GNSS spoofing detection method fusing orthogonal anomaly score and incremental gating

CN122776282APending Publication Date: 2026-09-18XIANGTAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611143986.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-30
Publication Date
2026-09-18

AI Technical Summary

Technical Problem

传统固定阈值方法难以在不同场景下保持稳定性能;离线训练的检测模型虽然能够学习一定的非线性判别边界,但在长期运行或跨平台部署时容易出现模型失配

Benefits of technology

[0040] (1) The GNSS deception detection method of the present invention, which integrates orthogonal anomaly scoring and incremental gating, groups and models anomalies in the physical process of GNSS signal reception and anomalies in the kinematic consistency of GNSS/IMU into an orthogonal scoring subspace of the signal layer and an orthogonal scoring subspace of the data layer. These subspaces are then input into independent expert sub-models for discrimination. An orthogonality reward term is constructed using the statistical correlation between the two subspaces under normal conditions, effectively utilizing the positive complementary relationship between the signal layer and the data layer. Gain enhancement is achieved when two relatively independent physical dimensions are simultaneously abnormal, and false alarms are suppressed when only a single dimension is abnormal. Compared with the method of directly splicing features into a single classifier, this method significantly improves the reliability of deception detection and reduces the false alarm rate and false negative rate caused by single-dimensional anomalies in complex environments such as multipath and occlusion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122776282A_ABST
    Figure CN122776282A_ABST
Patent Text Reader

Abstract

The application discloses a GNSS spoofing detection method of orthogonal abnormal score and incremental gate fusion, and relates to the technical field of unmanned aerial vehicle navigation safety. The method first collects GNSS observation, positioning and IMU data, constructs signal layer and data layer basic abnormal index and converts into orthogonal abnormal score subspace; inputs signal layer expert and data layer expert respectively to obtain two spoofing confidence degrees; the fusion weight of the two experts is dynamically calculated according to the flight state vector through the gate arbitration network; the statistical correlation of the two score subspaces under the normal state is utilized to construct the orthogonality index and calculate the orthogonality reward item; the final spoofing probability is calculated based on the weighted fusion result and the orthogonality reward item, and a three-level grading response is executed; only the normal state sample is used to update the gate network parameters through limited incremental learning. The application effectively reduces the false positive rate and the missed detection rate of spoofing detection in a complex environment, and has good robustness and migration.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of unmanned aerial vehicle (UAV) navigation safety technology, and in particular to a GNSS spoofing detection method that fuses orthogonal anomaly scoring with incremental gating. Background Technology

[0002] With the rapid development of applications such as low-altitude economy, drone logistics, low-altitude inspection, emergency communication, and urban air traffic, drones, as important mobile nodes in low-altitude networks, increasingly rely on stable, continuous, and reliable positioning and navigation information. Global Navigation Satellite Systems (GNSS) can provide drones with all-weather position, velocity, and time information, serving as a crucial foundation for autonomous flight, trajectory planning, mission execution, and safe return. However, GNSS signals reach ground or low-altitude receivers at extremely low power, and their publicly available format makes them vulnerable to obstruction, multipath propagation, interference, and spoofing attacks. GNSS spoofing attacks, in particular, transmit forged satellite navigation signals, causing target receivers to lock onto incorrect pseudorange, Doppler, and navigation message information. This induces drones to calculate incorrect position, velocity, and time results, potentially leading to veergency, loss of control, intrusion into no-fly zones, or collisions.

[0003] Existing GNSS spoofing detection methods mainly include signal layer detection methods, data layer detection methods, and anomaly detection methods based on multi-source fusion. Signal layer detection methods typically use observational indicators such as carrier-to-noise ratio, received power, automatic gain control (AGC), correlation function shape, Doppler consistency, or signal direction of arrival to identify spoofing signals. These methods can directly reflect abnormal changes in GNSS signals during propagation, reception, RF front-end processing, and baseband correlation processing. However, in low-altitude urban environments, building reflections, obstructions, and strong multipath propagation can also cause similar signal quality anomalies, leading to an increased false alarm rate.

[0004] Data layer detection methods typically utilize the consistency relationships between GNSS positioning results, inertial measurement units (IMUs), barometers, visual odometry, or other navigation sensors to identify anomalies. For example, they identify positioning anomalies through indicators such as position residuals, velocity residuals, Kalman filter innovations, and differences between the IMU-calculated trajectory and the GNSS trajectory. These methods can use UAV kinematic constraints to determine the reliability of GNSS calculations; however, under conditions of high-dynamic UAV maneuvers, airframe vibration, accumulated IMU noise, or significant sensor calibration errors, the data layer residuals themselves can fluctuate considerably. Furthermore, in slow-drag spoofing attacks, attackers gradually alter the forged positioning results, potentially slowing the accumulation of data layer anomalies and increasing detection latency.

