A multi-state target threat assessment and collaborative management method for low-altitude economy
Patent Information
- Application Number
- CN202610905721.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-23
- Publication Date
- 2026-09-04
- Estimated Expiration
- 2046-06-23
AI Technical Summary
在威胁评估层面,现有方案多采用单一评估通道,要么完全依赖数据驱动模型而缺乏可解释性,要么仅基于专家规则而无法充分利用飞行行为数据中蕴含的隐性特征
[0022] Beneficial Effects: Compared with existing technologies, this invention has the following significant advantages: By introducing a transitional state as an intermediate state and designing a rigorous merging and verification process, reliable control over the transformation process of a target from non-compliant to compliant status is achieved, enhancing the system's security and flexibility. By dynamically setting the avoidance routes generated by system commands as temporary equivalent authorized routes, the benchmark for threat assessment can keep pace with real-time updates to control commands. The dual-channel assessment architecture integrates the sensitivity of data-driven approaches with the logic of expert rules, enabling the capture of complex abnormal behavior patterns while ensuring clear interpretability in the assessment of critical security events. Through pre-handling linkage effect prediction and proactive avoidance command issuance, the collateral impact of control measures on legitimate flight activities within the airspace is minimized, effectively protecting the low-altitude economic order.
Smart Images

Figure CN122454790B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of low-altitude economic technology, and in particular to a method for multi-mode target threat assessment and collaborative management for low-altitude economy. Background Technology
[0002] In recent years, with the rapid iteration of drone technology and the continuous expansion of application scenarios, low-altitude airspace has evolved from the exclusive domain of traditional general aviation into a multi-dimensional transportation space where diverse industries such as logistics delivery, urban inspection, emergency rescue, and agricultural plant protection coexist. As the low-altitude economic industry chain matures, the operational density of various drones in urban and key areas continues to rise, leading to a sharp increase in the complexity of airspace management and the difficulty of ensuring safety.
[0003] Existing technological solutions have significant shortcomings in addressing the aforementioned challenges. Some solutions focus only on threat assessment of single-type targets, lacking a unified management framework for compliant, transitional, and non-compliant targets. While some solutions introduce multi-target fusion tracking technology, they lack systematic design for reliable verification of identity state transitions, particularly in the merging verification process of non-compliant targets transitioning to compliant identities, where anti-spoofing mechanisms such as dual track comparison are lacking. At the threat assessment level, existing solutions mostly employ a single assessment channel, either relying entirely on data-driven models that lack interpretability, or relying solely on expert rules that fail to fully utilize the implicit features inherent in flight behavior data. More critically, existing solutions generally neglect the linkage between control instructions and assessment benchmarks, failing to establish a closed-loop mechanism for writing circumvention routes back to the flight plan database, and also lacking the following collaborative control capabilities. Summary of the Invention
[0004] Purpose of the invention: The purpose of this invention is to provide a method for multi-state target threat assessment and collaborative control for the low-altitude economy, which can simultaneously realize multi-state target identity management, provide reliable identity conversion verification, ensure that assessment benchmarks and control instructions are updated synchronously, and predict the linkage impact before disposal, thereby solving the problems existing in the background technology.
[0005] Technical Solution: The present invention provides a method for multi-mode target threat assessment and collaborative control for low-altitude economy, comprising the following steps:
[0006] Step 1: For flight targets within the airspace, based on the identity broadcast status and flight plan matching status, uniformly classify them into three identity statuses: compliant targets, transitional targets, and non-compliant targets, and implement differentiated identity management.
[0007] Step 2: When a target that already holds a virtual identifier within the system begins broadcasting a valid operational identification signal, the merging verification and certification process is initiated;
[0008] Step 3: When generating avoidance routes for compliant or transitional targets in response to changes in airspace situation, the avoidance routes are synchronously recorded in the flight plan database and marked as temporary equivalent authorized routes. This allows the threat assessment module to calculate deviations based on the updated baseline routes, thereby distinguishing between system-mandated avoidance behaviors and unauthorized route deviations. The compliance deviation is a dual-channel threat assessment architecture with shared input, used to quantify the degree of deviation of the target's flight behavior from the baseline routes. The two assessment channels are a data-driven assessment channel and an expert rule assessment channel. By fusing the threat levels output by the two channels, the final threat level of the target is determined.
[0009] Step 4: Before taking countermeasures against non-compliant targets, predict the ripple effects, determine the scope of impact based on the physical characteristics of the proposed measures, and identify all compliant and transitional targets that are about to enter the scope of impact based on trajectory prediction. Prioritize issuing evasion instructions to these affected targets. After the evasion instructions are issued, take countermeasures against non-compliant targets.
[0010] Furthermore, in step 2, a pre-verification is performed before the merging verification process, including: verifying that the identifier in the running identification signal has a valid record in the registration database, verifying that there is currently no prohibited merging entry for the identifier, and verifying that no other target in the current airspace situation is using the identifier or is using the identifier for merging verification.
[0011] Furthermore, step 2 specifically involves: during the preset verification period, simultaneously maintaining track tracking based on the target's virtual identifier and track tracking based on its broadcast location, and performing cycle-by-cycle comparisons; when the positional difference between the two tracks meets the preset consistency conditions, the merge verification is deemed successful, and based on the flight plan matching results, the target's identity is converted into a compliant target or a transitional target.
[0012] Furthermore, in step 3, the compliance deviation is specifically as follows: According to a preset priority order, targets are sequentially judged to determine whether they meet specific rules, and the corresponding compliance deviation value is adopted when the first applicable rule is met; for targets that do not possess a valid operational identification signal or are undergoing merge verification, the compliance deviation is directly set to the highest value; for targets marked as having suspected identity spoofing, the compliance deviation is directly set to the highest value during the duration of the suspected label; for targets in a transitional state, within a preset retry period after entering the transitional state, the compliance deviation takes a low fixed value; if this period is exceeded and the target has not yet become compliant, the compliance deviation rises to a high fixed value; for compliant targets that do not meet any of the above specific rules, the compliance deviation is determined based on the maximum value among the lateral deviation between their actual flight path and the reference route, the altitude deviation, and the position cross-validation deviation rate obtained from multi-source sensor data.
[0013] Furthermore, in step 3, the expert rule evaluation channel obtains a basic threat score by querying a preset threat classification lookup table. The threat classification lookup table uses the target's representative abnormal behavior type, compliance deviation level, and spatial sensitivity level of the current airspace as input conditions, and pre-sets basic threat scores under different combinations of conditions based on domain expert knowledge. Then, it uses the current time scenario factor to weight and adjust the basic threat score.
[0014] Furthermore, the method also includes setting and updating a threat level lower limit for each target, the threat level lower limit being determined by a set of triggering conditions; when a target is in any of the following states: trust observation period, missing location cross-verification, or changed identity, the corresponding condition entry is triggered, and a threat level lower limit not lower than a preset level is set to prevent underestimation of the threat level of the target due to state transition or missing information.
[0015] Furthermore, the method also includes an evasion exemption mechanism, specifically: when the target is in the process of executing an evasion command, the system suspends the effective periodic accumulation of various statistical indicators representing abnormal behavior and route deviation, and at the same time forces the input quantity used for abnormal behavior assessment to be set to a value representing a normal state.
[0016] Furthermore, the method also includes a state transition anti-oscillation mechanism, specifically: maintaining a counter for the number of times each target that has obtained a compliant identity has transitioned from a compliant state to a non-compliant state; when the counter value reaches a preset threshold, the identity identifier is added to the prohibited merging list and its non-compliant state is locked, which must be unlocked after operator review and confirmation.
[0017] The present invention discloses a multi-mode target threat assessment and collaborative control system for low-altitude economy, comprising:
[0018] Multi-source heterogeneous data fusion module: used to access multi-source information including operation identification broadcast data, non-cooperative sensor detection data, flight plan data and registration data, and fuse them into a spatiotemporally consistent global situational map. It is also responsible for three-state identity management, merging verification and identification, and cross-verification of location information.
[0019] Flight behavior feature sequence extraction module: used to extract the behavior feature sequence of each flight target from the situation map, and identify whether it has predefined abnormal behavior patterns such as approaching sensitive areas, abnormal hovering, flight path deviation, abnormal altitude changes, etc., while calculating the degree of collision risk with other targets in the airspace;
[0020] Dual-channel threat assessment module: It uses compliance deviation degree, which quantifies the degree to which the target flight behavior deviates from the baseline route, as a common input. It assesses the threat level through a data-driven assessment channel and an expert rule-based assessment channel, respectively. After fusing the assessment results of the two channels and combining them with possible lower limit constraints on the threat level, it outputs the final threat level.
[0021] The differentiated control scheme automatic generation module is used to generate a tiered response plan for non-compliant targets based on the final threat level, including monitoring, warning, continuous observation to countermeasures, and to initiate the prediction of the linkage effect before implementing countermeasures; for compliant targets and transitional targets, when they face collision risks or are affected by the response, an avoidance route is automatically generated and synchronously written into the flight plan database as a temporary equivalent authorized route.
