Multi-agent attack-resistant consensus control method and system based on double-layer observer
By constructing a two-layer observer framework to generate a secure state baseline and combining event-triggered updates and dynamic threshold detection, Byzantine nodes are identified and isolated, solving the consistency tracking problem of multi-agent systems in open communication networks. This achieves elastic consistency tracking under conditions that do not depend on an upper bound on the number of attacking nodes and a robust topology.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGDONG UNIV OF TECH
- Filing Date
- 2026-06-11
- Publication Date
- 2026-07-28
AI Technical Summary
Existing multi-agent systems are vulnerable to Byzantine attacks in open communication networks, leading to reduced detection accuracy and isolation reliability. Furthermore, existing methods rely on an upper bound on the number of attacking nodes or strong robust topology conditions, making them difficult to apply to dynamic networks.
A multi-agent anti-attack consistency control method based on a two-layer observer is constructed. A secure state benchmark that does not depend on neighbor node information is generated through an independent virtual twin layer. By combining event-triggered updates and dynamic threshold detection, Byzantine nodes are identified and isolated, cooperative topology is reconstructed, and a resilient consistency control law is constructed.
It improves the accuracy of Byzantine behavior detection and the reliability of malicious node isolation, reduces communication resource consumption, and achieves elastic consistency tracking in an open network environment, balancing system security, control performance, and communication efficiency.
Smart Images

Figure CN122475931A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intelligent agent consensus control technology, specifically to a multi-agent anti-attack consensus control method and system based on a two-layer observer. Background Technology
[0002] The statements in this section are merely background information related to the present invention and do not necessarily constitute prior art.
[0003] Multi-agent systems are widely used in scenarios such as UAV swarms, spacecraft formations, smart grids, robot networks, and unmanned system collaboration. These systems rely on information interaction among multiple agents to achieve collaborative decision-making. Leader-follower consensus tracking control is an important research direction in multi-agent systems, aiming to enable followers to collectively track the leader's state through distributed control. However, in open communication networks, these systems face challenges such as bandwidth consumption, energy depletion, and network congestion due to continuous communication, and are also vulnerable to attacks from malicious nodes. Therefore, it is necessary to improve existing consensus control methods to reduce communication burdens while enhancing the system's resilience in attack environments.
[0004] Existing resilient consistency control methods for Byzantine attacks typically suppress the influence of malicious nodes through methods such as neighbor information filtering, anomaly data removal, or online detection. However, Byzantine nodes (malicious or faulty nodes) can send inconsistent false information to different neighbors, making attack detection references built based on neighbor interaction information susceptible to contamination, thereby reducing detection accuracy and isolation reliability. Furthermore, some methods require prior knowledge of the upper bound on the number of attacking nodes or rely on strong network topology robustness, requirements that are often difficult to meet in dynamic, open real-world networks, thus limiting the applicability of existing methods in practical scenarios. Summary of the Invention
[0005] To address the aforementioned issues, this invention proposes a multi-agent anti-attack consistency control method and system based on a two-layer observer. It constructs a two-layer observer framework combining an independent virtual twin layer and a network physical layer in an open communication network. Through trusted state benchmark generation, event-triggered updates, dynamic behavior detection, malicious node classification and isolation, and control law design, it achieves elastic consistency tracking of the leader's trajectory by cooperative nodes under Byzantine attack conditions.
[0006] To achieve the above objectives, the present invention adopts the following technical solution: One or more embodiments provide a multi-agent attack-resistant consensus control method based on a two-layer observer, comprising the following steps: An independent virtual twin layer and a network physical layer are constructed for each follower node; In the independent virtual twin layer, a continuous-time feedback observer is run based on the local output information of the follower nodes to generate a security state baseline that does not depend on the information of neighboring nodes. In the network physical layer, the state baseline is sampled, updated and maintained according to the event triggering mechanism to obtain the estimated state of the local node and the estimated state of its neighbors. Based on the network physical layer reception state and the local security state benchmark of the virtual twin layer, the detection error is constructed by obtaining the neighbor node state and the local node security state benchmark, and combined with dynamic threshold to detect Byzantine attack behavior. Based on the detection results, neighboring nodes are classified and the communication edge weights between each follower node are updated in order to isolate Byzantine nodes and reconstruct the cooperative topology. Based on the reconstructed cooperative topology, neighbor error, and local state estimation error, a resilient consistency control law is constructed to generate control inputs for follower nodes, enabling follower nodes to follow the leader node in a consistent manner.
[0007] A further technical solution involves creating a separate virtual twin layer for each follower node. Construct a continuous-time feedback observer that only uses the output of the current follower node. and local observation status The system is continuously updated, and the generated state estimate serves as the safety state baseline.
[0008] A further technical solution involves, at the network physical layer, assigning each follower node... Construct an incremental sequence of event trigger times, and update the security state baseline in the independent virtual twin layer to the network physical layer at each trigger time; Between two consecutive trigger times, the network physical layer uses a zero-order hold method to save the security state baseline of the most recent trigger time.