[0005] To improve detection performance, existing research has attempted to input multiple signal quality indicators and multi-source sensor indicators into machine learning or deep learning models for classification. However, these methods typically concatenate indicators from different sources into a unified feature vector and then output the detection result through a fixed threshold or a single classifier, failing to fully utilize the differences between signal layer features and data layer features in terms of physical sources, noise mechanisms, and attack susceptibility. Specifically, signal layer features mainly originate from GNSS electromagnetic signal propagation, antenna reception, RF front-end gain control, and baseband correlation operations; data layer features mainly originate from the consistency relationship between GNSS positioning results and IMU kinematic constraints. The corresponding physical processes are independent of each other, and the ways in which they are affected by environmental interference and spoofing attacks are not entirely the same. When anomalies occur simultaneously in two relatively independent physical dimensions, the credibility of a GNSS spoofing attack is usually higher than that of a single-dimensional anomaly; while when anomalies occur only in the signal layer or only in the data layer, they may be caused by multipath, obstruction, vibration, or short-term sensor noise. Existing methods lack explicit modeling of the above positive complementary relationships, which can easily lead to false alarms or missed detections in complex environments.

[0006] Furthermore, the flight environment of low-altitude UAVs exhibits significant dynamic changes. When UAVs operate at different altitudes, speeds, attitudes, temperatures, vibrations, and electromagnetic environments, the noise distribution of the GNSS receiver and IMU drifts. Traditional fixed-threshold methods struggle to maintain stable performance across different scenarios; while offline-trained detection models can learn certain nonlinear discrimination boundaries, they are prone to model mismatch during long-term operation or cross-platform deployment. Directly updating the entire detection model using online samples may introduce deceptive or abnormal samples into the training process, contaminating model parameters and reducing detection reliability. Summary of the Invention

[0007] To address the aforementioned technical problems, this invention provides a GNSS spoofing detection method that integrates orthogonal anomaly scoring and incremental gating. It groups and models GNSS signal reception physical process anomalies and GNSS / IMU kinematic consistency anomalies, and utilizes the positive complementary relationship between the two to improve the reliability of spoofing detection.

[0008] To solve the above-mentioned technical problems, the technical solution proposed by this invention is as follows:

[0009] A GNSS spoofing detection method that fuses orthogonal anomaly scoring with incremental gating includes the following steps:

[0010] Step S1: Real-time acquisition of raw GNSS receiver observation data, GNSS positioning calculation results, and inertial measurement unit (IMU) measurement data of the UAV under test during its flight.

[0011] Step S2: Set a sliding detection window of length T. Within each sliding detection window, perform time synchronization and preprocessing on the collected data, and construct basic anomaly indicators for the signal layer and basic anomaly indicators for the data layer respectively.

[0012] Step S3: Based on the normal state baseline and the direction of index anomalies, convert the basic anomaly index of the signal layer into the orthogonal anomaly scoring subspace of the signal layer, and convert the basic anomaly index of the data layer into the orthogonal anomaly scoring subspace of the data layer.

[0013] Step S4: Input the signal layer orthogonal anomaly scoring subspace into the first expert sub-model, and obtain the first deception confidence after multi-branch encoding and branch weight fusion; input the data layer orthogonal anomaly scoring subspace into the second expert sub-model, and obtain the second deception confidence after multi-branch encoding and branch weight fusion;

[0014] Step S5: Construct a state vector based on the current flight speed and GNSS observation environment, input the state vector into the gated arbitration network, and dynamically calculate the first fusion weight of the first expert sub-model and the second fusion weight of the second expert sub-model.

[0015] Step S6: Determine the orthogonality index based on the statistical correlation between the signal layer orthogonal anomaly scoring subspace and the data layer orthogonal anomaly scoring subspace under normal flight conditions;

[0016] Step S7: Calculate the orthogonality reward item based on the orthogonality index, the first deception confidence level, and the second deception confidence level;

[0017] Step S8: Calculate the final deception probability based on the first fusion weight, the second fusion weight, the first deception confidence, the second deception confidence, and the orthogonality reward term, and execute the three-level hierarchical response strategy based on the final deception probability.

[0018] In step S9, the detection window samples that are determined to be in a normal state are written into the rolling sample buffer. When the number of samples in the buffer reaches the preset trigger threshold, only the parameters of the gated arbitration network are updated in a limited incremental manner, keeping the parameters of the first expert sub-model and the second expert sub-model unchanged.