[0022] Beneficial Effects: Compared with existing technologies, this invention has the following significant advantages: By introducing a transitional state as an intermediate state and designing a rigorous merging and verification process, reliable control over the transformation process of a target from non-compliant to compliant status is achieved, enhancing the system's security and flexibility. By dynamically setting the avoidance routes generated by system commands as temporary equivalent authorized routes, the benchmark for threat assessment can keep pace with real-time updates to control commands. The dual-channel assessment architecture integrates the sensitivity of data-driven approaches with the logic of expert rules, enabling the capture of complex abnormal behavior patterns while ensuring clear interpretability in the assessment of critical security events. Through pre-handling linkage effect prediction and proactive avoidance command issuance, the collateral impact of control measures on legitimate flight activities within the airspace is minimized, effectively protecting the low-altitude economic order. Attached Figure Description
[0023] Figure 1 This is a flowchart of the present invention;
[0024] Figure 2This is a system architecture diagram of the present invention;
[0025] Figure 3 This is the airspace situation and evasion route spatial distribution map of the present invention;
[0026] Figure 4 This is the polymorphic target threat level evolution of the present invention;
[0027] Figure 5 This is the compliance deviation and behavioral abnormality curve of the present invention; wherein, Figure 5 (a) in the middle is Changes with the evaluation cycle; Figure 5 (b) in the middle is Changes with the evaluation cycle. Detailed Implementation
[0028] The technical solution of the present invention will be further described below with reference to the accompanying drawings.
[0029] like Figure 1 As shown, embodiments of the present invention provide a method for multi-morphic target threat assessment and collaborative management for low-altitude economy. This method includes the following steps:
[0030] Step 1: For flight targets within the airspace, based on the identity broadcast status and flight plan matching status, uniformly classify them into three identity statuses: compliant targets, transitional targets, and non-compliant targets, and implement differentiated identity management.
[0031] Step 2: When a target that already possesses a virtual identifier within the system begins broadcasting a valid operational identification signal, the merge verification and certification process is initiated. Specifically, during a preset verification period, the target is simultaneously tracked based on its virtual identifier and tracked based on its broadcast position, and a cycle-by-cycle comparison is performed. When the positional difference between the two tracks meets a preset consistency condition, the merge verification is deemed successful, and the target's identity is converted to a compliant target or a transitional target based on the flight plan matching results. Prior to the merge verification and certification process, pre-verification is also performed, including: verifying that the identifier in the operational identification signal has a valid record in the registration database, verifying that there is currently no prohibited merge entry for that identifier, and verifying that no other target in the current airspace situation is using that identifier or is using that identifier for merge verification.
[0032] Step 3: When generating avoidance routes for compliant or transitional targets in response to changes in airspace situation, the avoidance routes are synchronously recorded in the flight plan database and marked as temporary equivalent authorized routes. This allows the threat assessment module to calculate deviations based on the updated baseline routes, thereby distinguishing between system-mandated avoidance behavior and unauthorized route deviations. The compliance deviation is a dual-channel threat assessment architecture with shared input, used to quantify the degree of deviation of target flight behavior from the baseline routes. The two assessment channels are a data-driven assessment channel and an expert rule assessment channel. By fusing the threat levels output by the two channels, the final threat level of the target is determined. The compliance deviation is specifically as follows: according to a preset priority order, it is judged whether the target meets specific rules, and the target meets the first rule. When applying the rules, the corresponding compliance deviation value is used. For targets that do not possess a valid operational identification signal or are undergoing merge verification, the compliance deviation value is directly set to the highest value. For targets marked as potentially spoofing their identity, the compliance deviation value is directly set to the highest value during the duration of the suspected label. For targets in a transitional state, the compliance deviation value is set to a low fixed value within a preset retry period after entering the transitional state. If this period is exceeded and the target has not yet become compliant, the compliance deviation value is raised to a high fixed value. For compliant targets that do not meet any of the above specific rules, the compliance deviation value is determined based on the maximum value among the following three factors: the degree of lateral deviation between the actual flight path and the reference route, the degree of altitude deviation, and the position cross-validation deviation rate obtained from multi-source sensor data.
[0033] The expert rule evaluation channel obtains a basic threat score by querying a preset threat classification lookup table. The threat classification lookup table takes the target's representative abnormal behavior type, compliance deviation level, and spatial sensitivity level of the current airspace as input conditions, and pre-sets basic threat scores under different combinations of conditions based on domain expert knowledge. The basic threat score is then weighted and adjusted using the current time context factor.
[0034] Step 4: Before taking countermeasures against non-compliant targets, predict the ripple effects, determine the scope of impact based on the physical characteristics of the proposed measures, and identify all compliant and transitional targets that are about to enter the scope of impact based on trajectory prediction. Prioritize issuing evasion instructions to these affected targets. After the evasion instructions are issued, take countermeasures against non-compliant targets.
[0035] It also includes maintaining a threat level lower limit for each target, which is determined by a set of triggering conditions. When a target is in a specific state such as a trust observation period, missing location cross-verification, or a change in identity, the corresponding condition entry is triggered to set a threat level lower limit that is not lower than the preset level, thereby preventing the underestimation of the threat level of the target due to state transitions or missing information.
[0036] The evasion exemption mechanism is as follows: when the target is in the process of executing evasion instructions, the system suspends the effective periodic accumulation of various statistical indicators that characterize abnormal behavior and route deviation, and at the same time forces the input used for abnormal behavior assessment to be set to the value that represents the normal state.
[0037] The state transition anti-oscillation mechanism is as follows: for each target that has obtained a compliant identity, maintain a counter for the number of times it has transitioned from a compliant state to a non-compliant state; when the counter value reaches a preset threshold, the identity identifier is added to the prohibited merging list and its non-compliant state is locked. The lock must be released after operator review and confirmation.
[0038] like Figure 2 As shown in the illustration, this invention also provides a multi-dimensional target threat assessment and collaborative management system for the low-altitude economy, comprising: a multi-source heterogeneous data fusion layer, a flight behavior feature sequence extraction layer, a dual-channel threat assessment layer, and a differentiated management scheme automatic generation layer, in sequence. The four layers share a global data set called a situational awareness map. Within the same assessment cycle, the four layers execute in a fixed order, and data written by a preceding layer can be read by subsequent layers within the current cycle. In this invention, "operator" refers to the on-duty personnel of the airspace control system; "operator" refers to the external operator of the UAV; and "management agency" refers to the competent authority responsible for configuring airspace control strategies and maintaining rules.
[0039] The multi-source heterogeneous data fusion layer (layer 1) integrates low-altitude perception data into a spatiotemporally unified and consistently labeled airspace situational map. Input data includes UAV RID broadcast data, detection data from non-cooperative sensors such as radar / RF / electro-optical sensors, flight plan databases, scenario context data, UAS registration databases (hereinafter referred to as the registration database), and manned aircraft track data provided by external air traffic control systems. The flight plan database also contains temporary equivalent authorized routes generated by layer 4. Each temporary equivalent authorized route has an absolute time validity period, and is checked and removed by layer 1 after expiration. The flight plan database includes an operation type field for use by layer 2 behavioral baseline grouping. Scenario context data includes geofence data, spatial sensitivity level data, and time scenario labels, providing data sources for layer 3 spatial sensitivity factors and time scenario factors, respectively. All data sources are unified to the WGS-84 coordinate system and UTC time base after timestamp delay compensation. After multi-target data association and state estimation filters, a global track state estimate is output.
[0040] Location cross-validation: For compliance targets, the system compares its broadcast RID location with the fused location from non-cooperative sensors in each evaluation period. Within a preset sliding window period, the location cross-validation bias rate is... Defined as the ratio of the number of cycles with deviations exceeding the position consistency threshold to the number of valid cycles. Cycles in which the avoidance marker is in an active sub-state, cycles where the RID broadcast position is unavailable, and cycles where non-cooperative sensors fail to provide fused positions are not counted as valid cycles. When the number of valid cycles is zero or below a preset threshold, Marked as unavailable. When a compliance target fails to complete cross-validation for more than a preset number of consecutive periods due to missing coverage by non-cooperative sensors, the system marks the cross-validation missing status and writes the cross-validation missing condition (lower limit II) into the threat level lower limit trigger condition set; it is cleared after coverage is restored.
[0041] The first layer checks the validity period of the compliance target's flight plan in each assessment cycle. Upon expiration, the following actions are performed synchronously: update the flight plan matching status to unmatched, terminate the trust observation period and remove the corresponding lower limit conditions (if any), clear the missing cross-validation status and remove the corresponding lower limit conditions (if any), reset the high threat cumulative timer and the cumulative value of the Level III handling observation period to zero, reset the identity verification request status and flight plan supplement request flag, clear the sliding window samples of lateral and altitude deviations in the compliance deviation score, record the transition state start time and set the effective duration of the transition state to zero, and the target enters the transition state. Avoidance instructions being executed at the time of expiration are unaffected. For targets in the transition state, the first layer automatically retryes matching in each assessment cycle. Successful matching requires passing pre-verification (excluding additional conditions for merging verification paths); after successful verification, the target enters the trust observation period; if pre-verification fails, the target remains in the transition state.
