A method for simulating attacks and evaluating cooperative spectrum sensing systems, and a storage medium.

CN122579131APending Publication Date: 2026-08-14HENAN UNIV OF SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-09
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

在引入RIS与MIMO技术的动态环境网络中,瞬时信道状态信息(Instantaneous Channel State Information,CSI)的精确估计或预测对导频开销、频谱带宽及系统能耗的需求极高,导致攻击者在获取上述攻击依据时面临计算、通信与能量消耗等资源消耗极大,难以在有限的资源约束下实现攻击增益与攻击代价的平衡匹配

Benefits of technology

通过模拟攻击者在无法获得全局瞬时CSI条件下的最坏情况攻击行为,能够有效评估系统在不同场景下的脆弱性边界。同时,针对RIS与审计比特双路径上报以及多跳DF传输结构,能够在理想感知信道、高信噪比与低信噪比等典型场景下量化分析系统对拜占庭攻击的耐受能力,为防御策略设计提供量化依据。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122579131A_ABST
    Figure CN122579131A_ABST
Patent Text Reader

Abstract

A method and storage medium for simulating attacks on a cooperative spectrum sensing system, comprising: under the constraint that the attacker cannot obtain global instantaneous channel state information from the primary user through a reconfigurable smart surface and a multi-hop decoding forwarding relay node to the fusion center; constructing an expected expression for the maximum likelihood fusion statistics reported by both paths at the fusion center; and decomposing the contributions of each link, honest group, and dishonest group of the two paths in the expected expression; aiming to force the expected value of the maximum likelihood fusion statistics to approach zero; and solving based on the contributions; this invention, under the condition that the attacker cannot obtain global instantaneous information in real time, designs the data flip probability of the Byzantine node to make the decision statistics at that point reach the most unfavorable state, thereby achieving a controllable assessment of the system's security vulnerability; and features strong adaptability, a clear assessment process, and low computational complexity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of wireless communication and network security technology, specifically to a method for simulating attacks and evaluating cooperative spectrum sensing systems, and a storage medium. Background Technology

[0002] With the large-scale deployment of 5G and the forward-looking evolution of 6G, low-power IoT devices and heterogeneous mobile terminals are growing rapidly, making the demand for flexible scheduling and efficient utilization of spectrum resources increasingly prominent. Cognitive radio networks can alleviate the imbalance between spectrum supply and demand by allowing secondary users (SUs) to access idle frequency bands without interfering with primary users (PUs). Among them, cooperative spectrum sensing aggregates the local decisions of distributed SUs through a fusion center (FC), and uses spatial diversity to improve the reliability of sensing in complex environments such as low signal-to-noise ratio and obstruction.

[0003] To improve the accuracy of SU sensing, this system introduces RIS technology based on the dual-path reporting architecture of audit bits. In traditional research, the audit bit system pairs SUs, requiring each SU to simultaneously upload decision bits via direct links and paired relay links, using data redundancy consistency verification to provide key decision references for FC. Building on this, this patent reconstructs the physical layer resource structure by deploying RIS, which has inherent advantages such as dynamic beamforming, intelligent environmental sensing, spatial diversity and multiplexing, beamforming, and space-time switching, along with enabling technologies such as Multiple-Input Multiple-Output (MIMO). Among them, RIS achieves active reconstruction of the electromagnetic propagation environment through the coordinated control of the phase of massive reflective units, breaking the passive characteristics of traditional wireless channels and ensuring that the SU's sensing signal can still achieve high-gain transmission and wide-area reliable coverage in extreme environments with severe obstruction or low signal-to-noise ratio; while MIMO technology, with its spatial diversity and multiplexing advantages, can significantly improve system throughput and effectively combat multipath fading in complex environments. The deep integration of these technologies has not only significantly optimized perception metrics, but also constructed a more complex and multi-dimensional resource boundary for collaborative perception networks by reconstructing the physical layer resource landscape.

[0004] However, while enabling technologies such as RIS and MIMO significantly improve SU perception performance, they also pose serious challenges to network security attack and defense models. While opening up new paths for human understanding of the physical world, RIS and MIMO are also gradually becoming powerful tools for network attacks, exhibiting a growing "double-edged sword" effect. Due to the openness of wireless channels, data integrity is difficult to guarantee during transmission, and Byzantine attacks have become one of the most serious threats to data integrity. With the increasing scale of SUs, even if only a small percentage of SU nodes are hijacked by attackers, the network resources that attackers can control will increase exponentially, empowered by the inherent advantages of dynamic beamforming, spatial diversity, and space-time swapping provided by RIS and MIMO technologies. This transforms hijacked SU nodes into "supernodes" with extremely high degrees of tampering freedom. Their malicious empowerment can exploit physical layer characteristics to bypass the logical verification rules of audit bits, causing immeasurable negative impacts on the reliability of FC detection fusion results. In conclusion, faced with an increasingly complex network communication environment, attackers will inevitably seek change first, launching new and more threatening data tampering attacks by exploiting logical shortcomings and system vulnerabilities in new technologies such as RIS and MIMO, thereby undermining the integrity of perceived data. This makes the "double-edged sword" effect of technologies such as RIS and MIMO increasingly prominent.