[0019] A further improvement to the above technical solution is as follows:

[0020] Preferably, in step S2, the signal layer basic anomaly indicators include one or more of the following: received power cross-channel dispersion characteristics, code observation and carrier observation physical consistency characteristics, observation satellite number and geometric strength characteristics, and Doppler frequency shift dispersion characteristics; the data layer basic anomaly indicators include one or more of the following: position change trend slope characteristics, velocity change trend slope characteristics, position residual mean absolute deviation characteristics, and velocity and position ratio consistency characteristics.

[0021] Preferably, in step S3, converting the signal layer basic anomaly indicators into a signal layer orthogonal anomaly scoring subspace and converting the data layer basic anomaly indicators into a data layer orthogonal anomaly scoring subspace specifically involves: estimating the statistical distribution parameters of each basic anomaly indicator based on historical data under normal flight conditions, converting each indicator into a standardized deviation relative to the normal baseline, forming a signal layer orthogonal anomaly scoring subspace from the standardized deviations corresponding to the signal layer basic anomaly indicators, and forming a data layer orthogonal anomaly scoring subspace from the standardized deviations corresponding to the data layer basic anomaly indicators.

[0022] Preferably, in step S4, the first expert sub-model divides the signal layer orthogonal anomaly scoring subspace into several signal anomaly scoring sub-vectors according to the physical process of GNSS signal reception. Each signal anomaly scoring sub-vector is input into the corresponding lightweight branch encoder to obtain each branch latent vector. The branch weight is calculated based on each branch latent vector, and the branch latent vectors are weighted and fused to obtain the signal layer fused latent vector. The first deception confidence is output from the signal layer fused latent vector. The second expert sub-model divides the data layer orthogonal anomaly scoring subspace into several data anomaly scoring sub-vectors according to the source of kinematic consistency, and outputs the second deception confidence in the same way.

[0023] Preferably, in step S5, the state vector includes a flight speed state index, an inertial estimation reliability index, and a GNSS observation quality index.

[0024] The state vector Input the gated arbitration network and calculate the fusion weights corresponding to the first expert sub-model:

[0025]

[0026] in, Indicates the first The fusion weights of the first expert sub-model in each window; The weight parameters represent the weights of the gated arbitration network. Indicates the bias parameters of the gated arbitration network; Indicates the first The state vector of each window, Represents the sigmoid function;

[0027] The fusion weights corresponding to the second expert sub-model are:

[0028]

[0029] in, Indicates the first The fusion weights of the second expert sub-model in each window; Indicates the first The fusion weights of the first expert sub-model in each window.

[0030] Preferably, in step S6, the orthogonality index is calculated by measuring the overall statistical correlation between the signal layer orthogonal anomaly scoring subspace and the data layer orthogonal anomaly scoring subspace. The orthogonality index is obtained. The overall statistical correlation index It is obtained by any one of the statistical dependence measures, such as Pearson correlation coefficient, Spearman correlation coefficient, mutual information normalized value, or distance correlation coefficient.

[0031] Preferably, in step S7, the formula for calculating the orthogonality reward term is:

[0032]

[0033] in, express Orthogonality reward items for each window, An orthogonality index representing the orthogonality between the signal layer orthogonal anomaly scoring subspace and the data layer orthogonal anomaly scoring subspace. Indicates the first The first level of deception confidence for each window. Indicates the first The second deception confidence level of the window. This is a two-expert consensus function.

[0034] Preferably, in step S8, the final deception probability is calculated as follows:

[0035]

[0036] in, Indicates the first The final probability of deception for each window. Indicates the first Fusion weights of signal layer experts in each window This indicates the first level of confidence in deception. Indicates the first The fusion weight of data layer experts in each window This indicates the second level of confidence in deception. Indicates the first Orthogonality reward items for each window, This represents the orthogonality gain factor. This represents a range mapping function.

[0037] Preferably, in step S8, a high threshold is set. and low threshold As a preset constant, satisfying The three-level hierarchical response strategy is specifically as follows: when the final deception probability... If the system is determined to be in a high-confidence deception state, an alarm will be triggered and the system will switch to pure inertial navigation mode; when When the condition is deemed suspicious, GNSS closed-loop correction of the IMU is suspended and the sliding detection window step size is shortened; when When the condition is normal, continue to use GNSS data for integrated navigation closed-loop correction, and store the current window information in the rolling sample buffer.