[0042] Transitional targets are not compliance targets, and downgrade procedures are not subject to the compliance-to-non-compliance additional rules. The conditions for the transitional period of identifier changes in the following scenarios are written independently. When a transitional target RID is lost, downgrade procedures are executed immediately. If the threat level before the change was Level II or higher, the transitional period conditions for identifier changes are written (the lower limit is the threat level before the change). When a UAS ID changes, downgrade procedures are executed and a suspected spoofing marker is added. The pairing of the downgraded VID with the old UASID is recorded in the merge exclusion list. If the threat level before the change was Level II or higher, the transitional period conditions for identifier changes are written (the lower limit is the threat level before the change). The new UAS ID is processed according to the merge verification process in subsequent evaluation cycles.
[0043] Virtual Identifier Encoding: For targets that have not broadcast a valid RID, the system matches them with existing VID tracks based on track characteristics. If a match is successful, the VID is reused. Before reuse, if the VID has an evasion flag, it is first cleared according to the evasion flag. Target-level data fields, except for flags indicating suspected spoofing, flags indicating suspended compliance identification, and the set of threat level lower limit trigger conditions, are reset to their initial state. Track history is taken from newly detected tracks, the temporal anomaly detection model is reinitialized, and the availability flag for behavioral anomalies is set to unavailable until the first valid period is completed. If a match fails, a new VID is assigned. When a VID is assigned due to an identifier change, data processing is performed according to the identifier change rules, and the general reset process of this invention does not apply. After a target exceeds a preset undetected time limit, the system cancels the VID, and the merge verification session (if any) associated with the VID is simultaneously terminated and the merge verification in progress status is cleared.
[0044] Compliance identity verification: Compliance identity verification includes two paths: direct verification upon initial network access and verification through consolidation.
[0045] Initial network entry is directly identified: This applies only to targets that do not yet possess a VID. After the system passes pre-verification and matches the flight plan, it registers the target using the UAS ID as a compliance identifier and enters a trust observation period. Downgrading is implemented if pre-verification conditions are not met. If multiple targets broadcast the same UAS ID within the same period, all identification is rejected, all targets are downgraded and marked with a suspected spoofing flag, and then the VID-RID pairings of each target are added to a merge exclusion list and reported to the operator. A transitional state is entered if flight plan matching fails. Targets that already possess a VID will subsequently undergo merge verification.
[0046] When a compliance target RID is temporarily lost, its compliance status is maintained for the preset RID retention period. When the RID resumes broadcasting within the retention period, the RID retention timer is reset and UAS ID consistency is verified. If inconsistent, the trust observation period is terminated, and the trust observation period condition (if any) in the threat level lower limit is removed. Missing cross-validation states are cleared, and corresponding lower limit conditions (if any) are removed. If the threat level before the change was Level II or higher, the transitional conditions for the change (lower limit level is the threat level before the change) are written into the threat level lower limit trigger condition set. Downgrade actions are performed, and a suspected spoofing marker is added. The pairing of the downgraded VID with the old UAS ID is recorded in the merge exclusion list. The new UAS ID is processed according to the merge verification process in subsequent assessment cycles. If the RID has not resumed broadcasting after the RID retention period expires, compliance downgrade actions are performed; if the RID resumes broadcasting subsequently, it is processed according to the merge verification process in the next assessment cycle.
[0047] Merge Verification Assessment: When the system detects that a target already holding a VID is broadcasting a valid RID, the system executes a three-step verification process. Targets undergoing merge verification are marked as "Merge Verification in Progress" on the situational awareness map and are still evaluated as non-compliant targets in Layer 2 and Layer 3. Only one merge verification session is allowed per UAS ID at a time.
[0048] The first step is to pass the pre-verification (including additional conditions for merging the verification path). The second step is for the system to enter the merging verification period, which lasts for a preset verification time. During this period, dual tracking of VID tracks and RID broadcast positions is maintained simultaneously, and the position difference between the two is calculated in each cycle. The third step is considered successful if the number of cycles in which the position difference exceeds the merging consistency threshold does not exceed a preset allowable value.
[0049] After successful merge verification, the system clears the merge verification in progress status and re-executes the verification of basic conditions (excluding additional conditions in the merge verification path). Upon successful verification, the flight plan is queried: if a match is successful, the VID is merged into the compliant identifier and the VID is deregistered, processed according to basic rules and additional rules for non-compliant to compliant status, and enters a trust observation period; if a match fails, the VID is deregistered, and the target enters a transitional state identified by its UAS ID, where only basic rules apply. The start time and duration of the transitional state are reset according to the general rules for entering the transitional state.
[0050] Unified handling of abnormal termination of merge verification: When a merge verification session terminates, the system synchronously clears the merge verification in progress status. In the following situations that cause abnormal termination of verification, the corresponding VID-RID pair will be added to the merge exclusion list, and the target will have its VID identity restored for continued evaluation:
[0051] (aa) Multiple VIDs broadcasting the same UAS ID in the same period: Mark the target holding all of the above VIDs as suspected spoofing and report to the operator; (bb) RID loss exceeding the preset merge verification signal interruption tolerance time: Do not mark as suspected spoofing; (cc) UAS ID change: Mark as suspected spoofing, the new UAS ID will be processed according to the merge verification process in subsequent evaluation cycles; (dd) Third step position difference verification fails: Mark as suspected spoofing; (ee) After merging verification passes, re-execution of basic condition verification fails: Report to the operator, do not mark as suspected spoofing; (ff) VID track interruption due to non-cooperative sensor detection, resulting in position difference not being calculated for more than a preset number of consecutive cycles: Do not mark as suspected spoofing. When the first step verification fails, merge is rejected and the merge verification session is terminated, the target maintains its VID identity.
[0052] The following trust observation period mechanism applies to all situations entering the trust observation period. During the trust observation period, the target is a compliant target but subject to stricter constraints: the trust observation period condition (lower limit Level II) is written into the threat level lower limit trigger condition set, the evasion flag is paused while it is in an active sub-state, and the condition is removed after the trust observation period ends.
[0053] Flight behavior feature sequence extraction layer (second layer): This layer extracts flight behavior feature sequences and collision risk peaks from the situational awareness map. For targets whose avoidance markers are in an active sub-state, they are handled according to the general rules of avoidance exemption, and collision risk calculation is performed normally.
[0054] Establishment of normal flight behavior baseline envelope and identification of abnormal behavior: For compliant targets, flight behavior feature sequences such as speed, altitude, rate of change of heading, and deviation from the baseline route are extracted, grouped by operation type, and clustering algorithms (e.g., K-means or density clustering) are used to establish the normal behavior baseline envelope for each group. For non-compliant targets, flight behavior feature sequences without route deviation are extracted, and a general baseline envelope is established by automatic clustering based on kinematic statistical features. The baseline envelope is updated periodically. Transitional targets use a behavior baseline envelope without route deviation. The availability flag for the behavior anomaly degree of newly registered targets is initially set to unavailable, and is restored to available after the first effective period is completed. When the baseline type is switched (e.g., from one with route deviation to one without route deviation or vice versa), the anomaly type codes in set Ω that do not belong to the target's current triggerable range are removed synchronously, the timing anomaly detection model is reinitialized, and the availability flag of behavioral anomaly degree is set to unavailable before the first effective period, and restored to available after the calculation is completed in the first effective period; while the avoidance flag is in an effective sub-state, the switching process is delayed until the avoidance flag is cleared, and the baseline type to be used is re-determined based on the target's current compliance status, and the switch is only performed when the current baseline type is inconsistent with the type to be used.
[0055] Abnormal behavior recognition employs a dual-path detection mechanism that parallelizes temporal anomaly detection and rule-based triggering conditions. The temporal anomaly detection path uses a temporal anomaly detection model (e.g., methods based on autoencoders or recurrent neural networks), employing normal behavior trajectories within the corresponding cluster as the training set, and outputs the behavior anomaly score. (Values [0, 1]), and it is judged as abnormal when it exceeds the preset abnormal behavior judgment threshold.
[0056] The rule-triggered condition detection path continuously checks four predefined anomaly types. The trigger conditions for each type are adapted to the flight platform type; when the flight platform type is unknown, the most conservative parameter configuration is used: Type 1 is the approach to sensitive areas mode (distance below the threshold and approach rate exceeding the threshold); Type 2 is the abnormal hovering or spatial dwelling mode (speed below the threshold and duration exceeding the preset time threshold); Type 3 is the route deviation mode (lateral or altitude deviation exceeding the threshold, applicable to targets with a baseline route); Type 4 is the abnormal altitude change mode (altitude change rate exceeding the threshold). Transitional targets and non-compliant targets can trigger types 1, 2, and 4. After an identifier change, baseline switch, or evasion marker clearing, the cumulative quantities and persistence judgment conditions in the rule-triggered condition detection are reset.
[0057] Abnormal behavior set encoding: The system maintains a set of triggered abnormal types Ω for each target, and adopts an cumulative maintenance method: when the triggering conditions of a predefined abnormal type are met, the code of that type is added to set Ω; when the time sequence detection determines an abnormality, the unclassified abnormal marker (code 0) is added to set Ω.