[0009] A further technical solution, based on the network physical layer's received state and the local security state benchmark of the virtual twin layer, constructs a detection error by comparing the received neighbor node states with the local node's security state benchmark, and combines this with a dynamic threshold to detect Byzantine attack behavior, including the following steps: For any cooperating follower node i, at the event trigger time Receive network physical layer state broadcast by neighbor node j ; The follower node i at the time of the most recent event trigger. The generated independent virtual twin layer security state baseline As a reference for testing; Calculate the deviation between the state of neighbor node j and the safety state baseline of the current follower node as the detection error; Construct a dynamic threshold that decays over time, the dynamic threshold being based on the triggering time of neighbor node j. An exponentially decaying dynamic threshold constructed from threshold parameters and constants; A detection criterion is constructed based on the difference between the detection error and the dynamic threshold. When the detection criterion is not greater than zero, determine the neighboring node. For this node If a node is a cooperative node, then it is a neighboring node. For this node This is a Byzantine node.
[0010] A further technical solution involves classifying neighboring nodes based on the detection results and updating the communication edge weights between each follower node to isolate Byzantine nodes and reconstruct the cooperative topology, including the following steps: Define detection events Safety benchmark conformance events For any follower node i and its neighbor node j, define a detection event. For nodes For neighboring nodes The test results are normal; define a safety baseline consistency event. For: Neighboring nodes At the trigger time The broadcast state value and neighboring nodes The security state benchmark of the independent virtual twin layer is consistent; Based on event detection Safety benchmark conformance events Classify the neighbor node j by type, and then classify the neighbor node... They are classified as cooperative nodes, Byzantine type I nodes, and Byzantine type II nodes. Based on the neighbor node classification results, update the cooperative neighbor set and Byzantine neighbor set of the current node i; Based on the cooperative neighbor set and the Byzantine neighbor set, the communication edge weights between node i and its neighbor node j are... Dynamic updates are performed, and the current cooperative topology matrix is reconstructed based on the updated communication edge weights.
[0011] A further technical solution involves constructing a resilient consensus control law based on the reconstructed cooperative topology, neighbor errors, and local state estimation errors, including the following steps: Based on the reconstructed cooperative topology matrix, determine the effective neighbor information of node i; For any follower node i, based on the reconstructed communication edge weights The network physical layer states of neighbor node j, the network physical layer states of node i, and the leader node state are used to define the observer-based neighbor error of node i. ; For any follower node i, obtain the state estimation error of node i's network physical layer. ; Based on the state matrix A, input matrix B, and reconstructed cooperative topology matrix H(t) in the mathematical model of agent control, the algebraic Riccati equation is constructed and solved to obtain the symmetric positive definite solution P, and then the feedback control gain matrix F is calculated. For any follower node i, based on the neighbor error Error in state estimation at the network physical layer And the feedback control gain matrix F, to construct the elastic consistency control law for node i.
[0012] A further technical solution is that, under the event triggering condition, the difference between two adjacent triggering times satisfies the positive lower bound condition.
[0013] One or more embodiments provide a multi-agent attack-resistant consensus control system based on a two-layer observer, including: The two-layer observer building module is configured to build independent virtual twin layers and network physical layers for each follower node; In the independent virtual twin layer, a continuous-time feedback observer is run based on the local output information of the follower nodes to generate a security state baseline that does not depend on the information of neighboring nodes. In the network physical layer, the state baseline is sampled, updated and maintained according to the event triggering mechanism to obtain the estimated state of the local node and the estimated state of its neighbors. The detection module is configured to obtain the neighbor node status and the local security status benchmark of the virtual twin layer based on the network physical layer reception status and the local security status benchmark of the virtual twin layer, construct the detection error, and combine it with dynamic thresholds to detect Byzantine attack behavior. The abnormal node isolation module is configured to classify neighboring nodes based on the detection results and update the communication edge weights between each follower node in order to isolate Byzantine nodes and reconstruct the cooperative topology. The control solution module is configured to construct a resilient consensus control law based on the reconstructed cooperative topology, neighbor error, and local state estimation error, and generate control inputs for follower nodes, enabling follower nodes to perform consensus tracking of the leader node.
[0014] An electronic device includes a memory and a processor, as well as computer instructions stored in the memory and running on the processor. When the processor executes the computer instructions, the computer instructions perform the steps in the above-described multi-agent anti-attack consistency control method based on a two-layer observer.
[0015] A computer-readable storage medium for storing computer instructions, which, when executed by a processor, perform the steps in the above-described multi-agent anti-attack consistency control method based on a two-layer observer.
[0016] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention constructs a two-layer observer architecture consisting of an independent virtual twin layer and a network physical layer. The security state baseline is continuously generated by the independent virtual twin layer based on local output, without relying on neighbor node interaction information. This avoids the contamination of the detection reference by Byzantine node spoofing, improving the accuracy of Byzantine behavior detection and the reliability of malicious node isolation. Simultaneously, the event-triggered update mechanism of the network physical layer reduces resource consumption caused by continuous communication. Combined with dynamic threshold detection, node classification, communication edge weight updates, and cooperative topology reconstruction, it isolates identified Byzantine nodes from the cooperative topology without prior knowledge of the upper bound of the number of attacking nodes or relying on strong robust topology conditions. This enables elastic consistency tracking of the leader node by cooperative follower nodes in an open network environment, while balancing system security, control performance, and communication efficiency.
[0017] The advantages of the present invention, as well as its additional advantages, will be described in detail in the following specific embodiments. Attached Figure Description
[0018] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute a limitation thereof.