[0005] Most existing collaborative spectrum awareness defense systems are passive defenses. When facing attack systems with novel and evolving characteristics, these defense strategies are prone to "structural misalignment" in terms of time, space, and technology, resulting in insufficient targeting, mediocre effectiveness, or even failure. This "prescription-based" passive protection cannot deeply understand the attack mechanisms, making it difficult to embed inherent security attributes during the design phase, and may also lead to a severe decline in security effectiveness due to the misallocation of defense resources.

[0006] Existing research on Byzantine data attacks targeting cooperative spectrum sensing largely focuses on traditional, simple communication scenarios. The effectiveness of these attacks often heavily relies on the attacker's accurate estimation or prediction of prior system information (such as sensor detection probabilities, false alarm probabilities, and fusion rules), using the results as the attack basis. However, in large-scale distributed heterogeneous network architectures, the introduction of RIS and MIMO technologies significantly complicates communication scenarios. Traditional research results in the aforementioned simple communication scenarios will exhibit clear limitations. In dynamic network environments incorporating RIS and MIMO technologies, the accurate estimation or prediction of instantaneous channel state information (CSI) demands extremely high pilot overhead, spectrum bandwidth, and system energy consumption. This results in attackers facing enormous resource consumption in computation, communication, and energy when obtaining the attack basis, making it difficult to achieve a balance between attack gain and cost within limited resource constraints. In summary, technologies such as RIS and MIMO have made the communication environment increasingly complex. While attackers have access to richer physical layer resources, relying on traditional attack methods that depend on high-precision prior information will lead to a dilemma where the "attack cost" and "attack gain" become increasingly contradictory, making it difficult to achieve performance matching under resource constraints. Therefore, it is necessary to design a method for cooperative spectrum sensing systems based on RIS-enhanced audit bits that can perform fast, accurate, and robust worst-case attack simulations under constraints where attackers lack sufficient attack evidence, and to quantitatively assess the system's vulnerability based on this method. Summary of the Invention

[0007] The purpose of this invention is to propose a simulation attack and evaluation method and storage medium for a cooperative spectrum sensing system. Under the condition that the simulated attacker cannot obtain the global instantaneous CSI in real time, the decision statistics at the FC are made to reach the most unfavorable state by designing the data flip probability of the Byzantine node, thereby achieving a controllable evaluation of the system's security vulnerability. It has the characteristics of strong adaptability, clear evaluation process and low computational complexity.

[0008] The technical solution adopted in this invention is: a simulated attack method for a cooperative spectrum sensing system. The cooperative spectrum sensing system includes a primary user (PU), a reconfigurable intelligent surface (RIS), multiple secondary users (SU), a multi-hop decoding and forwarding relay node, and a fusion center (FC). The signal of the primary user (PU) is transmitted to each secondary user (SU) via a direct link or via a reflection link through the reconfigurable intelligent surface (RIS). Each secondary user (SU) obtains local statistics based on energy detection. The local statistics include the user proportion of Byzantine nodes and the sum of bit-flip probabilities, but cannot identify specific malicious individuals at the node level. The signal of the primary user (PU) received by each secondary user (SU) is subjected to local hard decision according to a preset threshold, generating local binary decision bits. Based on an audit bit reporting mechanism, the local binary decision bits are reported to the fusion center (FC) through dual paths. The fusion center (FC) divides the secondary user (SU) into honest and dishonest groups based on the consistency check of the local binary decision bits received through dual paths, and calculates the corresponding Byzantine posterior probabilities. The simulated attack method is executed by the attacker and includes the following steps: Under the constraint that the attacker cannot obtain the global instantaneous channel state information (CSI) from the primary user PU through the reconfigurable smart surface RIS and the multi-hop decoding and forwarding relay node to the fusion center FC, a prediction expression for the maximum likelihood fusion statistics reported by the dual paths is constructed on the fusion center FC side, and the contributions of each link, honest group, and dishonest group of the dual paths in the prediction expression are decomposed. With the goal of forcing the expected value of the maximum likelihood fusion statistic to approach zero, the solution is performed based on the item-by-item contribution to determine the optimal fusion rule between the first flip probability α of the Byzantine node executing a flip to 0 when the local binary decision is 1 and the second flip probability β of executing a flip to 1 when the local binary decision is 0. According to the optimal fusion rule, an optimal flip probability parameter is configured for at least one Byzantine node controlled by the attacker, so that each Byzantine node performs probabilistic tampering on its local binary decision bit according to the configured optimal flip probability parameter before reporting in accordance with the audit bit reporting mechanism.

[0009] As a preferred option, if the secondary user's SU sensing channel is an ideal channel and the multi-hop decoding and forwarding relay network is in a scenario with high signal-to-noise ratio (SNR), the optimal fusion rule is that the first flip probability α and the second flip probability β are equal. If the secondary user's SU sensing channel is an ideal channel and the multi-hop decoding and forwarding relay network is under low signal-to-noise ratio (SNR) conditions, and each relay transmission process is equivalent to a binary symmetric channel, the optimal fusion rule is that the first flip probability α and the second flip probability β are equal. In the general scenario where the secondary user's SU sensing channel is a non-ideal channel, the optimal fusion rule is that the sum of the first flip probability α and the second flip probability β equals 1.