[0058] Representative anomaly coding Take the highest threat priority among the predefined anomaly types in set Ω (priority from high to low: type 1, 4, 2, 3); take 0 if it contains only unclassified markers; take the normal state code if the set is empty. , To distinguish it from the preset values of 0 to 4. Abnormal Complexity (Values [0, 1]) Matched according to the following rules: 0 when empty set; 1 / M when containing predefined exception types; 1 / M when containing only unclassified tags. Where M is the total number of predefined exception types that can be triggered for the target (4 types for compliant targets, 3 types for non-compliant targets and transitional targets).
[0059] Each predefined exception type is removed if it has not been triggered again after a preset cleanup time since its most recent trigger. Unclassified tags are removed after a preset number of consecutive normal judgments during time-series detection. When an identifier changes, the basic rules reset the set Ω to an empty set.
[0060] Collision risk peak calculation: In each assessment cycle of the second layer, neighboring target pairs are screened based on the predicted trajectories of all flying targets (including known tracks of human and aircraft) in the situational awareness map. For each pair of neighboring targets, within the prediction window... Internal calculation of collision risk index (Values [0, 1]), based on the relationship between predicted location spacing and safety spacing, for example... It can be defined as a monotonically decreasing function of the ratio of predicted location spacing to safe spacing, with the spacing approaching zero. The value approaches 1, and is set to 0 when the safe distance is reached or exceeded (a larger safe distance is used for target pairs involving manned aircraft).
[0061] For each UAV target, take the values of its relative positions to each neighboring target within the prediction window. Maximum value; peak collision risk The system selects the largest of the above values, setting it to 0 if there are no nearby targets. The system also records... The maximum value exceeds the conflict threshold A list of conflict-proximity target identifiers. The above results are fully reconstructed by the second layer in each evaluation cycle.
[0062] Dual-channel threat assessment layer (third layer): This layer constructs a dual-channel assessment architecture that combines a data-driven channel and an expert rule channel, and merges them to output the final threat level.
[0063] Compliance Deviation Rate: Compliance Deviation Rate (Values [0, 1]) are the input quantities shared by the two channels. They are matched sequentially according to the following rules. When the first applicable rule is met, the corresponding value is taken: VID target (including targets in the process of merging verification) takes 1.0; the duration of the disguised suspect mark takes 1.0; the effective duration of the transition state takes the lower fixed value of the preset retry time, and rises to the higher fixed value of the preset after the timeout.
[0064] The compliance objective for failing to meet any of the above rules is calculated using the following formula:
[0065] ;
[0066] in and The mean of the absolute values of the lateral and height deviations within the preset sliding window is used as the basis for determining the effective period. and Each has a preset maximum allowed value. This represents the cross-validation bias rate. If it is unavailable, the item is removed from the input set of the max operation mentioned above; and If the number of valid cycles for any item is less than the preset threshold, that item is removed from the input set of the max operation mentioned above; if all items are removed, the preset data is insufficient to reach the default value. The lateral deviation ratio and altitude deviation ratio can be greater than 1 when the deviation exceeds the corresponding preset maximum allowable value, and the outermost min operation truncates the upper limit of the result to 1.0. The deviation is calculated with reference to the reference route, where the lateral deviation is the normal distance between the target fusion position on the horizontal plane and the centerline of the reference route, and the altitude deviation is the absolute value of the difference between the target fusion altitude and the nominal altitude of the corresponding segment of the reference route. The valid cycles for lateral and altitude deviations exclude cycles in which the avoidance mark is in an active sub-state and cycles when the reference route is unavailable.
[0067] Data-driven channel: Takes the following characteristic values: , , , Output the weighted sum according to preset weights. (Values [0, 1]), the sum of weights is 1. When the behavior abnormality degree is unavailable, the corresponding weight is reset to zero, and the remaining weights are proportionally amplified. The weights are selected according to the default configuration based on the compliance status category.
[0068] Expert rule channel: Based on three types of pre-configured knowledge bases: spatial sensitivity rule base defines spatial sensitivity factors. Time-based scenario rule base defines time-based scenario factors. (Not less than 1); Threat classification lookup table with (Values cover normal state codes) (Unclassified code 0 and predefined exception type codes 1 to 4) Discretization (four levels: good compliance, slight deviation, significant deviation, and serious deviation) and Discretization (low, medium, and high levels) is used as input, and the output is a basic threat score. (Values [0, 1]). The lookup table is in Discretization level and The discretization level remains monotonically non-decreasing in both dimensions. No monotonicity constraints are imposed on the dimensions; they are configured and updated periodically by the management organization based on specific scenarios. Expert scores are calculated using the following formula:
[0069] ;
[0070] Dual-channel fusion: Threat levels are divided into Level I (normal), Level II (attention), Level III (early warning), and Level IV (emergency). and Each threat level is mapped to the same preset threshold, and the higher value is taken after merging. The system reads the lower limit of the threat level; if the current level is lower than the lower limit, the lower limit value is used. Operators can adjust the final level, but it is still constrained by the lower limit; this adjustment only takes effect in the current period.
[0071] Differentiated Control Scheme Automatic Generation Layer (Layer 4): This layer automatically generates control schemes based on threat levels, and additionally references the countermeasures library (an external database pre-configured and maintained by the management agency) as the data source for Level IV handling. The Layer 4 executes in the following order: (1) routine monitoring of transitional targets and operator response processing; (2) threat level check of transitional targets; (3) flight path compliance monitoring (including evasion completion condition determination); (4) graded handling of non-compliant targets (including prediction of synergistic effects); (5) security assurance for compliant targets and transitional targets; and (6) high-threat handling of compliant targets. Data written into the situational awareness map for each sub-step is immediately visible to subsequent sub-steps in the current cycle.
[0072] For targets in transitional states, regular monitoring is performed if the effective duration of the transitional state does not exceed the preset retry time; after the preset retry time exceeds the time limit, enhanced monitoring is performed, and a flight plan supplement request is sent to the operator (without resubmission). After the operator supplements the flight plan, the first layer performs matching; if the operator denies it, the system marks it as a suspected spoofing target and records the UASID as a UAS ID entry in the merge and exclusion list, and performs downgrade processing. Downgrade processing is performed when a target in transitional states meets any of the following conditions: Conditions 1 and 2 are determined independently and are not triggered by an operator's response; Condition 3 is triggered by the operator's failure to respond within the time limit. Condition 1: The effective duration of the transitional state exceeds the preset maximum duration. After downgrading, the UAS ID is recorded as a UAS ID entry in the merge and exclusion list. Condition 2: The threat level reaches Level III or above. After downgrading, the assigned VID is paired with the original UAS ID and recorded in the merge and exclusion list, and the transitional period conditions for the identifier change are written (the lower limit level is the threat level before the change). Condition 3: If the operator fails to respond within the timeout period, after downgrading, the pairing of the assigned VID with the original UAS ID will be added to the merge exclusion list. If multiple conditions are met simultaneously, they will be sorted by priority in the order of Condition 1 > Condition 2 > Condition 3, and only the additional processing corresponding to the highest priority condition will be executed.
[0073] Tiered approach to handling non-compliant targets:
[0074] Level I is routine surveillance. Level II is enhanced surveillance with warnings. Level III first executes the Level II actions (enhanced surveillance and warnings), then enters a continuous surveillance phase, monitoring behavioral trends within a preset observation period. If trajectory prediction determines that the target will enter a sensitive area or its threat level will rise to Level IV within a preset time, Level IV actions are immediately executed; if the target does not fall to Level II or below within the observation period, it is upgraded to Level IV. Level III actions continue across cycles; upon reaching Level IV, the Level III action observation period is terminated and reset to zero, restarting when Level IV falls to Level III; if the target falls to Level II or below and then rises back to Level III, the Level III action observation period accumulation continues from the previous accumulation value, and if the time limit is reached, it is immediately upgraded to Level IV. Level IV selects countermeasures from the countermeasures library based on timeliness, minimization of collateral damage, and resource constraints, and then executes a cascading effect prediction process; for multiple targets, they are first sorted by threat level from high to low, and within the same level, they are sorted by their expected arrival time from the sensitive area from near to far. Targets undergoing verification are merged and validated according to their VID and threat level, and this plan is executed.
[0075] Compliance Target and Transitional Target Security Assurance Scheme: The security assurance of this invention is independent of the target's own threat level and is based on real-time risk triggering in the airspace environment. When multiple triggering conditions for the same target are met simultaneously, a comprehensive avoidance route is generated.
[0076] Avoiding route directives: When the predicted trajectory of a compliant target or a transitional target is about to enter the active handling impact zone or the peak collision risk exceeds the conflict threshold. The system uses a three-dimensional route planning method to generate avoidance routes. Constraints include geofence boundaries, active response impact domain boundaries, safe distances from other known tracks, and target maneuverability limitations. Multiple targets are generated in descending order of collision risk peak. For targets with a collision risk peak of zero triggered solely by the response impact domain, they are sorted in ascending order of their expected entry time into the impact domain. Avoidance routes are simultaneously written to the flight plan database as temporary equivalent authorized routes. Route planning has a timeout limit. If the plan is not completed within the timeout period, the current optimal feasible solution is output; if no feasible solution is found, a hovering command is sent. Completion conditions are reaching the destination and meeting the avoidance completion conditions. Once met, the avoidance marker is cleared; if the destination is reached but the conditions are not met, a hovering command is sent. If an avoidance marker already exists for a target, the system can update the avoidance route and the corresponding temporary equivalent authorized route, and new trigger sources are merged into the avoidance trigger source list. In each evaluation cycle of the fourth layer, the validity period of the temporary equivalent authorized route is checked and extended if necessary.