[0019] Figure 1 This is a flowchart of the multi-agent anti-attack consensus control method based on a two-layer observer according to Embodiment 1 of the present invention; Figure 2 This is a schematic diagram of dynamic network topology reconstruction of a multi-agent system under Byzantine attack in a simulation example of Embodiment 1 of the present invention; Figure 3 This is a planar trajectory diagram of a multi-agent system under a Byzantine attack in a simulation example of Embodiment 1 of the present invention; Figure 4 This is a graph showing the number of event triggers of cooperative nodes under a Byzantine attack in a simulation example of Embodiment 1 of the present invention; Figure 5 This is a tracking error curve of a cooperative node in a multi-agent system in a simulation example of Embodiment 1 of the present invention; Figure 6 This is a tracking error curve of the isolated Byzantine node 4 in the simulation example of Embodiment 1 of the present invention; Figure 7This is a simulation example of the independent virtual twin layer TL state estimation error curve in Embodiment 1 of the present invention; Figure 8 This is a simulation example of the network physical layer CPL state estimation error curve in Embodiment 1 of the present invention; Detailed Implementation The present invention will be further described below with reference to the accompanying drawings and embodiments.
[0020] It should be noted that the following detailed descriptions are exemplary and intended to provide further illustration of the invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.
[0021] It should be noted that the terminology used herein is for describing particular embodiments only and is not intended to limit the exemplary embodiments of the present invention. As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. Furthermore, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof. It should be noted that, without conflict, the various embodiments and features within those embodiments can be combined with each other. The embodiments will now be described in detail with reference to the accompanying drawings.
[0022] Example 1 In one or more of the technical solutions disclosed in the embodiments, such as Figures 1 to 8 As shown, a multi-agent anti-attack consensus control method based on a two-layer observer is applied to a multi-agent system containing a leader node and multiple follower nodes to achieve multi-agent consensus control, including the following steps: Step 1: Construct an independent virtual twin layer and network physical layer for each follower node; In the independent virtual twin layer, a continuous-time feedback observer is run based on the local output information of the follower nodes to generate a security state baseline that does not depend on the information of neighboring nodes. In the network physical layer, the state baseline is sampled, updated and maintained according to the event triggering mechanism to obtain the estimated state of the local node and the estimated state of its neighbors. Step 2: Based on the network physical layer reception status and the local security status benchmark of the virtual twin layer, obtain the neighbor node status and the security status benchmark of the local node to construct the detection error, and combine it with dynamic threshold to detect Byzantine attack behavior. Step 3: Classify neighboring nodes based on the detection results and update the communication edge weights between each follower node to isolate Byzantine nodes and reconstruct the cooperative topology; Step 4: Based on the reconstructed cooperative topology, neighbor error, and local state estimation error, construct a resilient consensus control law to generate control inputs for follower nodes, enabling follower nodes to follow the leader node in a consistent manner. Specifically, the local state estimation error is constructed based on the network physical layer state of this node and the actual state of this node, and the neighbor error is constructed based on the network physical layer state of neighboring nodes, the network physical layer state of this node, and the state of the leader node. This embodiment constructs a two-layer observer architecture consisting of an independent virtual twin layer and a network physical layer. The security state benchmark is continuously generated by the independent virtual twin layer based on local output, without relying on neighbor node interaction information. This avoids the contamination of the detection reference by Byzantine node false broadcasts, improving the accuracy of Byzantine behavior detection and the reliability of malicious node isolation. At the same time, the event-triggered update mechanism of the network physical layer reduces the resource consumption caused by continuous communication. Combined with dynamic threshold detection, node classification, communication edge weight update, and cooperative topology reconstruction, the identified Byzantine nodes are isolated from the cooperative topology without knowing the upper bound of the number of attacking nodes in advance and without relying on strong robust topology conditions. This enables elastic consistency tracking of the leader node by cooperative follower nodes in an open network environment, while taking into account system security, control performance, and communication efficiency.
[0023] Before constructing the two-layer observer, we first establish the basic dynamic model of the multi-agent system.
[0024] First, construct a system consisting of a leader node and... A linear multi-agent system consisting of follower nodes. For any follower node... Its dynamic model is expressed as: ; ; The dynamic model of the leader node is represented as follows: ; in, For the first The state vector of each follower To control the input, This is the output vector; In the leader's state, The input signal is bounded. For the system matrix, For the input matrix, This is the output matrix.
[0025] Optionally, a time-varying directed graph can be used. Describe the communication topology of a multi-agent system, where, Let be the set of edges. For a weighted adjacency matrix; when When, it indicates a node Able to receive nodes Information at this time ,otherwise ,and Define nodes The set of neighbors is as follows: ; Define the in-degree matrix and Laplace matrix ; in-degree matrix The total connection weight received by each follower node from its neighboring nodes is used to describe the total connection weight, expressed as: ; ; in, The in-degree of the i-th follower node at time t; Let i be the set of neighbors. All edge weights; Laplace matrix This is used to describe the topology and coupling relationships between nodes in a multi-agent system, and is represented as: ; Let node 0 be the leader node. Some followers can directly obtain information from the leader. The pinning matrix is a matrix used to describe the follower nodes that can directly receive information from the leader node. The pinning matrix is defined as follows: ; Specifically, when the i-th follower is able to receive the leader's information, ,otherwise Therefore, the interaction matrix is defined. for: ; Furthermore, define the first The tracking error of each follower relative to the leader: ; The control objective of this embodiment is to keep the tracking errors of all cooperative follower nodes consistent and eventually bounded in the presence of a Byzantine attack. Further technical solutions include constructing a two-layer observer architecture, including: Independent Virtual Twin Layer (TL Layer) is used to continuously generate security state baselines. It runs a feedback observer over a continuous time based on the local output information of follower nodes to generate security state baselines that do not depend on the information of neighboring nodes. The Network Physical Layer (CPL layer) is used to sample, update, and maintain the state baseline according to the event-triggered mechanism to obtain the estimated state of the local node and the estimated state of its neighbors. The two-layer observer architecture constructed in this embodiment is used to provide input for subsequent Byzantine detection, classification isolation, and resilient consistency control.