[0010] As a preferred embodiment, in the simulated attack method: the attacker pre-controls a certain proportion of secondary users (SU) as Byzantine nodes, and the Byzantine nodes maintain consistency with the secondary users (SU) of the honest group in the apparent behavior of local hard decision and dual-path reporting structure, so as to integrate into the cooperative spectrum sensing system.

[0011] As a preferred approach, the dual-path reporting involves pairing the secondary users (SU) into two cooperative units; each secondary user (SU) simultaneously uploads its local decision bits to the fusion center (FC) via a multi-hop decoding and forwarding relay node through both a direct reporting link and an indirect link relayed by its paired user.

[0012] As a preferred embodiment, the channel between the two multi-hop decoding and forwarding relay nodes is a binary channel.

[0013] An evaluation method for a cooperative spectrum sensing system includes the following steps: Simulated attack: The simulated attack method described above is used to probabilistically tamper with the local binary decision bits of the cooperative spectrum sensing system; Vulnerability assessment: During simulated attacks, the decision results of the fusion center FC are collected, and the system bit error rate or detection probability is calculated to quantitatively analyze the security vulnerability of the cooperative spectrum sensing system under different attack configurations or different system parameters.

[0014] A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a simulated attack method and / or an evaluation method.

[0015] Compared with the prior art, the beneficial effects of the present invention are: By simulating worst-case attack behavior under conditions where global instantaneous CSI cannot be obtained, the vulnerability boundaries of the system can be effectively assessed in different scenarios. Furthermore, for dual-path reporting of RIS and audit bits, and multi-hop DF transmission structures, the system's tolerance to Byzantine attacks can be quantitatively analyzed in typical scenarios such as ideal sensing channels, high SNR, and low SNR, providing a quantitative basis for defense strategy design. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 Mobile CRN under RIS-enhanced Byzantine attacks aided by audit bits; Figure 2 A system transmission model that takes into account Byzantine data attacks; Figure 3 The absolute value of LLR under the optimal fusion rule; Figure 4 To determine the bit error rate performance of the optimal fusion rule under different numbers of SUs antennas; Figure 5 To determine the bit error rate performance of the optimal fusion rule under different numbers of RIS reflection units and SUs; Figure 6 Attack strength The attack performance is below; Figure 7 Attack strength The attack performance is below; Figure 8 Attack strength The attack performance is below; Figure 9 Attack strength The attack performance is below; Figure 10 Attack strength The attack performance is below; Figure 11 Attack strength The attack performance is below; Figure 12 Byzantine proportion The attack performance is below; Figure 13 Byzantine proportion The attack performance is below; Figure 14 Byzantine proportion The attack performance is below; Figure 15 Byzantine proportion The attack performance is below. Detailed Implementation

[0018] The present invention will now be described in detail through exemplary embodiments. However, it should be understood that, without further description, elements, structures, and features in one embodiment may be advantageously incorporated into other embodiments.

[0019] It should be noted that, unless otherwise defined, the technical or scientific terms used herein should have the ordinary meaning understood by one of ordinary skill in the art to which this invention pertains. The terms "a," "an," or "the," etc., used in the specification and claims of this patent application do not express a limitation on quantity, but rather indicate the presence of at least one; the terms "first," "second," and "third," as used herein, should not be considered as a limitation on the order of components, but are merely for distinguishing different components; the terms "comprising," "including," etc., indicate that the elements or objects preceding "comprising" or "including" encompass the elements or objects listed following "comprising" or "including" and their equivalents, but do not exclude other elements or objects having the same function.

[0020] To more clearly describe the simulated attack and evaluation methods, and storage media of this cooperative spectrum sensing system, in conjunction with the attached... Figure 1-15 This embodiment is described as follows: like Figure 1-2 As shown, a simulated attack method for a cooperative spectrum sensing system is presented. The cooperative spectrum sensing system includes a primary user (PU), a reconfigurable smart surface (RIS), multiple secondary users (SU), a multi-hop decoding and forwarding relay node, and a fusion center (FC). The simulated attack method includes the following steps: Step S1: The signal from the primary user PU is transmitted to each secondary user SU via a direct link or via a reflection link through a reconfigurable smart surface RIS. Each secondary user SU obtains local statistics based on energy detection. The local statistics include the user proportion of Byzantine nodes and the sum of bit flip probabilities, but cannot identify specific malicious individuals at the node level. The signals from the primary user PU received by each secondary user SU are subjected to local hard decision according to a preset threshold, generating local binary decision bits. Step S2: Based on the audit bit reporting mechanism, the local binary decision bits are reported to the fusion center FC through dual paths. The fusion center FC divides the secondary user SU into honest group and dishonest group according to the consistency verification of the local binary decision bits received through dual paths, and calculates the corresponding Byzantine posterior probability.