[0077] Emergency Avoidance Command: When the collision risk peak exceeds the preset emergency threshold (greater than the conflict threshold), regardless of whether the target already has an avoidance marker, a predefined simple maneuver command is sent directly while maintaining the avoidance marker. No avoidance route is generated. The avoidance maneuver method is determined based on the threat source's location. In emergency situations, geofence constraints can be temporarily breached. Emergency avoidance takes precedence over the original avoidance command. At this time, the original avoidance command terminates, and the avoidance route data and temporary equivalent authorized routes are cleared. However, the original triggering source is not cleared due to the termination of the original avoidance command. The completion condition is the completion of the maneuver or reaching the preset maximum duration. If the avoidance completion condition is met after completion, the avoidance marker is cleared; otherwise, an avoidance route command is generated and processing continues.
[0078] Hovering hold instruction: Triggered when there is no feasible solution for the route planning or when the completion conditions are not met after reaching the destination. The maximum holding time is calculated from the first time the hovering hold instruction is sent, and the timer is paused during the execution of other avoidance instructions; during each evaluation cycle, the avoidance completion conditions are checked first, and the avoidance mark is cleared if they are met; if they are not met, the planning is retried, and if successful, the holding is terminated and an avoidance route instruction is issued; after the timeout, a forced return or nearby landing instruction is initiated.
[0079] Forced return to origin or nearby landing instruction: Initiated after hovering wait timeout. The system removes the temporary equivalent authorized route, writes the return or landing route into the flight plan database as a temporary equivalent authorized route, and simultaneously writes the route into the avoidance route data. The completion condition is reaching the route endpoint; once this is met, the avoidance marker is cleared.
[0080] Avoidance Marker Management: When a new avoidance requirement arises, if the avoidance mark does not exist, it is set to a pending sub-state and the trigger source identifier (collision risk type records the conflict neighboring target identifier, and handling impact domain type records the corresponding impact domain identifier) and its source type are written. If it already exists, the sub-state is maintained and only the trigger source is merged. The avoidance mark remains unchanged when the instruction type is switched. When the system issues or switches avoidance instructions, it simultaneously writes the current avoidance instruction type into the situation map. The avoidance completion condition is that all collision risk trigger sources in the avoidance trigger source list have dropped below the conflict threshold and all handling impact domain trigger sources have been eliminated. Whether a collision risk trigger source has dropped below the conflict threshold is determined according to the following rules: if the conflict neighboring target identifier corresponding to the trigger source still exists in the conflict neighboring target identifier list of the target in the current period, it is considered not to have dropped below the threshold; if it is not in the list or the conflict neighboring target is no longer tracked by the situation map, it is considered to have dropped below the threshold. Whether the handling impact domain trigger source has been eliminated is based on whether the impact domain identifier corresponding to the trigger source still exists in the active handling impact domain record.
[0081] Track compliance monitoring: Layer 4 monitors the track compliance of targets executing avoidance commands. When executing an avoidance route, it checks track deviation and execution duration; if limits are exceeded, the avoidance marker is cleared and operator intervention is requested. When executing emergency avoidance, only timeouts are checked; completion is considered achieved upon reaching the maximum duration or maneuver completion. When executing hovering, it checks position deviation; if limits are exceeded, the avoidance marker is cleared and operator intervention is requested. When executing forced return or nearby landing, it checks track deviation and execution duration; if limits are exceeded, the avoidance marker is cleared and operator intervention is requested. Avoidance markers inherited after a change in identifier continue to be subject to track compliance monitoring.
[0082] High-threat handling for compliance objectives: Identity verification request status values include not sent, sent pending reply, and confirmed under observation. Upon reset, it reverts to not sent. When the threat level is Level II or below and the high-threat cumulative timer is not zero, the timer is reset to zero and the identity verification request status is reset. When the threat level reaches Level III or above, if the behavioral anomaly degree is lower than the behavioral anomaly judgment threshold, the compliance deviation degree is lower than the preset compliance deviation threshold, and the anomaly complexity degree is zero, then identity verification is exempted for that period (the high-threat cumulative timer is not included in this period, accumulation is paused but not reset to zero); if the behavioral anomaly degree is unavailable, it is considered that the exemption conditions are not met; for periods where the evasion mark is in an effective sub-state, accumulation is paused according to the general rules of evasion exemption.
[0083] When the high-threat cumulative timer exceeds the preset trigger threshold, an identity verification request is sent to the operator (not sent repeatedly). If the operator does not provide valid confirmation within the preset response time limit, it is treated as invalid confirmation. When the operator confirms the validity, the timer is reset to zero and a preset post-confirmation observation period is entered (during which the accumulation of the high-threat cumulative timer is suspended). If the threat level has not dropped to Level II or below by the end of the observation period, operator intervention is requested; if the threat level drops to Level II or below within the time limit, the observation is terminated and the identity verification request status is reset. In the case of invalid confirmation, compliance identity verification is suspended: a suspended compliance identity verification flag is set, the UAS ID is recorded as a UAS ID entry in the merge exclusion list, the trust observation period is terminated, and the trust observation period condition (if any) in the threat level lower limit is removed. The cross-validation missing status is cleared and the corresponding lower limit condition (if any) is removed. If the threat level before the change is Level II or above, the transition period condition (the lower limit level is the threat level before the change) is written into the threat level lower limit trigger condition set, and downgrade processing is performed. Subsequently, the threat level participates in non-compliance processing as a VID.
[0084] State transition counter anti-oscillation: The system maintains a state transition counter for each UAS ID that holds or has previously held a compliance identifier, indicating a transition from compliance to non-compliance. When the counter reaches a preset threshold, the UAS ID is added to the merge exclusion list (UAS ID entry) and locked in a non-compliant state. Unlocking requires operator approval. Upon unlocking, the corresponding entry in the merge exclusion list is simultaneously removed, suspended compliance identification markers and identifier change transition conditions (if any) are cleared, the trust observation period is terminated and corresponding lower limit conditions (if any) are removed, missing cross-validation states and corresponding lower limit conditions (if any) are cleared, and the counter is reset. Suspicious spoofing markers must be cleared after separate operator approval. The target then re-enters the merge verification process with a VID identity. UAS ID entries written due to operator denial, transition status timeout, or ineffective identity verification must also be removed after operator review. When removing them, the suspended compliance identity recognition mark and the transition period conditions for the identifier change (if any) of the target will be cleared simultaneously, the trust observation period will be terminated and the corresponding lower limit conditions will be removed (if any), the cross-validation missing status will be cleared and the corresponding lower limit conditions will be removed (if any), and the state transition counter of the UAS ID will be reset (if any).
[0085] Threat Response Effect Prediction: The system calculates the impact domain of a response based on its physical characteristics and writes it into an active impact domain record (this record is removed when the response is terminated, and the removal takes effect in the next evaluation cycle). Based on trajectory prediction, it identifies compliant and transitional targets within the impact domain and generates evasion instructions. Response is executed only after the evasion instructions for affected targets are issued; in emergency situations, execution can proceed with operator confirmation. A timeout limit is set; if the timeout expires, protection is maintained for targets that have already been evaded, and response is executed; for incomplete evasion, the process is suspended, and operator intervention is requested.
[0086] Example effect verification:
[0087] For the urban low-altitude logistics corridor application scenario of this invention, the airspace range is 2000 m × 2000 m, and the evaluation period is... =1 s, a total of 60 evaluation cycles were run. A sensitive area exists in the upper right of the central airspace, with a center at (1500, 1200) m and a radius of 200 m. The spatial sensitivity buffer zone has a radius of 500 m. There are a total of 3 UAV targets within this area; their flight trajectories are shown below. Figure 3 .
[0088] D1 is a compliant target (delivery drone), holding a valid RID (UAS ID = UAS-D1) and an approved flight plan, flying along the approved route from (200, 300) m to (1800, 500) m, with a cruising speed of approximately 27 m / s. Starting from the 15th cycle, it began to gradually deviate from the route due to navigation deviations.
[0089] D2 is initially a non-compliant target and does not broadcast a RID. The system assigns a virtual identifier VID-D2. It starts from (300, 1400) m with a speed of approximately 20 m / s. Starting from the 20th cycle, it broadcasts a valid RID (UAS ID = UAS-D2).
[0090] D3 is initially a non-compliant target with no RID, and the system assigns it a virtual identifier VID-D3. Starting from (1000, 500) m, it continuously approaches the sensitive area at a speed of 14 m / s.
