical state under strong attack interference.

[0059] Step 4: During the online operation phase, the contaminated sensor data is mapped in real time to a system state that satisfies physical consistency using an adaptive residual weighted network.

[0060] 1. State Reconstruction Formula:

[0061] Real-time acquired measurement vectors Input into the trained and optimized adaptive residual weighted network In the output, the reconstructed system state is displayed. :

[0062]

[0063] In the formula, : Represents the final system state estimate after "cleaning" and reconstruction (including voltage amplitudes at all nodes). and phase angle This value satisfies the constraints of the physical mechanism equation, eliminating the influence of spurious data. This represents the mathematical mapping function of the adaptive residual weighted network constructed in step 2 and optimized through iterative training in step 3. This represents the sensor measurement vector input at the current moment, which may contain noise or maliciously attacked data. This represents the set of network parameters that converge after training and optimization using the "adaptive weighted loss function". These parameters record the network's ability to ignore attack data and extract physical features.

[0064] To further ensure the reliability of the output state, the theoretical measurement value corresponding to the reconstructed state is calculated. :

[0065]

[0066] This represents the "clean" measurement value calculated based on the reconstructed state. : represents the nonlinear physical mechanism equation defined above. With the original input The difference reflects the magnitude of the attack vector. When an attack occurs, the network automatically outputs a value consistent with physical laws. ,therefore It will remain "pure" through physical equations, and will not follow... The attack data has been shifted.

[0067] Step 5: Attack Identification and Location

[0068] This module is deployed in the post-processing stage of model inference. It is used after the aforementioned neural network has completed training and outputs the reconstructed state. Instead of directly trusting the original measurement data, it utilizes the "byproduct" generated during the training process of the neural network—the adaptive weight vector. By combining physical residual information, a dual-criteria mechanism is used to accurately identify fake data injection attacks. The core logic is that if a data point is malicious, it will both violate physical laws (leading to a large residual) and be "rejected" by the adaptive network (leading to an automatic reduction in weight).

[0069] 1. Obtaining the basis for judgment: Extracting two key pieces of information from the trained neural network:

[0070] First, the system state after reconstruction This is a "clean" state that conforms to the physical equations;

[0071] Second, the final weight vector This is the network's final score for the credibility of each sensor's data.

[0072] 2. Calculate the attack bias (residual analysis):

[0073] Using physical equations According to the reconstruction state Calculate the theoretically existing measurement values Compare it with the actual measured values. Compare the measurements and calculate the measurement deviation (i.e., residual) for each sensor.

[0074] 3. Implement dual threshold judgment: To reduce the false alarm rate (e.g., to avoid misjudging normal random noise as an attack), this invention designs a dual judgment logic of "residual + weight":

[0075] Condition 1 (Physical Consistency Check): Check whether the measurement deviation exceeds the normal noise range allowed by the system. ).

[0076] Condition 2 (Data Reliability Check): Check the adaptive weights of the data. Is it below the extremely low confidence threshold? Only when the weight is extremely low can it be said that the data is judged as a "serious outlier" by the neural network.

[0077] Attack determination function formula:

[0078]

[0079] In the formula, Indicates the first The final attack determination result for sensor number 1. An output of 1 indicates that the sensor has been subjected to a false data injection attack; an output of 0 indicates that the sensor data is normal or contains only random noise within the allowable range. This represents the sensor's index number, with values ​​ranging from 1, 2, ..., M. : indicates the first The final measurement residual (absolute value) of each sensor. For the first The actual data collected by each sensor (may be tampered with). These are theoretical measurements derived from the real state reconstructed by the neural network. This represents the residual judgment threshold. This value is typically set to three times the standard deviation of the measurement error of the system's historical normal operating data; for example, it can be set to 0.03 pu in a power system. This indicates the output of the neural network for the first... The final adaptive weight value for each data point. This represents the weight cutoff threshold. It's an empirical constant used to define "data discarded by the model." Based on the characteristics of the adaptive weighting function, a value of 0.1 or 0.05 is recommended. That is, when the weights are below this value, it indicates that the data severely violates physical laws and has extremely low confidence.

[0080] 4. Positioning and Output: Traverse all sensor nodes, for all nodes that satisfy... For nodes with a value of 1, record their number. and output its attack deviation. This serves as the final attack detection report.