[0026] In step 1, within the independent virtual twin layer, for each follower node... Construct a continuous-time feedback observer that only uses the output of the current follower node. and local observation status For continuous updates, the state update equation of the feedback observer is: ; in, For the first The state estimates generated by each follower in an independent virtual twin layer are used as a security state baseline and updated to the network physical layer (CPL). Given the observer gain matrix, the state estimation error of the independent virtual twin layer is defined as: ; Because the feedback observer of the independent virtual twin layer only utilizes the output of its own follower node. and local observation status It is continuously updated and does not rely on state information sent by neighboring nodes, so the state baseline generated in the independent virtual twin layer is not polluted by malicious broadcast data from Byzantine nodes.
[0027] In step 1, at the network physical layer (CPL layer), for each follower node... Construct a strictly increasing sequence of event trigger times. and at the trigger time The security state baseline in the independent virtual twin layer is updated to the network physical layer (CPL); between two adjacent trigger times, the network physical layer (CPL) uses a zero-order hold method to save the security state baseline of the most recent trigger time (TL), that is: ; Define the state estimation error of the CPL layer as: ; This results in a two-layer state evolution structure where TL continuously generates the safety state baseline and CPL discretely triggers and updates the state.
[0028] Furthermore, for any neighboring node When it is triggered Broadcast status value Afterwards, cooperative follower nodes For the neighbor node The CPL storage state is updated using the zero-order hold method as follows: ; When neighboring nodes When a node is a cooperative follower, its broadcast value satisfies: ; When neighboring nodes When it is a Byzantine node, its broadcast value is any deceptive value, and satisfies: ; This embodiment introduces an event-triggered mechanism into the two-layer observer resilient control framework. The CPL layer updates the TL layer's security state baseline only when the event triggering conditions are met. Specifically, the CPL layer does not update the state continuously; instead, it updates the security state baseline of the independent virtual twin layer TL to the network physical layer only when the event triggering conditions are met. Between two adjacent triggering moments, the CPL layer uses a zero-order hold method to save the state baseline of the most recent triggering moment. Furthermore, the event triggering conditions described later incorporate both the CPL local state estimation error and the global tracking error relative to the leader into the decision, ensuring that nodes only perform state updates and communication when necessary. This reduces communication frequency and improves communication resource utilization efficiency.
[0029] Step 2: Based on the received state of the network physical layer and the local security state benchmark of the virtual twin layer, construct the detection error by comparing the received neighbor node state with the security state benchmark of the current node, and combine this with a dynamic threshold to detect Byzantine attack behavior, including the following steps: Step 21, Receive neighbor node status: For any cooperative follower node i, at the event trigger time... Receive network physical layer state broadcast by neighbor node j ; Step 22: Select local detection reference: based on the most recent event trigger time of the current follower node i. The generated independent virtual twin layer security state baseline As a reference for testing; Step 23: Construct the detection error: Calculate the deviation between the state of neighbor node j and the safety state benchmark of this follower node as the detection error; Specifically, cooperative follower nodes Upon receiving neighbor nodes At the trigger time After broadcasting the state value, follow the follower nodes. At the last trigger moment TL state reference As a detection reference, construct a method for targeting neighboring nodes. The detection error is: ; Step 24: Construct a dynamic threshold that decays over time, wherein the dynamic threshold is based on the triggering time of neighbor node j. An exponentially decaying dynamic threshold is constructed using threshold parameters and constants to enable multiple agents to change their states over time and reduce the probability of false alarms caused by deviations from normal states. This embodiment constructs a dynamic threshold that decays over time, which can adapt to the normal dynamic changes in the state of multiple agents and avoid false alarms caused by deviations from the normal state. Specifically, construct a target for neighboring nodes. The dynamic threshold is: ; in, , , For threshold parameters, It is a constant.
[0030] Step 25: Construct a detection criterion based on the difference between the detection error and the dynamic threshold. When the detection criterion is not greater than zero, determine the neighboring node. For this node If a node is a cooperative node, then it is a neighboring node. For this node This is a Byzantine node.
[0031] The detection criteria are: ; when At that time, determine the neighboring nodes. For nodes As a cooperative node; when At that time, determine the neighboring nodes. For nodes This is a Byzantine node.