[0038] Preferably, in step S9, the restricted incremental update specifically involves: for samples in the rolling sample buffer that are determined to be in a normal state, freezing all parameters of the first expert sub-model and the second expert sub-model, using the pseudo-label of the normal sample as the supervision signal, and updating the weight parameters and bias parameters of the gated arbitration network using a small learning rate gradient descent algorithm with the sole objective of reducing the final deception probability; and clearing the rolling sample buffer after each incremental update.

[0039] The GNSS spoofing detection method based on orthogonal anomaly scoring and incremental gating fusion provided by this invention has the following advantages compared with existing technologies:

[0040] (1) The GNSS deception detection method of the present invention, which integrates orthogonal anomaly scoring and incremental gating, groups and models anomalies in the physical process of GNSS signal reception and anomalies in the kinematic consistency of GNSS / IMU into an orthogonal scoring subspace of the signal layer and an orthogonal scoring subspace of the data layer. These subspaces are then input into independent expert sub-models for discrimination. An orthogonality reward term is constructed using the statistical correlation between the two subspaces under normal conditions, effectively utilizing the positive complementary relationship between the signal layer and the data layer. Gain enhancement is achieved when two relatively independent physical dimensions are simultaneously abnormal, and false alarms are suppressed when only a single dimension is abnormal. Compared with the method of directly splicing features into a single classifier, this method significantly improves the reliability of deception detection and reduces the false alarm rate and false negative rate caused by single-dimensional anomalies in complex environments such as multipath and occlusion.

[0041] (2) The GNSS deception detection method of orthogonal anomaly scoring and incremental gating fusion of the present invention dynamically allocates the fusion weights of the two expert sub-models according to the current flight speed, IMU credibility and GNSS observation quality through a gating arbitration network. When the flight is highly dynamic or the IMU error accumulation is large, the signal layer expert is given priority. When the GNSS observation quality is degraded or the environment is strong multipath, the data layer expert is given priority. This realizes the adaptive allocation of expert credibility under different flight environments, so that the system can maintain stable detection performance under complex flight conditions such as high dynamic maneuvering of UAV and sensor noise drift.

[0042] (3) The GNSS deception detection method of orthogonal anomaly scoring and incremental gating fusion of the present invention freezes all parameters of the two expert sub-models by only performing security screening on normal state judgment samples and only updating the parameters of the gating arbitration network. While utilizing online samples to adapt to the slow drift of sensor noise distribution, it effectively avoids the risk of deception samples or abnormal samples contaminating the expert sub-models, ensuring the reliability and stability of the detection model during long-term operation, and has good cross-scene and cross-platform deployment capabilities. Attached Figure Description

[0043] Figure 1 This is a flowchart illustrating step S9 in this invention.

[0044] Figure 2 This is a schematic diagram of the cross-correlation matrix between the signal layer features and the data layer features of this invention.

[0045] Figure 3 This is a comparison of experimental results between the present invention and the direct splicing feature. Detailed Implementation

[0046] The following provides a detailed description of specific embodiments of the present invention. It should be understood that the specific embodiments described herein are for illustrative and explanatory purposes only and are not intended to limit the scope of the invention.

[0047] like Figure 1 As shown, the GNSS spoofing detection method based on orthogonal anomaly scoring and incremental gating fusion of the present invention first constructs basic anomaly indicators from raw GNSS receiver observation data, GNSS positioning solution results, and IMU measurement data, and transforms these basic anomaly indicators into anomaly scores based on the normal state baseline. Then, according to the physical source, the anomaly scores are divided into a signal layer orthogonal scoring subspace and a data layer orthogonal scoring subspace, and input into the corresponding expert sub-models to obtain spoofing confidence. Further, based on the current flight state and GNSS observation environment, the fusion weights of the two expert sub-models are dynamically allocated through a gating arbitration network. Simultaneously, based on the statistical independence of the signal layer orthogonal scoring subspace and the data layer orthogonal scoring subspace under normal conditions, an orthogonality index is constructed, and an orthogonality reward term is introduced when both orthogonal detection dimensions simultaneously output high spoofing confidence, ultimately obtaining the GNSS spoofing probability and executing a graded response. This method also uses a rolling sample buffer and a restricted incremental learning mechanism to update the gating arbitration network parameters using only reliable normal samples, while keeping the parameters of the two expert sub-models unchanged, thereby reducing the risk of online sample contamination and improving long-term operational stability.

[0048] The detection algorithm described in this invention is deployed on an UAV onboard computing platform to collect measurement data from a GNSS receiver and an IMU in real time at a preset sampling frequency. Using a sliding detection window as the basic processing unit, the algorithm specifically includes the following steps:

[0049] Step S1: Real-time acquisition of raw GNSS receiver observation data, GNSS positioning calculation results, and inertial measurement unit (IMU) measurement data of the UAV under test during its flight.