Claims

1. A method for identifying spoofed data injection attacks based on adaptive residual weighted PINN, characterized in that, include: Step 1: Determine the connection relationships and line parameters between nodes based on the network topology file of the industrial control system, and construct observation equations describing the system's operating status; Step 2: Construct an adaptive residual weighted network. The adaptive residual weighted network takes sensor measurement data with noise or attacks as input and the reconstructed system state as output. The adaptive residual weighted network includes a fully connected physical information neural network, a physical constraint module, and an adaptive weight module. The physical information neural network includes an input layer, a hidden layer, and an output layer. The actual sensor measurement data is input into the input layer. After linear transformation and nonlinear activation in the hidden layer, the preliminary estimated state vector of the system at the current moment is output in the output layer. The physical constraint module inputs the preliminary estimated state vector output by the physical information neural network into the observation equation describing the system's operating state, obtains the theoretical measurement value, and calculates the physical residual between the theoretical measurement value and the actual sensor measurement data collected; the adaptive weight module is used to calculate dynamic weights based on the physical residual. Step 3: Train the adaptive residual weighted network using the gradient descent algorithm. Training is complete when the change in the total loss function for a set number of consecutive iterations is less than the set convergence threshold, or when the preset maximum number of training rounds is reached. Step 4: Use an adaptive residual weighted network to map the sensor data to a system state that satisfies physical consistency in real time; Step 5: Based on the weight coefficients and physical residual information calculated in real time by the adaptive residual weighted network, identify fake data injection attacks through a dual criterion mechanism.

2. The method for identifying spoofed data injection attacks based on adaptive residual weighted PINN according to claim 1, characterized in that, The observation equations describing the system's operating state are as follows: ; In the formula, For theoretical measurement vectors, This represents a nonlinear mapping function determined by the physical mechanism of the target industrial control system and the spatial topological connections of the equipment. This is a vector of state variables.

3. The method for identifying spoofed data injection attacks based on adaptive residual weighted PINN according to claim 2, characterized in that, When the industrial control system is a power control system, the specific method for constructing the observation equations describing the system's operating state is as follows: Voltage amplitude of nodes in power industrial control system and phase angle As the vector of state variables to be estimated Select the active power collected by the sensor reactive power As a measurement vector Based on Kirchhoff's laws and line parameters, observation equations are constructed. Specifically: ; In the formula, Represents a node The amount of active power injected. Represents a node The amount of reactive power injected. Represents a node voltage amplitude, Represents nodes Connected nodes voltage amplitude, Represents nodes The set of all neighboring nodes that have direct electrical connections. Indicates the connection node and nodes The line conductivity, Indicates the connection node and nodes Line susceptance, Represents a node With nodes The voltage phase angle difference between them.

4. The method for identifying spoofed data injection attacks based on adaptive residual weighted PINN according to claim 2, characterized in that, When the industrial control system is a fluid pipeline system, the specific method for constructing the observation equations describing the system's operating state is as follows: The fluid pressure at each junction in the pipeline network is taken as the state variable vector to be estimated. Real-time pressure and flow data collected by pressure sensors and flow meters deployed on pipeline nodes or pipelines are selected as measurement vectors. For any pipeline node , with fluid pressure For state variable vectors, inject traffic into nodes. For the measurement quantity, a nonlinear physical equation is constructed based on the law of conservation of mass and the characteristics of pipe resistance. Represented as: ; In the formula, Represents nodes The set of directly connected adjacent nodes; , They are nodes and nodes Estimated pressure state quantities; For connecting nodes With nodes The physical impedance characteristic coefficient of the pipeline; It is a symbolic function.

5. The method for identifying spoofed data injection attacks based on adaptive residual weighted PINN according to claim 1, characterized in that, The specific formula for the adaptive weighting module to calculate the dynamic weighting coefficients based on the physical residuals is as follows: ; In the formula, Indicates the first The weighting coefficients of each sensor data in the loss function Indicates the first The physical residual value corresponding to each sensor data.

6. The method for identifying spoofed data injection attacks based on adaptive residual weighted PINN according to claim 1, characterized in that, The total loss function during training of the adaptive residual weighted network is: ; In the formula, This represents the total loss value during neural network training. This indicates the total number of sensors in the system. Indicates the first Adaptive weighting of sensor data, Indicates the first The actual measured values ​​of each sensor This indicates that the state vector is estimated based on the network. The first one derived from the observation equation Theoretical measurements at each location Represents the regularization coefficient. The set of vectors representing the weights of all sensors. This represents the L2 norm.

7. The method for identifying spoofed data injection attacks based on adaptive residual weighted PINN according to claim 1, characterized in that, Based on the weight coefficients and physical residual information calculated in real time by the adaptive residual weighted network, the specific formula for identifying fake data injection attacks through a dual-criteria mechanism is as follows: ; In the formula, Indicates the first The final attack determination result for the sensor. A value of 1 indicates that the sensor has been subjected to a false data injection attack; A value of 0 indicates that the sensor data is normal or contains only random noise within the allowable range. This represents the theoretical measurement calculated based on the system state output by the trained adaptive residual weighted network. For the first The actual measured values ​​of each sensor This indicates the network output for the first... Adaptive weight values ​​for each sensor measurement. This represents the residual judgment threshold. This represents the weight cutoff threshold.