[0032] In step 3, neighboring nodes are classified based on the detection results, and the communication edge weights between each follower node are updated to isolate Byzantine nodes and reconstruct the cooperative topology. This includes the following steps: Step 31: Define the detection event Safety benchmark conformance events ; For any follower node i and its neighbor node j, define a detection event. For nodes For neighboring nodes The test results are normal, which means the following: ; Define security baseline consistency events For: Neighboring nodes At the trigger time The broadcast state value and neighboring nodes The security state baseline of the independent virtual twin layer is consistent, as shown below: ; Step 32, based on detection events Safety benchmark conformance events Classify the neighbor node j by type, and then classify the neighbor node... Nodes are classified into cooperative nodes, Byzantine type I nodes, and Byzantine type II nodes. The specific classification method is as follows: (1) When neighboring node j simultaneously satisfies the detection event Safety benchmark conformance events ,Right now If the neighbor node j is a cooperative node, then the neighbor node j is a cooperative node. (2) When neighboring node j does not simultaneously satisfy the detection event Safety benchmark conformance events ,Right now If the neighboring node j is a Byzantine type I node; (3) When neighbor node j does not satisfy the detection event Safety benchmark conformance events ,Right now If the neighboring node j is a Byzantine type II node; Step 33: Based on the neighbor node classification results, update the cooperative neighbor set and Byzantine neighbor set of the current node i; Specifically, define nodes The set of cooperative neighbors is the set of neighbor nodes that have passed the detection and whose broadcast state is consistent with the TL safety state benchmark in all triggering times up to the current time t, and is represented as: ; Define nodes The Byzantine neighbor set is the set of neighbor nodes that, as of the current time t, have at least one detected anomaly or have an inconsistent TL safety state baseline, denoted as: ; Step 34: Based on the set of cooperative neighbors Gathering with Byzantine neighbors The communication edge weights between node i and its neighbor node j Dynamically update the current cooperative topology matrix H(t) based on the updated communication edge weights; Based on the neighbor classification results, the communication topology is dynamically reconstructed, and the edge weights are updated as follows: ; This isolates the identified Byzantine nodes from the current cooperative topology.
[0033] After completing the edge weight update, all those that satisfy... The communication edges are removed from the current cooperative topology, and all edges that satisfy the condition are retained. The communication edge is used to isolate the identified Byzantine nodes from the cooperative topology, forming a reconstructed topology in which only normal cooperative nodes participate in information interaction.
[0034] In the above implementation, by combining the detection results of neighboring nodes with the consistency results of the TL security state benchmark, online identification, anomaly classification, and dynamic updating of communication edge weights of neighboring nodes are achieved. Compared with existing Byzantine fault-tolerant consistency methods that rely on a prior upper bound on the number of attacking nodes or strong robust graph conditions, this embodiment does not require prior knowledge of the upper bound on the number of Byzantine attacking nodes in the network, nor does it require the original communication network to meet strict topological conditions such as strong robustness. It only needs to maintain connectivity in the cooperative topology reconstructed after the Byzantine nodes are isolated to achieve the identification and isolation of abnormal nodes.
[0035] Therefore, this embodiment reduces the dependence of Byzantine attack detection and resilient consistency control on prior network information and topology, improving the applicability of the algorithm in scenarios with unknown attack scale, dynamic attack behavior, and general communication topology. Simultaneously, by setting the communication edge weights of nodes identified as Byzantine nodes to zero while preserving valid communication connections between cooperative nodes, this embodiment can dynamically eliminate abnormal information sources during operation and reconstruct a cooperative topology where only trusted cooperative nodes participate in information exchange. This effectively suppresses the interference of Byzantine nodes on the consistency control process and ensures the stable tracking performance of normal cooperative nodes on the leader's trajectory.
[0036] Step 4: Construct a resilient consensus control law based on the reconstructed cooperative topology, neighbor errors, and local state estimation errors, including the following steps: Step 41: Based on the reconstructed cooperative topology matrix, determine the effective neighbor information of node i; For any follower node i, the reconstructed communication edge weights obtained in step 3 are used as follows: Determine the effective neighbor nodes of node i that can be used for collaborative control at the current time t, that is: when When the neighbor node j is a cooperative neighbor node, node i receives and uses the state information of neighbor node j to participate in cooperative control. Step 42: Construct the observer-based neighbor error for node i. ; For any follower node i, based on the reconstructed communication edge weights The observer-based neighbor error of node i is defined by considering the CPL layer states of neighbor node j, the CPL layer state of node i, and the leader node state. for: ; in, Let i represent the set of neighboring nodes of node i at time t. This represents the reconstructed communication edge weight between node i and its neighbor node j. This indicates the CPL layer state of neighbor node j. This represents the CPL layer state of node i itself. Indicates the state of the leader node. This represents the connection weight between node i and the leader node.
[0037] Neighbor error in this embodiment Used to characterize the relative state deviation between node i and its cooperative neighbor nodes, and the tracking deviation between node i and the leader node; Step 43: For any follower node i, obtain the state estimation error of node i's CPL layer. ,Right now: ; Define the state estimation error of the CPL layer as: ; Step 44: Based on the state matrix A, input matrix B, and reconstructed cooperative topology matrix H(t) in the mathematical model of agent control, construct and solve the algebraic Riccati equation to obtain the symmetric positive definite solution P, and then calculate the feedback control gain matrix F. Construct and solve the following algebraic Riccati equation: ; Where P is the symmetric positive definite matrix to be solved, and A and B are the system state matrix and input matrix, respectively. This represents the minimum topology matrix corresponding to the reconstructed cooperative topology. Represents the minimum topological matrix The smallest eigenvalue; Furthermore, we define the reconstructed cooperative topology matrix. The symmetrical part is:
[0038] And order: ; When the system When the cooperative subgraph remains connected after being stably isolated by Byzantine nodes, the algebraic Riccati equation has a unique positive definite solution. ; Control gain matrix Determined by the following formula: ; Step 45: For any follower node i, based on the neighbor error... CPL layer state estimation error And the feedback control gain matrix F, construct the elastic consistency control law for node i as follows: ; in, For observer-based neighbor error, For nodes The state estimation error of the CPL layer.
[0039] This control law utilizes neighbor information under the reconstructed topology for collaborative control.