[0091] D1 (Compliance Deviation Gradual Escalation and Collaborative Avoidance): D1 flies stably along the approved route from cycle 0 to cycle 14. The first layer calculates the position cross-validation deviation rate in each assessment cycle. The third layer calculates the compliance deviation. Take the mean of the lateral deviation and The ratio, mean height deviation and The ratio, The maximum of the three. The initial number of periods with insufficient effective samples (3 periods). The default value was 0.10 due to insufficient data; as the sample size accumulated, it rose to 0.237 in the 10th period and reached 0.280 in the 14th period. This represents the abnormality level of behavior during this phase. Fluctuating between 0 and 0.23, the set As an empty set, the threat level remains at Level I after dual-channel fusion.
[0092] From cycle 15 onwards, track D1 began to deviate from the approved route. The second layer detected a progressively increasing lateral deviation: approximately 14.0 m in cycle 15, increasing to 32.6 m in cycle 25, 41.5 m in cycle 26, 64.4 m in cycle 28, 89.1 m in cycle 30, and 118.3 m in cycle 32. The average lateral deviation within the third layer sliding window was... The ratio of (50m) increases accordingly. It gradually rose from 0.281 in the 15th cycle: reaching 0.325 in the 26th cycle, within the same cycle. Rising to 0.576, the threat level has risen to Level II for the first time since the dual-channel fusion; 28th cycle. Reaching 0.473 Reached 0.924; 30th cycle It reached 0.778. At this point, the lateral deviation had exceeded... ×1.5=75 m, the second layer triggers a type 3 anomaly (course deviation mode), and the type 3 code is written to the set. ={3}, Threat level raised to Level III. 31st cycle. It continued to rise to 0.981, and saturated to 1.000 in the 32nd cycle.
[0093] In cycle 32, the threat level of D3 was simultaneously upgraded to Level IV. The fourth layer of execution involved predicting the synergistic effect: calculating the impact zone with a radius of 300 meters centered on D3's current location and writing it into the active log. Flight path prediction identified that D1 would enter this impact zone. The system first generated an avoidance route for D1 and simultaneously wrote it into the flight plan database as a temporary equivalent authorized route. The avoidance marker was set to a pending sub-state, and the impact zone identifier was recorded in the avoidance trigger source list. Countermeasures against D3 were only implemented after the avoidance command for D1 was issued.
[0094] At the start of cycle 33, the scheduler switches the D1 avoidance flag to the active sub-state. D1 then flies along the avoidance route, and the system applies the general avoidance exemption rule to it: the second layer will... Take 0, Take 0, take the representative abnormal code and take the normal state code, set {3} remains unchanged; collision risk calculation proceeds normally. The effective period accumulation of lateral and vertical deviations in the compliance deviation score is suspended in the third layer. No new samples will be collected once the value is frozen at 1,000. Pause synchronously.
[0095] After the exemption takes effect, the data-driven channel input vector becomes [ , , , = [0, 0, 1.000, 0], weighted by compliance weights [0.25, 0.25, 0.35, 0.15]. =0.35, mapped to Level II. The expert rule channel looks up the table using the normal state code. This is also below the Level III threshold. A higher value is used for fusion, resulting in a Level II threat level. For example... Figure 4 As shown, the D1 threat level dropped from Level III to Level II in the 33rd cycle, and the evasion exemption general rule prevented the evasion instructions issued by the system from being misjudged as route deviations.
[0096] During this period, the baseline route is defined according to a three-tier priority system, using avoidance route data (first priority). Even if the avoidance marker is subsequently removed, the temporary equivalent authorized route in the flight plan database (second priority) can still be used as a transitional baseline until it is removed and the original flight plan is reverted to (third priority).
[0097] At the end of cycle 43, the affected domain expires and is removed from the active records. In cycle 44, the fourth layer determines that the avoidance completion condition is met: all affected domain identifiers in the avoidance trigger source list are no longer in the active records; the system clears the avoidance markers, simultaneously clears the avoidance route data and removes the temporary equivalent authorized route; and the lateral and altitude deviation sliding window samples are simultaneously cleared. From cycle 45 onwards, the second layer resumes normal detection. It rebounded to 0.337; the third level, due to the window being cleared, had insufficient effective cycles to meet the threshold. Temporarily set the value to 0; after the sample reaches the target in the 47th cycle. The value was recalculated using the formula and reached 0.493. D1 then continued flying along the original route, but the deviation was not yet fully corrected. It remains stable around 0.45, and the threat level remains at Level II.
[0098] D2 (Three-State Identity Management and Merging Verification): D2 initially represents a non-compliant target. The third layer uses a sequential matching rule, with the VID target being... =1.0. Under non-compliant weights =0.370, mapped to Level II; the expert rule channel uses normal state encoding, low spatial sensitivity, and severe deviation level lookup table to obtain... =0.40, also Level II. The threat level after fusion is Level II, which remains unchanged from cycle 0 to cycle 19.
[0099] In cycle 20, the system detected that a target holding VID-D2 was broadcasting a valid RID. The system first performed pre-verification: confirming that UAS-D2 is valid in the registration database, that there is no entry for this UAS ID in the merge exclusion list, that no other target in the situation map is identified by this UAS ID, and that there are no merge verification sessions using this UAS ID; the merge path was further confirmed to have no entries paired with VID-D2 and that the suspended compliance identification flag was not set. With all conditions met, merge verification was initiated.
[0100] The merging verification period consists of 5 evaluation cycles (cycles 20 to 24). The system simultaneously maintains dual tracking of VID tracks and RID broadcast positions, calculating the position difference between the two cycle by cycle. If the number of cycles in which the position difference exceeds the merging consistency threshold (20m) within the 5 cycles is 0, and the number of cycles that do not exceed the preset allowable value by 1, the verification is successful.
[0101] The 24th cycle merge verification passed. The system re-executed the basic condition verification, and after passing, the flight plan was queried and matched successfully: VID-D2 was merged into the compliance identifier UAS-D2, and the set was completed. Reset to an empty set and clear the transition conditions for the identifier change. D2 enters the trust observation period.
[0102] The system will add the trust observation period condition (lower limit Level II) to the threat level lower limit trigger condition set. D2 has now been converted into a compliance target. Calculated according to the compliant formula. Since the sliding window has just been initialized, the number of effective periods in periods 24 and 25 is insufficient to meet the threshold. The default value is 0.10; starting from the 26th cycle. Calculated using the formula, it is approximately 0.05~0.09. The threat level after dual-channel fusion should be Level I, but the lower limit constraint locks it at Level II. For example... Figure 4 As shown, the threat level for D2 remained at Level II throughout cycles 24 to 31.
[0103] When the 32nd trust observation period (8 periods) expires, the system removes the trust observation period conditions, the trigger condition set becomes empty, and the lower bound is cleared. At this time... =0.097、 =0.064, the threat level dropped to Level I, and remained stable thereafter. By cycle 59, D2 was flying normally along the new route. =0.042. For example... Figure 5 As shown in (a) of D2, It dropped from 1.0 to 0.10 in the 24th cycle and has remained at a low level ever since.
[0104] D3 (Prediction of Tiered Handling and Linkage Effects of Non-Compliant Targets): D3 is always a non-compliant target. The value is consistently set to 1.0. In period 0, D3 is approximately 848 m from the center of the sensitive area, located outside the buffer zone, indicating low spatial sensitivity. The representative anomaly code is the normal state code, obtained from a table. =0.40, mapped to Level II. The system performs Level II action (enhanced monitoring and push warnings).
[0105] D3 continues to approach the sensitive area: in the 19th cycle, it was about 572 m away from the sensitive area, and in the 23rd cycle, it was about 513 m away. Both were outside the buffer zone, and the spatial sensitivity remained low, while the threat level remained at Level II.
[0106] In cycle 24, D3 is approximately 497 m from the sensitive region, entering the buffer zone (500 m), and its spatial sensitivity jumps from low to medium. The representative anomaly code remains normal (still more than 400 m from the sensitive region, Type 1 approximation mode not triggered), according to the table... =0.55, exceeding the Level III threshold of 0.50, the threat level rises to Level III. The system initiates Level III response: enhanced monitoring and push notifications, enters continuous monitoring phase and starts the observation time limit. Subsequently, D3 continued to approach, reaching approximately 403 m from the sensitive area in the 31st cycle, still beyond the Type 1 trigger distance (400 m).
[0107] In cycle 32, D3 flies to a distance of approximately 385 m from the sensitive region, which is less than the Type 1 anomaly trigger distance of 400 m, and the approach rate meets the condition. The second layer then writes the Type 1 code (approaching the sensitive region mode) into the set. ={1}. Representative anomaly coding is taken as Type 1 (highest priority). Third-level expert rules are obtained by looking up tables based on Type 1, intermediate sensitivity, and severe deviation. =0.92, exceeding the Level IV threshold of 0.75, the threat level has been raised to Level IV.
[0108] The fourth layer executes Level IV response for D3. Based on the linkage effect prediction mechanism, the system calculates the impact zone (radius 300m) and writes it into the active record. Track prediction identifies that D1 will enter the impact zone. Following the principle of avoidance before response, an avoidance command is first issued to D1, followed by countermeasures against D3. The Level IV countermeasure execution is completed and the process ends.
[0109] D3 then maintained Level IV until the end of the simulation. In cycle 59, D3 was only about 5.7 m from the center of the sensitive area. The D3 trajectory approached the center of the sensitive area in a straight line.