[0021] The simulated attack method is executed by the attacker: Step S3: The attacker pre-controls a certain proportion of secondary users SU as Byzantine nodes. The Byzantine nodes maintain consistency with the secondary users SU of the honest group in terms of the apparent behavior of local hard decision and dual-path reporting structure, so as to integrate into the cooperative spectrum awareness system. Under the constraint that the attacker cannot obtain the global instantaneous channel state information (CSI) from the primary user PU through the reconfigurable smart surface RIS and the multi-hop decoding and forwarding relay node to the fusion center FC, a prediction expression for the maximum likelihood fusion statistics reported by the dual paths is constructed on the fusion center FC side, and the contributions of each link, honest group, and dishonest group of the dual paths in the prediction expression are decomposed. Step S4: With the attack target of forcing the expected value of the maximum likelihood fusion statistic to approach zero, solve the problem based on each contribution and determine the optimal fusion rule between the first flip probability α of the Byzantine node executing the flip to 0 when the local binary decision is 1 and the second flip probability β of executing the flip to 1 when the local binary decision is 0. According to the optimal fusion rule, an optimal flip probability parameter is configured for at least one Byzantine node controlled by the attacker, so that each Byzantine node performs probabilistic tampering on its local binary decision bit according to the configured optimal flip probability parameter before reporting in accordance with the audit bit reporting mechanism.

[0022] Furthermore, the vulnerability boundaries of cooperative spectrum sensing systems differ under different operating conditions. The following describes the worst-case attack conditions for typical scenarios such as ideal sensing channels, high signal-to-noise ratio (SNR), and low SNR: If the secondary user's SU sensing channel is an ideal channel and the multi-hop decoding and forwarding relay network is in a scenario with high signal-to-noise ratio (SNR), the optimal fusion rule is that the first flip probability α and the second flip probability β are equal. If the secondary user's SU sensing channel is an ideal channel and the multi-hop decoding and forwarding relay network is under low signal-to-noise ratio (SNR) conditions, and each relay transmission process is equivalent to a binary symmetric channel, the optimal fusion rule is that the first flip probability α and the second flip probability β are equal. In the general scenario where the secondary user's SU sensing channel is a non-ideal channel, the optimal fusion rule is that the sum of the first flip probability α and the second flip probability β equals 1.

[0023] In the above technical solution, dual-path reporting specifically refers to: pairing secondary users (SU) in pairs to form cooperative units; each secondary user (SU) simultaneously uploads its local decision bits to the fusion center (FC) via a multi-hop decoding and forwarding relay node through a direct reporting link and an indirect link relayed by its paired user. The channel between the two multi-hop decoding and forwarding relay nodes is a binary channel.

[0024] The following is a detailed explanation of the simulated attack methods for cooperative spectrum sensing systems: Step S1 specifically includes: Step S11: Binary data generated by the PU or After being transmitted via wireless channel or forwarded by a reconfigurable smart surface, it is received by SUs. The path SUs receives binary signals sent by the PU via the direct path and the reconfigurable smart surface auxiliary path. : (1) in, Indicates from RIS to the 1st Channel matrix of SU; Indicates from PU to the number Channel matrix of SU; and These refer to the transmit power of the PU and the information signal, respectively. The phase response of the RIS is represented by a diagonal matrix. Define the phase shift of each unit. It can be independently controlled within the range. Indicates from RIS to the 1st Channel matrix of SU; This represents the adjustment phase matrix of the RIS system; This represents the channel matrix from PU to RIS; additive white Gaussian noise term. It follows a complex Gaussian distribution, i.e. ,in The variance representing Gaussian white noise, Represents a dimension The identity matrix; Step S12: To optimize the received signal quality, the system employs beamforming technology and uses a beamformer. The filter combines the signals and satisfies the power constraint. Filtered scalar signal for: (2) Step S13: In the spectrum sensing phase, each SU detects the activity state of the PU by continuously acquiring signal samples. Therefore, in the... At each sampling time, the received signal It can be restated as: (3) in, and Indicates the state of the source. and These represent binary signals 0 and 1, respectively.

[0025] Step S14: Energy-based sensing schemes are widely used in this system. Definition Sampling frequency, To determine the duration of the sensing, the total number of sampling points is: The detection statistics are constructed as follows: (4) Step S15: The corresponding binary hypothesis test decision criterion is as follows: (5) in, Indicates the first The detection threshold for each SU. For a RIS-assisted spectrum sensing system, the energy detection value... It can be calculated in the following ways (6) Step S16: According to the central limit theorem, when the number of sampling points T is sufficiently large, the detection statistic... It can be approximately distributed according to a Gaussian distribution, that is: (7) in, It is the instantaneous received signal-to-noise ratio. This represents the number of antennas at the receiving end. Based on the Gaussian distribution assumption, the local false alarm probability... and detection probability This can be deduced as: (8) (9) In the formula, Let be the right-tail probability function of the standard Gaussian distribution.