[0040] A further technical solution involves calculating the control input of node i based on the elastic consistency control law: For any follower node i, at the current time t, node i calculates its control input as follows: First, based on the communication edge weights obtained in step 3 Filter out those that meet the requirements The cooperative neighbor nodes, and discard the satisfying Status information of Byzantine nodes or abnormal nodes; Secondly, based on the CPL layer state of the cooperating neighbor node j The CPL layer state of node i itself and the leader node status Calculate neighbor error ; Then, based on the state estimation results of the CPL layer at node i, the CPL state estimation error is calculated. ; Finally, , Substituting the feedback control gain matrix F into the elastic consistency control law, we obtain the control input of node i at the current time t. ; Through the above implementation method, the control input of node i depends only on the trusted neighbor information, leader node state information and its own local state estimation error under the reconstructed cooperative topology, thereby avoiding the participation of abnormal state information of Byzantine nodes in the control input calculation.
[0041] A further technical solution involves updating the communication state of node i based on an event-triggered mechanism; for any follower node... The time of its next event trigger is defined as: ; in, , , and For design parameters, This represents the total number of follower nodes. This represents the k-th trigger time of node i. This indicates the (k+1)th trigger time of node i; This triggering mechanism introduces both local state estimation error and global tracking error into the CPL, where, For nodes The state estimation error of the CPL layer reflects the local estimation error; For nodes This reflects the global tracking error relative to the leader node's tracking error. The event triggering conditions... Corresponding to the local error term, This corresponds to the global error term. It allows the system to perform state updates and communication only when necessary, thereby reducing the communication burden.
[0042] Furthermore, by selecting event triggering parameters and control gain, the tracking error of cooperative followers towards the leader is made consistent and eventually bounded, and the interval between adjacent triggering times has a positive lower bound to avoid Zeno behavior.
[0043] definition ; in, This is the deviation term between the TL continuous state and the CPL held state; if a constant exists... Make Under the above event triggering conditions, the strict positive lower bound is satisfied between two consecutive triggering times: ; Through the above implementation method, there is a minimum time interval greater than zero between any two adjacent event trigger times, thereby eliminating Zeno's behavior.
[0044] Under the conditions of system stability, bounded leader state, leader immunity to Byzantine attacks, and continued connectivity of the reconstructed cooperative subgraph, the two-layer observer event-triggered resilient consistency control framework proposed in this embodiment can guarantee that the tracking errors of cooperative nodes and the state estimation errors of the TL layer are consistent and eventually bounded, and satisfies: ; in, , , The normal numbers are determined by system parameters and design parameters. This indicates that this embodiment constructs a resilient consistency control law based on reconstructing the cooperative topology, and calculates the control input of each follower node according to this control law. This enables the isolation of abnormal neighbor information and the maintenance of stable tracking performance of cooperative nodes on the leader's trajectory in the presence of Byzantine attacks.
[0045] This embodiment, based on the integrated design of Byzantine attack detection, node classification, anomaly isolation, resilient consistency control, and event-triggered communication mechanisms, can identify and isolate abnormal nodes online in open communication network environments where Byzantine attacks exist, and achieve trusted information exchange between normal cooperative nodes based on the reconstructed cooperative topology. By combining the detection and control processes, the impact of abnormal state information propagated by Byzantine nodes on the cooperative control process can be effectively suppressed, improving the security and robustness of multi-agent systems in malicious attack environments.
[0046] Meanwhile, the constructed elastic consistency control law ensures that the tracking errors of cooperative nodes are consistent and eventually bounded, enabling normal nodes to stably track the leader's trajectory even in the presence of Byzantine attacks. The designed event-triggered mechanism allows nodes to update their state and communicate only when triggering conditions are met, reducing unnecessary continuous communication and computational overhead, and effectively avoiding Zeno behavior by providing positive lower bounds for adjacent triggering times. Therefore, the control method in this embodiment can balance system security, control performance, and communication efficiency, and is suitable for multi-agent cooperative control scenarios in open communication network environments.
[0047] To verify the effectiveness of the method proposed in this embodiment, a linear multi-agent system consisting of one leader node and five follower nodes is considered. In the simulation, dots represent leader nodes and follower nodes, and triangles represent Byzantine nodes, as shown below. Figure 2 As shown.
[0048] In this embodiment, the system matrix is set as follows: ; The initial positions of each node are set as follows:
[0049] in, The leader's initial position is shown below, while the rest are the followers' initial positions.
[0050] The leader is a virtual leader, and its reference trajectory is set as follows: ; The total simulation time is The integration step size is .
[0051] In this embodiment, the control and triggering related parameters are set as follows: ; ; ; ; ; ; ; ; ; ; ; ; ; ; ; To verify the elastic control performance of this invention under Byzantine attacks, the following attack scenario was set up: Node 5 in... During this period, a Byzantine Type I attack was launched, employing link-layer deception by broadcasting a false state. The broadcast state was set as follows: ; Node 4 in At that time, a Byzantine Type II attack was launched, which carried out an execution-level attack by injecting divergent control input. The malicious input was set as follows: ; Figure 2 The dynamic network topology reconstruction process under Byzantine attacks is presented. It can be seen that, with the execution of detection errors, dynamic thresholds, and classification logic, cooperative nodes can gradually identify Byzantine nodes and update edge weights, thus enabling subsequent control to rely solely on trusted neighbor information.