[0110] Figure 3 The flight paths of three targets are shown, including a sensitive area (radius 200 m), with an outer circle representing a buffer zone. Hollow markers indicate the starting point, and solid markers indicate the ending point. The thin gray line represents the D1 approved route. The track turning segment of D1 near the 32nd cycle is the temporary equivalent authorized route.
[0111] Figure 4 The threat level changes of three targets over 60 assessment periods are shown. D1 (black) was upgraded from Level I to Level III and then downgraded to Level II due to evasion exemption; D2 (red) remained at Level II after consolidation verification and was subject to the lower limit of the trust observation period, and then downgraded to Level I after the observation period ended; D3 (green) was upgraded from Level II to Level III and then to Level IV and remained thereafter.
[0112] Figure 5 (a) in the middle is As the evaluation cycle changes, the gray level marks three grading thresholds: 0.25, 0.50, and 0.75. Figure 5 (b) in the middle is As the evaluation cycle changes, the gray-level marking threshold for abnormal behavior is 0.50. During the D1 avoidance period... freeze, The phenomenon of taking 0 can be clearly observed.
[0113] The following basic concepts need to be explained in this invention:
[0114] 1. Basic Agreements:
[0115] The control object of this invention is unmanned aerial vehicles (UAVs). The flight path information of manned aircraft is provided by an external air traffic control system and included in collision risk calculations as known flight paths, but they are not subject to identification management, threat assessment, or control measures. Remote Identification (RID) is the mechanism by which UAV systems broadcast their own identification information. A valid RID refers to a broadcast signal with a complete format, parsable content, and containing a valid UAS ID (Unmanned Aircraft System Identifier); a valid UAS ID refers to an UAV system identification number that conforms to a preset format specification and can be parsed by the system. A compliant target refers to a target that broadcasts a valid RID and has passed compliant identity verification (including targets within the trust observation period). A transitional target refers to a target that broadcasts a valid RID but whose flight plan matching status is unmatched; its identifier is the UAS ID in the RID, and it is not a compliant target. When a target enters a transitional state, the system records the start time of the transitional state and sets the effective duration of the transitional state to zero. Each evaluation cycle adds a preset evaluation cycle duration to the effective duration of the transitional state. Cycles in which the avoidance marker (including two sub-states: pending and already effective) is in the already effective sub-state are not included in the calculation. VID (Virtual Identifier) is an internal identifier code assigned by the system. A compliance identifier refers to the identity status of a compliant target using its UAS ID as the system identifier, as opposed to the virtual identifier (VID). A non-compliant target refers to a target identified by its VID and processed according to rules for non-compliant targets at each layer, including targets assigned a VID without broadcasting a valid RID, targets whose compliance identity recognition has been suspended, and targets undergoing merge verification. The trust observation period is a preset time window during which the system imposes stricter monitoring constraints on a target after it acquires a new compliance identifier. Flight plan matching refers to retrieving the corresponding flight plan from the flight plan database using the target's UAS ID as the key, provided the current time is within the valid period of that flight plan. Flight plans here do not include temporary equivalent authorized routes generated at layer four. A neighboring target pair refers to a pair of flying targets whose predicted nearest distance is less than a preset neighbor screening distance within the prediction window, including target pairs consisting of UAVs and manned aircraft. A sensitive area refers to a geographical area whose spatial sensitivity level reaches a preset sensitive area threshold. A suspected camouflage marker is a marker set by the system for targets suspected of identity camouflage; it can only be removed after manual review by the operator.
[0116] Flight platform type is preferentially derived from RID data, followed by flight plan; if neither is available, it is marked as unknown. Non-compliant targets are marked as unknown. Flight platform type is re-determined according to the above rules for each assessment cycle of the first layer. Baseline route definition: For targets where the avoidance marker is in effect and the avoidance route data is not empty, the route recorded in the avoidance route data is used; for other compliant targets, the currently valid temporary equivalent authorized route (if it exists) in the flight plan database is used; otherwise, the currently valid flight plan for the target in the flight plan database (excluding temporary equivalent authorized routes) is used; there is no baseline route definition for other non-compliant and transitional targets.
[0117] 2. Situational Base Map:
[0118] The situational awareness map is a unified data set of all tracked targets and the overall system status. Target-level data includes, categorized as follows: Identification-related fields (target identifier, flight platform type, flight plan matching status, camouflage suspicion marker, trust observation period status, merge verification session status (values include no merge verification, merge verification in progress), suspended compliance identity verification marker, RID hold-up timer, transition state start time and transition state effective duration, etc.), track-related fields (fused position and velocity vectors, track history), anomaly detection-related fields (position cross-validation deviation rate and its availability marker, cross-validation missing status, set Ω and anomaly composite degree, behavioral anomaly degree and its availability marker, representative anomaly code), collision risk-related fields (collision risk peak, list of collision proximity target identifiers), and threat assessment-related fields (compliance deviation rate, dual-channel score, etc.). , The system-level data includes: merged threat level, lower limit of threat level and its triggering condition set, high threat cumulative timer, cumulative value of Level III response observation period, flight plan supplement request flag and sending time, identity verification request status, start time of post-confirmation observation period, etc.; avoidance-related fields (avoidance flag and sub-status, current avoidance command type: including avoidance route, emergency avoidance, hovering, and forced return or nearest landing command, avoidance route data, and avoidance trigger source list). System-level data includes merged exclusion lists, status transition counters for each UAS ID, and active response impact domain records.
[0119] The absence of an avoidance marker indicates that the target is not in the state of executing avoidance instructions. When the avoidance marker is cleared, the system terminates the avoidance instructions being executed for that target, simultaneously clears the avoidance route data, and removes the temporary equivalent authorized route associated with the target from the flight plan database. The above operations take effect immediately.
[0120] The merge exclusion list contains two types of entries. (a) VID-RID pairing entries (i.e., the pairing record of a specific VID with the UAS ID in its detected RID), which only prevents the merge verification of that specific pairing, has a preset validity period, and is automatically removed after expiration. (b) UAS ID entries, which block all compliant identity verification paths for that UAS ID, remain valid until removed after the operator unlocks it.
[0121] Each entry in the threat level lower limit trigger condition set contains a trigger condition identifier and a corresponding lower limit level. The threat level lower limit is the highest value of the corresponding lower limit level of each entry. When the trigger condition is no longer met, the entry is removed. When the set is empty, the threat level lower limit is cleared.
[0122] 3. Pre-verification of compliant identity:
[0123] The pre-verification of compliance identity (hereinafter referred to as pre-verification) includes: the UAS ID has a valid record in the registration database; there is no UAS ID entry for this UAS ID in the merge exclusion list; there are no other tracked targets identified by this UAS ID in the current situation map; and there is no merge verification session using this UAS ID. The merge verification path also requires the following additional conditions: there is no valid VID-RID pairing entry for this VID-RID pairing, and the target's suspended compliance identity verification flag is not in a set state. Verification is suspended when the registration database is unavailable and will be re-initiated after recovery. Verification is rejected if any of the above conditions are not met.
[0124] 4. Rules for changing logos:
[0125] The basic rules for label changes (hereinafter referred to as the basic rules) are as follows: (a) Set Ω is reset to an empty set; (b) Track history, camouflage suspicion markers, and avoidance-related fields are retained in the changed label, and avoidance-related fields include avoidance markers and sub-states, current avoidance instruction type, avoidance route data, and avoidance trigger source list; (c) Target labels recorded in issued avoidance instructions and associated temporary equivalent authorized routes are synchronously updated to the changed label; (d) High threat cumulative timer, Level III response observation time limit cumulative value, identity verification request status, and flight plan supplement request markers are set to zero or reset; (e) If the collision risk trigger source entries of other targets in the situation map reference the previous label in the avoidance trigger source list, their collision proximity target labels are synchronously updated to the changed label. Target-level data fields not explicitly listed above retain their previous values until recalculated by the corresponding layer in subsequent assessment cycles.
[0126] After the transition period conditions for the identifier change are written into the lower limit trigger condition set of the threat level, they are automatically removed after a preset duration. The timer for this duration is paused while the evasion marker is in an effective sub-state.
[0127] Additional rules for compliance to non-compliance: The trust observation period ends and the trust observation period condition in the threat level lower limit is removed (if any); the cross-validation missing status is cleared and the corresponding lower limit condition is removed (if any); if the threat level before the change is level II or above, the change transition period condition (the lower limit level is the threat level before the change) is written into the threat level lower limit trigger condition set.
[0128] Additional rules for non-compliant to compliant transition: Remove transitional conditions for identification changes (if any) and suspended compliant identity recognition marks (if any).
[0129] Downgrade Handling: Assign a VID to the target, process it according to the basic rules, do not increment the state transition counter, and subsequently evaluate and handle it as a non-compliant target. If the target does not yet have a registered identifier in the system, the inheritance and update operations in the basic rules are considered as initial assignments. Compliance Downgrade Handling: Assign a VID to the target, process it according to the basic rules and the additional rules for compliance to non-compliance, and simultaneously trigger the increment of the state transition counter for that UAS ID. Subsequently evaluate and handle it as a non-compliant target.