[0026] Step S17: For the first Each SU, upon receiving the signal Subsequently, the local judgment result The probabilities are as follows: (10) as well as probability (11) Thus, the detection probability and false alarm probability of SUs were obtained.

[0027] Furthermore, step S2 specifically includes: Step S21: The present invention in Figure 2 The paper presents a model for dual-path transmission using an audit bit mechanism, denoted as a group of adjacent users. and , and The data after multiple relay hops is and After merging the two sets of data, a match / mismatch test will be performed. If... ,but The probability of being considered a Byzantine node is And divided into Groups, similar, if ,but The probability of being considered a Byzantine node is and divided into Group. Similarly, for FC received and After performing a match / non-match test, put Sub-in group or Group.

[0028] Two in a group and It can correspond to one of four possible configurations, that is, there are The probability that both users are honest is... The probability that both are hijacked by the Byzantine node is... The probability is that one is honest, and the other is hijacked by a Byzantine node. This represents the percentage of Byzantine users in the network. These four configurations are respectively used for... , , as well as express: (12) Where HH indicates that it is assumed that the current user and the adjacent secondary users are honest nodes. This represents the probability that the fusion center receives inconsistent data between the direct and indirect links when the decision of the current user is 0, assuming that both secondary users are honest users. This represents the probability that the fusion center receives inconsistent data from the direct and indirect links when the primary user's decision is 1, assuming both secondary users are honest. This represents the probability that, assuming both secondary users are honest users, the fusion center receives 1 direct link data and 0 indirect link data when the decision of the current secondary user is 0. This represents the probability that, assuming both secondary users are honest users, the fusion center receives 0 direct link data and 1 indirect link data when the decision of the current secondary user is 0. This represents the probability that, assuming both secondary users are honest users, the fusion center receives 1 direct link data and 0 indirect link data when the current secondary user's decision is 1. This represents the probability that, assuming both secondary users are honest users, the fusion center receives 0 direct link data and 1 indirect link data when the primary user's decision is 1. This represents the probability that the fusion center receives a direct link data of 1 when the current user's decision is 0, assuming that both secondary users are honest users. This represents the probability that the fusion center receives 0 indirect link data when the primary user's decision is 0, assuming both secondary users are honest users. This represents the probability that the fusion center receives 0 direct link data when the current user's decision is 0, assuming that both secondary users are honest users. This represents the probability that the fusion center receives indirect link data as 1 when the current user's decision is 0, assuming that both secondary users are honest users. This represents the probability that the fusion center receives a direct link data value of 1 when the current user's decision is 1, assuming that both secondary users are honest users. This represents the probability that the fusion center receives 0 indirect link data when the primary user's decision is 1, assuming both secondary users are honest users. This represents the probability that the fusion center receives 0 direct link data when the primary user's decision is 1, assuming both secondary users are honest users. This represents the probability that the fusion center receives indirect link data of 1 when the current user's decision is 1, assuming that both secondary users are honest users.

[0029] Similarly, we can conclude that: (13) Here, HB represents the assumption that the current user is an honest node and the adjacent secondary user is a Byzantine node.

[0030] (14) Here, BH represents the assumption that the current user is a Byzantine node and the adjacent secondary user is an honest node.

[0031] (15) Here, BB indicates that the current user and the adjacent secondary user are both Byzantine nodes.

[0032] in, This represents the probability of flipping data 0 during the transmission of adjacent SUs; This represents the probability of flipping data 1 during the transmission of adjacent SUs; Indicates the first The first path The probability of flipping a BC pair of data 0; Indicates the first The first path The probability of flipping BC pairs for data 1; This represents the probability that the i-th Byzantine user 1 is flipped to 0; The probability that the i-th Byzantine user's 0 is flipped to 1; Indicates the first The probability of a 0 being flipped to a 1 in a path; Indicates the first The probability that a 1 in a path will be flipped to a 0; Will Put in The probability of a group: (16) Put in The probability of the group is (17) consider That is, in In this case, The probability of being a Byzantine node (18) Next consideration That is, in In this case, The probability that it is a Byzantine node: (19) Thus, this invention yields the percentage of Byzantine users in the honest and dishonest groups.

[0033] for The size relationship only applies when or hour This is valid, as proven below.

[0034] First, let's analyze... and Relationship: (20) in: (twenty one) (twenty two) but: (twenty three) Because the denominator is greater than ,when When, the numerator must be equal to That is, it needs to meet or ; Similarly, analysis and Relationship (twenty four) The denominator of equation (24) is greater than 0, and the numerator is the opposite of the numerator of equation (20). Based on the above analysis, when At the same time, it is also necessary to meet the following requirements. or Q.E.D.