[0052] Figure 3 The planar trajectory of a multi-agent system under Byzantine attack is presented. Figure 3 It can be seen that cooperative nodes 1 to 3, as well as node 5 which has rejoined the cooperative task, can continuously track the leader's trajectory, while node 4, which suffered a Byzantine Type II attack and was isolated, deviates significantly from the leader's trajectory in subsequent moments. This result indicates that the control framework proposed in this embodiment can maintain the trajectory tracking capability of cooperative nodes after detecting and isolating Byzantine nodes.
[0053] Figure 4 The event triggering frequency curves for cooperative nodes are presented. Compared to a baseline of 15,000 timed samplings, cooperative nodes 1, 2, and 3, and the re-integrated node 5, require only 10,557, 11,758, 11,574, and 12,617 triggers, respectively, representing reductions in communication frequency of 29.62%, 21.61%, 22.84%, and 15.89%. This result demonstrates that the event triggering mechanism proposed in this embodiment can effectively conserve communication resources even in the presence of Byzantine attacks.
[0054] Figure 5 The tracking error curves of the cooperative nodes are given, by Figure 5 It is evident that the tracking errors of all cooperating nodes remain consistent and eventually bounded.
[0055] Figure 6 This represents the tracking error curve of the isolated Byzantine node 4. (From...) Figure 6 It can be seen that node 4 is in A significant divergence then occurred. This result is consistent with the aforementioned stability conclusion, indicating that this embodiment can simultaneously achieve malicious node isolation and cooperative node tracking.
[0056] Figure 7 The error curves for TL layer state estimation are presented. Figure 7 It is evident that the TL layer observer consistently maintains high accuracy, with its error norm remaining within a certain range. The magnitude indicates that the independent virtual twin layer can continuously provide a high-precision, pollution-free security state benchmark.
[0057] Figure 8 The state estimation error curve for the CPL layer is presented. Figure 8 It is evident that the network physical layer state estimation error fluctuates to some extent with the trigger update, and these fluctuations mainly originate from the discrete update process under the event triggering mechanism; however, overall, the CPL state estimation error remains bounded and does not affect the overall effectiveness of the proposed detection, isolation, and resilient consistency control methods.
[0058] It should be noted that the system matrix, initial conditions, triggering parameters, and attack scenarios in this embodiment are only used to verify the effectiveness of the technical solution of the present invention. Those skilled in the art can adjust the parameters according to different application scenarios without departing from the basic idea of the present invention.
[0059] Example 2 Based on Example 1, this example provides a multi-agent anti-attack consensus control system based on a two-layer observer, including: The two-layer observer building module is configured to build independent virtual twin layers and network physical layers for each follower node; In the independent virtual twin layer, a continuous-time feedback observer is run based on the local output information of the follower nodes to generate a security state baseline that does not depend on the information of neighboring nodes. In the network physical layer, the state baseline is sampled, updated and maintained according to the event triggering mechanism to obtain the estimated state of the local node and the estimated state of its neighbors. The detection module is configured to obtain the neighbor node status and the local security status benchmark of the virtual twin layer based on the network physical layer reception status and the local security status benchmark of the virtual twin layer, construct the detection error, and combine it with dynamic thresholds to detect Byzantine attack behavior. The abnormal node isolation module is configured to classify neighboring nodes based on the detection results and update the communication edge weights between each follower node in order to isolate Byzantine nodes and reconstruct the cooperative topology. The control solution module is configured to construct a resilient consensus control law based on the reconstructed cooperative topology, neighbor error, and local state estimation error, and generate control inputs for follower nodes, enabling follower nodes to perform consensus tracking of the leader node.
[0060] It should be noted that each module in this embodiment corresponds one-to-one with each step in embodiment 1, and their specific implementation process is the same, so it will not be repeated here.
[0061] Example 3 Based on Embodiment 1, this embodiment provides an electronic device, including a memory and a processor, as well as computer instructions stored in the memory and running on the processor. When the computer instructions are executed by the processor, they complete the steps in the multi-agent anti-attack consistency control method based on a two-layer observer described in Embodiment 1.
[0062] Example 4 Based on Embodiment 1, this embodiment provides a computer-readable storage medium for storing computer instructions. When the computer instructions are executed by a processor, they complete the steps in the multi-agent anti-attack consistency control method based on a two-layer observer described in Embodiment 1.
[0063] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
[0064] While the specific embodiments of the present invention have been described above in conjunction with the accompanying drawings, this is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art without creative effort based on the technical solutions of the present invention are still within the scope of protection of the present invention.
Claims
1. A multi-agent anti-attack consensus control method based on a two-layer observer, characterized in that, Includes the following steps: An independent virtual twin layer and a network physical layer are constructed for each follower node; In the independent virtual twin layer, a continuous-time feedback observer is run based on the local output information of the follower nodes to generate a security state baseline that does not depend on the information of neighboring nodes. In the network physical layer, the state baseline is sampled, updated and maintained according to the event triggering mechanism to obtain the estimated state of the local node and the estimated state of its neighbors. Based on the network physical layer reception state and the local security state benchmark of the virtual twin layer, the detection error is constructed by obtaining the neighbor node state and the local node security state benchmark, and combined with dynamic threshold to detect Byzantine attack behavior. Based on the detection results, neighboring nodes are classified and the communication edge weights between each follower node are updated in order to isolate Byzantine nodes and reconstruct the cooperative topology. Based on the reconstructed cooperative topology, neighbor error, and local state estimation error, a resilient consistency control law is constructed to generate control inputs for follower nodes, enabling follower nodes to follow the leader node in a consistent manner.