[0130] When a transitional target becomes a compliant target due to successful flight plan matching, the above rules do not apply because the identifier remains unchanged; however, the transitional conditions for identifier change (if any) are cleared simultaneously. When a compliant target enters transitional status due to flight plan expiration and the identifier remains unchanged, the identifier change rules are not triggered.
[0131] 5. General Rules for Avoiding Exemptions:
[0132] While the evasion marker is in an effective sub-state, the system suspends the following calculations and timekeeping for the target, including the effective period accumulation: location cross-verification deviation rate, horizontal and vertical deviation statistics in compliance deviation, trust observation period, identifier change transition period, high threat cumulative timer, cumulative value of Level III handling observation time limit, post-confirmation observation time limit (the time-limited observation window entered after the operator confirms its effectiveness, see the fourth layer), and effective duration of the transition state.
[0133] Regarding behavioral anomaly score: skip anomaly detection, behavioral anomaly score Set the value to 0, and the availability flag is set to available; abnormal composite degree Set to 0, not calculated based on set Ω; representative anomaly coding. Take normal state code The set Ω remains unchanged, but resets triggered by identity changes are not subject to this restriction.
[0134] The aforementioned exemption values are written to the situation map by the second layer when the target avoidance marker is detected to be in an active sub-state during the current assessment cycle. The clearing timer and count for each anomaly type in set Ω are synchronously paused. Collision risk calculation is performed normally.
[0135] 6. Evaluation cycle scheduling:
[0136] The system operates according to a preset evaluation cycle. The four-layer execution is triggered sequentially. At the start of each assessment cycle, the scheduler switches all evasion markers in the situation map that are in a pending sub-state to an active sub-state. It then removes expired VID-RID pairs from the exclusion list and checks and removes expired time-limited conditions in the threat level lower limit trigger condition set, triggering the four layers sequentially. The status update outputs of the fourth layer (temporary equivalent authorized routes, marker status changes, pending writes of evasion markers, etc.) are only read by the preceding layer in the next assessment cycle and take effect at that time. Evasion marker clearing takes effect immediately; evasion instructions are issued immediately after the fourth layer is executed, and when predicting cascading effects, they are issued in the order of evasion followed by action. Evasion route instructions and Level III non-compliant actions are continuous measures, extending across cycles; Level I and Level II non-compliant actions are regenerated each assessment cycle based on the current threat level; Level IV non-compliant countermeasures end upon completion. If a layer times out or a sensor is interrupted, operation continues based on the most recent valid output and requests operator intervention.
Claims
1. A method for multi-state target threat assessment and collaborative control for the low-altitude economy, characterized in that, Includes the following steps: Step 1: For flight targets within the airspace, based on their identity broadcast status and flight plan matching status, they are uniformly classified into three identity statuses: compliant targets, transitional targets, and non-compliant targets, and differentiated identity management is implemented. Among them, transitional targets refer to targets that broadcast valid RIDs but whose flight plan matching status is unmatched. Their identifier is the UAS ID in the RID, and they are not compliant targets. Step 2: When a target that already holds a virtual identifier within the system begins broadcasting a valid operational identification signal, the merging verification and certification process is initiated; Step 3: When generating avoidance routes for compliant or transitional targets in response to changes in airspace situation, the avoidance routes are synchronously recorded in the flight plan database and marked as temporary equivalent authorized routes. This allows the threat assessment module to calculate deviations based on the updated baseline routes, thus distinguishing between system-mandated avoidance behaviors and unauthorized route deviations. The compliance deviation is a dual-channel threat assessment architecture with shared input, used to quantify the degree of deviation of the target's flight behavior from the baseline routes. The two assessment channels are a data-driven assessment channel and an expert rule assessment channel. The final threat level of the target is determined by fusing the threat levels output by the two channels. The expert rule assessment channel obtains a basic threat score by querying a pre-set threat classification lookup table. The threat classification lookup table uses the target's representative abnormal behavior type, compliance deviation level, and the spatial sensitivity level of the current airspace as input conditions. It pre-sets basic threat scores under different combinations of conditions based on domain expert knowledge and then weights and adjusts the basic threat scores using the current time scenario factor. The data-driven channel takes the feature value: behavior anomaly degree. Collision risk peak Compliance Deviation Abnormal Complexity Output the weighted sum according to preset weights. ; Step 4: Before taking countermeasures against non-compliant targets, predict the ripple effects, determine the scope of impact based on the physical characteristics of the proposed measures, and identify all compliant and transitional targets that are about to enter the scope of impact based on trajectory prediction. Prioritize issuing evasion instructions to the affected targets. After the evasion instructions are issued, take countermeasures against non-compliant targets.
2. The method for multi-state target threat assessment and collaborative control for low-altitude economy according to claim 1, characterized in that, In step 2, a preliminary verification is performed before the merge verification process, including: verifying that the identifier in the running identification signal has a valid record in the registration database, verifying that there are no prohibited merge entries for the identifier, and verifying that there are no other targets in the current airspace situation using the identifier or using the identifier for merge verification.
3. The method for multi-state target threat assessment and collaborative control for low-altitude economy according to claim 1, characterized in that, Step 2 specifically involves: during the preset verification period, simultaneously maintaining track tracking based on the target's virtual identifier and track tracking based on its broadcast location, and comparing them periodically; when the position difference between the two tracks meets the preset consistency condition, the merge verification is deemed successful, and the target's identity is converted into a compliant target or a transitional target based on the flight plan matching result.
4. The method for multi-state target threat assessment and collaborative control for low-altitude economy according to claim 1, characterized in that, In step 3, the compliance deviation is as follows: according to the preset priority order, the target is judged to see if it meets the rules, and the corresponding compliance deviation value is adopted when the first applicable rule is met; for targets that do not have a valid operating identification signal or are undergoing merging verification, the compliance deviation is directly set to the highest value; for targets that are marked as having suspected identity spoofing, the compliance deviation is directly set to the highest value during the period when the suspected mark exists. For transitional targets, during a pre-set retry period after entering the transitional state, the compliance deviation is set to a low fixed value. If the retry period exceeds this time and the target still fails to become a compliant target, the compliance deviation is raised to a high fixed value. For compliant targets that do not meet any of the rules, the compliance deviation is determined based on the maximum value among the following three factors: the degree of lateral deviation between the actual flight path and the reference route, the degree of altitude deviation, and the position cross-validation deviation rate obtained from multi-source sensor data.
5. The method for multi-state target threat assessment and collaborative control for low-altitude economy according to claim 1, characterized in that, The method also includes setting and updating a threat level lower limit for each target, which is determined by a set of triggering conditions. When a target is in any of the following states: trust observation period, missing location cross-verification, or changed identity, the corresponding condition entry is triggered, and a threat level lower limit not lower than a preset level is set to prevent underestimation of the threat level of the target due to state transition or missing information.
6. The method for multi-state target threat assessment and collaborative control for low-altitude economy according to claim 1, characterized in that, The method also includes an evasion exemption mechanism, specifically: when the target is in the process of executing an evasion command, the system suspends the effective periodic accumulation of various statistical indicators that characterize abnormal behavior and route deviation, and at the same time forces the input used for abnormal behavior assessment to be set to a value that represents a normal state.
7. The method for multi-state target threat assessment and collaborative control for low-altitude economy according to claim 1, characterized in that, The method also includes a state transition anti-oscillation mechanism, which is as follows: for each target that has obtained a compliant identity, maintain a counter for the number of times it has changed from a compliant state to a non-compliant state; when the counter value reaches a preset threshold, the identity identifier is added to the prohibited merging list and its non-compliant state is locked, which must be unlocked after operator review and confirmation.
8. A multi-state target threat assessment and collaborative control system for low-altitude economy, employing the method described in any one of claims 1-7, characterized in that, include: Multi-source heterogeneous data fusion module: used to access multi-source information including operation identification broadcast data, non-cooperative sensor detection data, flight plan data and registration data, and fuse them into a spatiotemporally consistent global situational map. It is also responsible for three-state identity management, merging verification and identification, and cross-verification of location information. Flight behavior feature sequence extraction module: used to extract the behavior feature sequence of each flight target from the situation map, and identify whether it has predefined abnormal behavior patterns such as approaching sensitive areas, abnormal hovering, flight path deviation, and abnormal altitude changes, while calculating the degree of collision risk with other targets in the airspace; Dual-channel threat assessment module: It uses compliance deviation degree, which quantifies the degree to which the target flight behavior deviates from the baseline route, as a common input. It assesses the threat level through a data-driven assessment channel and an expert rule-based assessment channel, respectively. After fusing the assessment results of the two channels and combining them with the existing threat level lower limit constraints, it outputs the final threat level. The differentiated control scheme automatic generation module is used to generate a tiered response plan for non-compliant targets based on the final threat level, including monitoring, warning, continuous observation to countermeasures, and to initiate linkage effect prediction before implementing countermeasures; for compliant targets and transitional targets, when they face collision risks or are affected by the response, it automatically generates avoidance routes and writes them into the flight plan database as temporary equivalent authorized routes.
Citation Information
Patent Citations
Intelligent identification and anti-interference system of low-altitude aircraft
CN121711062A
Drone based security and defense system
US20230071981A1