[0035] Furthermore, suppose FC knows that a Byzantine data attack exists in the system and has complete knowledge of its global statistical parameters, including the percentage of Byzantine users and the bit-flipping probability, but cannot identify specific malicious individuals at the node level. This information state means that when assessing system vulnerability, the worst-case strategy that the attacker might employ must be considered. In a Byzantine data attack, for Group SUs, have for Group SUs, have in, This indicates the probability that the fusion center receives a value of 0 when user i's local decision is 1 in group S2. Let represent the probability that the fusion center receives a 1 when the local decision of user i is 0 in group S2. Based on the Maximum Likelihood (ML) criterion, we can obtain the decision fusion statistics for FC as shown below: (25) in, It is the binary vector received by the FC, containing The SUs of each branch road pass through Information after multiple jumps. It can be considered as the first The optimal decision fusion statistic for a given local observation. We give the first... The optimal decision statistics for the path are the focus of this invention. exist When grouping, Give the fusion statistic in the form of logarithmic natural ratio Contribution value It can be represented as: (26) in, This represents the probability that the fusion center receives a value of 0 when user i's local decision is 1 in group S1. This represents the probability that the fusion center receives a 1 when the local decision of user i is 0 in group S1. This indicates the probability that the fusion center receives a value of 0 when user i's local decision is 1 in group S2. This represents the probability that the fusion center receives a 1 when the local decision of user i is 0 in group S2. Similarly, when exist When grouping, there are (27) when and At that time, there were: (28) in, and These represent the assumptions under normal circumstances. and ,for FC observed The general probability is given by equations (30) and (31).

[0036] (29) in, This represents the probability that the fusion center receives a value of 0 when user i's local decision is 1 in group S1. This represents the probability that the fusion center receives a 1 when the local decision of user i is 0 in group S1. (30) when and At that time, there were: (31) in, and These represent the assumptions under normal circumstances. and ,for FC observed The general probability is given by equations (33) and (34).

[0037] (32) (33) when At that time, the corresponding item for As given by equation (35), and for Then it is given by equation (36), where , , ,as well as .

[0038] (34) (35) Substituting into equation (25), we can obtain (36) For each SU, there is (37) According to equation (37), equation (36) can be written as: (38) That is: (39) Further written as (40) in Representation group The number of elements in Representation group The number of elements in the array.

[0039] The core objective of attack assessment is to analyze the system's performance under worst-case conditions, that is, to examine how the attacker minimizes... This is because the absolute value of this statistic directly reflects the decision reliability of the FC: the larger the absolute value, the more clearly the FC can distinguish decisions. and When the absolute value approaches 0, the FC (Failure Center) cannot extract effective decision-making information from the received data, ultimately falling into a blind state. To determine which attack configuration can most thoroughly achieve this goal, Worst-case attack condition analysis needs to be conducted: To make FC blind, i.e. The following conditions must be met: (41) Right now (42) because , Therefore, the solution is: (43) (44) have to Only when or The equation only holds true when considering Byzantine data attacks, so it only holds true when... hour, This condition defines the attack parameter values ​​for the system in its most vulnerable state.

[0040] Similarly, in the scenario of an ideal local sensing channel, the signal detection capability of the SUs reaches its optimal state. At this point, interference and noise are effectively suppressed, and the sensing process is almost unaffected by environmental distortion. In this case, and Therefore, equations (28), (31), (34), and (35) can be rewritten as follows: (45) (46) (47) (48) in, and They represent the conditions under ideal local sensing channels, assuming... or At the time of its establishment, for FC observed The probability of. and This indicates that under ideal local sensing channel conditions, when assuming or At the time of its establishment, for FC observed The probability of . Its explicit expression is shown in equations (49), (50), (51) and (52).

[0041] (49) (50) (51) (52) Therefore, equation (40) can be written as equation (53).

[0042] (53) This indicates the number of secondary users in group S1; This indicates the number of secondary users in group S2.

[0043] In the suboptimal fusion criterion under ideal conditions, in order for FC to be in a blind state, the numerator of each term in equation (53) must be equal to its denominator, from which we can obtain (54) Right now: (55) because Therefore, the solution is: (56) (57) have to Only when or The equation only holds true when considering Byzantine data attacks, so it only holds true when... hour, This condition provides a quantitative basis for the vulnerability boundary of a system under an ideal sensing channel.

[0044] Similarly, in scenarios with high signal-to-noise ratio (SNR) in multi-hop relay networks, the communication link between SUs and FC is almost unaffected by interference, noise, and fading distortion. This means that the transmission of local decision and audit bits can be considered error-free. At this point, there are... and Therefore, equations (28), (31), (34), and (35) can be rewritten as follows: (58) (59) (60) (61) in, and These represent the conditions under which the SNR is high in a multi-hop relay network, assuming... or Established and At that time, FC observed The probability of. and This indicates that when the SNR is high in a multi-hop relay network, assuming... or Established and At that time, FC observed The probability of . Its explicit expression is shown in equations (62), (63), (64) and (65).

[0045] (62) (63) (64) (65) Therefore, equation (40) can be written as equation (66).

[0046] (66) When the SNR of a multi-hop relay network is high, for this suboptimal fusion criterion, the numerator of each term in equation (66) must be equal to its denominator, from which we can obtain: (67) Right now: (68) because Therefore, the solution is: (69) (70) have to Only when or The equation only holds true when considering Byzantine data attacks, so it only holds true when... hour, This condition is used to evaluate the system's tolerance limit to Byzantine attacks in high signal-to-noise ratio scenarios.