2. The multi-agent anti-attack consensus control method based on a two-layer observer as described in claim 1, characterized in that, In the independent virtual twin layer, for each follower node Construct a continuous-time feedback observer that only uses the output of the current follower node. and local observation status The system is continuously updated, and the generated state estimate serves as the safety state baseline.
3. The multi-agent anti-attack consensus control method based on a two-layer observer as described in claim 1, characterized in that, In the network physical layer, for each follower node Construct an incremental sequence of event trigger times, and update the security state baseline in the independent virtual twin layer to the network physical layer at each trigger time; Between two consecutive trigger times, the network physical layer uses a zero-order hold method to save the security state baseline of the most recent trigger time.
4. The multi-agent anti-attack consensus control method based on a two-layer observer as described in claim 1, characterized in that, Based on the received state of the network physical layer and the local security state benchmark of the virtual twin layer, the received neighbor node state and the local node's security state benchmark are used to construct the detection error, and combined with dynamic thresholds to detect Byzantine attack behavior, including the following steps: For any cooperating follower node i, at the event trigger time Receive network physical layer state broadcast by neighbor node j ; The follower node i at the time of the most recent event trigger. The generated independent virtual twin layer security state baseline As a reference for testing; Calculate the deviation between the state of neighbor node j and the safety state baseline of the current follower node as the detection error; Construct a dynamic threshold that decays over time, the dynamic threshold being based on the triggering time of neighbor node j. An exponentially decaying dynamic threshold constructed from threshold parameters and constants; A detection criterion is constructed based on the difference between the detection error and the dynamic threshold. When the detection criterion is not greater than zero, determine the neighboring node. For this node If a node is a cooperative node, then it is a neighboring node. For this node This is a Byzantine node.
5. The multi-agent anti-attack consensus control method based on a two-layer observer as described in claim 1, characterized in that, Based on the detection results, neighboring nodes are classified, and the communication edge weights between each follower node are updated to isolate Byzantine nodes and reconstruct the cooperative topology, including the following steps: Define detection events Safety benchmark conformance events For any follower node i and its neighbor node j, define a detection event. For nodes For neighboring nodes The test results were normal; Define security baseline consistency events For: Neighboring nodes At the trigger time The broadcast state value and neighboring nodes The security state benchmark of the independent virtual twin layer is consistent; Based on event detection Safety benchmark conformance events Classify the neighbor node j by type, and then classify the neighbor node... They are classified as cooperative nodes, Byzantine type I nodes, and Byzantine type II nodes. Based on the neighbor node classification results, update the cooperative neighbor set and Byzantine neighbor set of the current node i; Based on the cooperative neighbor set and the Byzantine neighbor set, the communication edge weights between node i and its neighbor node j are... Dynamic updates are performed, and the current cooperative topology matrix is reconstructed based on the updated communication edge weights.
6. The multi-agent anti-attack consensus control method based on a two-layer observer as described in claim 1, characterized in that, Based on the reconstructed cooperative topology, neighbor errors, and local state estimation errors, a resilient consensus control law is constructed, including the following steps: Based on the reconstructed cooperative topology matrix, determine the effective neighbor information of node i; For any follower node i, based on the reconstructed communication edge weights The network physical layer states of neighbor node j, the network physical layer states of node i, and the leader node state are used to define the observer-based neighbor error of node i. ; For any follower node i, obtain the state estimation error of node i's network physical layer. ; Based on the state matrix A, input matrix B, and reconstructed cooperative topology matrix H(t) in the mathematical model of agent control, the algebraic Riccati equation is constructed and solved to obtain the symmetric positive definite solution P, and then the feedback control gain matrix F is calculated. For any follower node i, based on the neighbor error Error in state estimation at the network physical layer And the feedback control gain matrix F, to construct the elastic consistency control law for node i.
7. The multi-agent anti-attack consensus control method based on a two-layer observer as described in claim 1, characterized in that, Under the event triggering condition, the difference between two adjacent triggering times satisfies the positive lower bound condition.
8. A multi-agent anti-attack consensus control system based on a two-layer observer, characterized in that, include: The two-layer observer building module is configured to build independent virtual twin layers and network physical layers for each follower node; In the independent virtual twin layer, a continuous-time feedback observer is run based on the local output information of the follower nodes to generate a security state baseline that does not depend on the information of neighboring nodes. In the network physical layer, the state baseline is sampled, updated and maintained according to the event triggering mechanism to obtain the estimated state of the local node and the estimated state of its neighbors. The detection module is configured to obtain the neighbor node status and the local security status benchmark of the virtual twin layer based on the network physical layer reception status and the local security status benchmark of the virtual twin layer, construct the detection error, and combine it with dynamic thresholds to detect Byzantine attack behavior. The abnormal node isolation module is configured to classify neighboring nodes based on the detection results and update the communication edge weights between each follower node in order to isolate Byzantine nodes and reconstruct the cooperative topology. The control solution module is configured to construct a resilient consensus control law based on the reconstructed cooperative topology, neighbor error, and local state estimation error, and generate control inputs for follower nodes, enabling follower nodes to perform consensus tracking of the leader node.
9. An electronic device, characterized in that, It includes a memory and a processor, as well as computer instructions stored in the memory and running on the processor, which, when executed by the processor, complete the steps in the multi-agent anti-attack consensus control method based on a two-layer observer as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, Used to store computer instructions, which, when executed by a processor, complete the steps in the multi-agent anti-attack consistency control method based on a two-layer observer as described in any one of claims 1-7.