[0047] Similarly, this invention considers fusion statistics under low SNR, in which case, we have , Therefore, the transmission process of each relay can be reasonably modeled as a binary symmetric channel (BSC). In this case, we can obtain... .

[0048] (71) (72) in, Indicates a fixed subscript Under the premise that, when from Change to At that time, in this indivual Find the smallest value among the possible values.

[0049] Directly calculating the exponent in (72) would introduce significant complexity and numerical instability. Therefore, a first-order Taylor series expansion can be used to approximate it. This method effectively avoids unnecessary fitting errors while maintaining sufficient numerical accuracy. Based on this approximation strategy, equation (72) can be further simplified to the following: (73) when Using Taylor's formula Equation (27) can be simplified to: (74) Similarly, for and At that time, there were: (75) for and At that time, there were: (76) for and At that time, there were: (77) To make FC blind, let equations (74), (75), (76), and (77) all be zero, and we can obtain (78) have to Only when or The equation only holds true when considering Byzantine data attacks, so it only holds true when... hour, This condition provides a basis for assessing system vulnerability in low signal-to-noise ratio scenarios.

[0050] like Figure 1 As shown, the overall workflow of the system is as follows: The PU transmits a sensing signal, which reaches each SU via a direct link and a RIS reflection link. Each SU completes local detection based on the received signal and generates a binary decision bit. Subsequently, the SUs are paired up and an audit bit mechanism is introduced. The decision information is transmitted to the FC through a multi-hop binary channel on two paths: direct reporting and indirect reporting via forwarding by paired SUs. After receiving the reports from each path, the FC first uses the audit bit to perform consistency verification to assess the reliability of the reporting and identify potential Byzantine data high attack behaviors. Then, it performs weighted fusion of the reported data based on different link error conditions.

[0051] This invention also discloses an evaluation method for a cooperative spectrum sensing system, comprising the following steps: Simulated attack: The simulated attack method of the cooperative spectrum sensing system described above is used to perform probabilistic tampering on the local binary decision bits of the cooperative spectrum sensing system; Vulnerability assessment: During simulated attacks, the decision results of the fusion center FC are collected, and the system bit error rate or detection probability is calculated to quantitatively analyze the security vulnerability of the collaborative spectrum sensing system under different attack configurations, different system parameters, or channels.

[0052] Figure 4 This indicates the variation of system performance with the number of receiver antennas M under a fixed attack strength. In attack-free scenarios, as M increases, the system achieves higher spatial diversity gain, resulting in a significant reduction in the bit error rate (BER). However, when employing a worst-case attack strategy that brings the system to its most vulnerable state, even increasing the number of antennas M rapidly approaches 0.5 BER at the fusion center. This demonstrates that simply increasing the antenna size is insufficient to effectively offset the decrease in decision reliability caused by the attack, thus exposing the vulnerability in this dimension. Furthermore, Figure 5 The impact of the number of secondary users I and the number of RIS reflection units N on the bit error rate is presented. Under attack-free conditions, increasing I can improve the reliability of global decision by utilizing the information redundancy brought by cooperative sensing, while increasing N can improve the reception quality by enhancing the reflection link gain and diversity effect and suppressing the influence of noise. Therefore, both can effectively reduce the bit error rate. Conversely, under optimal attack conditions, Figure 6 The bit error rate curve shown remains close to the level of random decision and is insensitive to changes in I and N, indicating that the system is significantly vulnerable to Byzantine attacks in these resource expansion dimensions.

[0053] exist Figures 7-11 Under the audit bit enhancement conditions shown, the red surface represents the condition where audit bits are not used, and the blue surface represents the condition where audit bits are used. In the simulation diagram, "Using Audit Bit" indicates that audit bits are used, and "Not Using Audit Bit" indicates that audit bits are not used. The system bit error rate (BER) exhibits a clear unimodal characteristic as the attack intensity changes, indicating the proportion of Byzantine nodes for any given attack strength. Each system possesses a set of worst-case attack parameters that maximize the decision error rate of the fusion center, meaning the system exhibits corresponding vulnerability peak ranges. Specifically, when... At that time, the optimal attack satisfies The condition can be achieved through either an all-1 attack (Always-Yes, AY) or an all-0 attack (Always-No, AN); under this condition, the misleading effect of a random attack (Random, RD) is the second best, while the misleading effect of an all-flip attack (Always-False, AF) is the weakest. At that time, the optimal attack point is compared to The situation shifts towards areas of higher attack intensity, manifesting as... This means that the attack strategy needs to employ a two-way flipping mechanism of "0→1" and "1→0" to achieve the strongest misleading effect; therefore, AY / AN attacks are no longer dominant, and attackers tend to use RF or AF type flipping strategies. Under this ratio condition, AY and AN are usually at a suboptimal level, while AF remains the attack method with the weakest misleading effect. The above analysis reveals the evolutionary pattern of system vulnerability under different Byzantine node ratios.

[0054] In summary, the evaluation method for a collaborative spectrum sensing system, by simulating worst-case attack behavior, quantifies the vulnerability boundary of the system under different scenarios. It has the characteristics of strong applicability, reliable evaluation, and easy implementation, and can provide a scientific basis for the accurate formulation of defense strategies.

[0055] The present invention also discloses a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method for simulating an attack on a cooperative spectrum sensing system, as well as the above-described method for evaluating a cooperative spectrum sensing system.

[0056] The parts not described in detail in the above embodiments are existing technologies.

[0057] It should be noted that although the present invention has been described through the above embodiments, the present invention may have many other embodiments. Without departing from the spirit and scope of the present invention, those skilled in the art can obviously make various corresponding changes and modifications to the present invention, but all such changes and modifications should fall within the scope of protection of the appended claims and their equivalents.

Claims

1. A method for simulating an attack on a cooperative spectrum sensing system, the cooperative spectrum sensing system comprising a primary user (PU), a reconfigurable intelligent surface (RIS), multiple secondary users (SU), a multi-hop decoding and forwarding relay node, and a fusion center (FC). The signal of the primary user (PU) is transmitted to each secondary user (SU) via a direct link or via a reflection link through the reconfigurable intelligent surface (RIS). Each secondary user (SU) obtains local statistics based on energy detection. The local statistics include the user proportion of Byzantine nodes and the sum of bit-flip probabilities, but cannot identify specific malicious individuals at the node level. The signal received by each secondary user (SU) from the primary user (PU) is subjected to local hard decision-making according to a preset threshold, generating local binary decision bits. Based on an audit bit reporting mechanism, the local binary decision bits are reported to the fusion center (FC) via a dual-path system. The fusion center (FC) divides the secondary user (SU) into honest and dishonest groups based on the consistency check of the local binary decision bits received via the dual paths, and calculates the corresponding Byzantine posterior probabilities. The method is characterized in that... The simulated attack method is executed by the attacker and includes the following steps: Under the constraint that the attacker cannot obtain the global instantaneous channel state information (CSI) from the primary user PU through the reconfigurable smart surface RIS and the multi-hop decoding and forwarding relay node to the fusion center FC, a prediction expression for the maximum likelihood fusion statistics reported by the dual paths is constructed on the fusion center FC side, and the contributions of each link, honest group, and dishonest group of the dual paths in the prediction expression are decomposed. With the goal of forcing the expected value of the maximum likelihood fusion statistic to approach zero, the solution is performed based on the item-by-item contribution to determine the optimal fusion rule between the first flip probability α of the Byzantine node executing a flip to 0 when the local binary decision is 1 and the second flip probability β of executing a flip to 1 when the local binary decision is 0. According to the optimal fusion rule, an optimal flip probability parameter is configured for at least one Byzantine node controlled by the attacker, so that each Byzantine node performs probabilistic tampering on its local binary decision bit according to the configured optimal flip probability parameter before reporting in accordance with the audit bit reporting mechanism.

2. The simulated attack method according to claim 1, characterized in that: If the secondary user's SU sensing channel is an ideal channel and the multi-hop decoding forwarding relay network is in a scenario with a high signal-to-noise ratio (SNR), the optimal fusion rule is that the first flip probability α and the second flip probability β are equal. If the secondary user's SU sensing channel is an ideal channel and the multi-hop decoding and forwarding relay network is under low signal-to-noise ratio (SNR) conditions, and each relay transmission process is equivalent to a binary symmetric channel, the optimal fusion rule is that the first flip probability α and the second flip probability β are equal. In the general scenario where the secondary user's SU sensing channel is a non-ideal channel, the optimal fusion rule is that the sum of the first flip probability α and the second flip probability β equals 1.

3. The simulated attack method according to claim 1, characterized in that, In the simulated attack method: the attacker pre-controls a certain proportion of secondary users (SU) as Byzantine nodes. The Byzantine nodes maintain consistency with the secondary users (SU) of the honest group in terms of the apparent behavior of local hard decision and dual-path reporting structure, so as to integrate into the cooperative spectrum sensing system.

4. The simulated attack method according to claim 1, characterized in that, The dual-path reporting method involves pairing the secondary users (SU) into two cooperative units; each secondary user (SU) simultaneously uploads its local decision bits to the fusion center (FC) via a multi-hop decoding and forwarding relay node through both the direct reporting link and the indirect link relayed by its paired user.

5. The simulated attack method according to claim 1, characterized in that: The channel between the two multi-hop decoding and forwarding relay nodes is a binary channel.

6. An evaluation method for a cooperative spectrum sensing system, characterized in that, Includes the following steps: Simulated attack: The simulated attack method described in any one of claims 1 to 5 is used to perform probabilistic tampering on the local binary decision bits of the cooperative spectrum sensing system; Vulnerability assessment: During simulated attacks, the decision results of the fusion center FC are collected, and the system bit error rate or detection probability is calculated to quantitatively analyze the security vulnerability of the cooperative spectrum sensing system under different attack configurations or different system parameters.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the simulated attack method as described in any one of claims 1 to 5 and / or the evaluation method as described in claim 6.