[0050] Raw GNSS receiver observation data includes one or more of the following: carrier-to-noise ratio, pseudorange, carrier Doppler shift, automatic gain control (AGC) value, correlator output value, number of visible satellites, and satellite signal quality indicators. GNSS positioning results include one or more of the following: position, velocity, time, positioning status, positioning accuracy factor, and satellite geometric distribution information. IMU measurement data includes one or more of the following: three-axis acceleration, three-axis angular velocity, attitude angle, attitude angular velocity, inertial-estimated position, and inertial-estimated velocity.

[0051] Let the first The raw GNSS observation set for each detection epoch is as follows:

[0052] (1)

[0053] in, Indicates the first The raw GNSS observation set of each detection epoch; Indicates the first The first calendar year The carrier-to-noise ratio of each satellite; Indicates the first The first calendar year Pseudorange observations from a single satellite; Indicates the first The first calendar year Carrier Doppler shift observations of the satellites; Indicates the first The receiver automatic gain control (AGC) value for each epoch; Indicates the first The first calendar year The correlator output information for each satellite; Indicates the epoch index for detection; Indicates satellite index, ; Indicates the first The number of satellites successfully tracked per epoch.

[0054] Let the first The GNSS positioning solution for each detection epoch is as follows:

[0055] (2)

[0056] in, Indicates the first GNSS positioning solution results for each detection epoch; This represents the position vector obtained from GNSS calculation; This represents the velocity vector obtained from GNSS calculations.

[0057] Let the first The IMU measurement data for each detection epoch are as follows:

[0058] (3)

[0059] in, Indicates the first IMU measurement data for each detection epoch; This represents the three-axis acceleration vector measured by the IMU; This represents the three-axis angular velocity vector measured by the IMU.

[0060] In the actual data acquisition of this embodiment, for each detection epoch... The onboard computer first reads the raw observation messages in NMEA (National Marine Electronics Association) format or UBX protocol format through the UART interface of the GNSS receiver, and then parses the carrier-to-noise ratio of each satellite. pseudo-distance Doppler frequency shift and receiver AGC value For receivers that do not have the original output of a multi-branch correlator, Position can be indirectly estimated by the carrier-to-noise ratio or replaced by a signal quality indication provided by the receiver. Simultaneously, the onboard computer extracts the position from the PVT (Position, Velocity, Time) messages of the GNSS receiver. and speed IMU data is read via SPI or I2C interface to obtain triaxial acceleration. and triaxial angular velocity All collected data is tagged with a uniform timestamp and cached in an in-memory queue for subsequent sliding window processing.

[0061] In this embodiment, since the publicly available dataset does not contain complete AGC values ​​and correlator multi-branch outputs, the AGC values ​​in step S1 are... and correlator output Equivalent substitutions can be made using carrier-to-noise ratio statistics and signal quality indicators. In actual drone deployment, the actual AGC and correlator values ​​directly output by the receiver hardware should be used.

[0062] Step S2, set the length to The sliding detection window performs time synchronization and preprocessing on the collected data within each sliding detection window, and constructs basic anomaly indicators for the signal layer and basic anomaly indicators for the data layer respectively.

[0063] The original observations are converted into quantitative indicators that can reflect anomalies in the physical processes of GNSS signal reception and anomalies in the kinematic consistency of GNSS / IMU, providing input for the subsequent construction of orthogonal scoring subspaces.

[0064] S2-1, Set the sliding detection window.

[0065] Set the length to A sliding detection window with a step size of 1. For the first A sliding detection window ,have:

[0066] (4)

[0067] in, Indicates the first A sliding detection window; This indicates the starting detection epoch of the window; This indicates the number of sampling points within the window. If the sampling period is... ,but The window's initial epoch satisfies ; Indicates the index of the sliding window.

[0068] S2-2 performs time synchronization and preprocessing on the collected data.

[0069] Within each sliding detection window, the raw GNSS receiver observation data, GNSS positioning solution results, and IMU measurement data undergo time synchronization, missing value removal, outlier removal, and coordinate system unification processing. For GNSS position data, latitude and longitude coordinates are converted to a local navigation coordinate system or a local plane coordinate system. The converted GNSS position is represented as follows:

[0070] (5)

[0071] in, Represents the first in a unified coordinate system GNSS position vectors for each epoch; This represents the position vector obtained from the original GNSS solution; This represents a coordinate transformation operator that converts latitude, longitude, and altitude coordinates into three-dimensional coordinates in a local navigation coordinate system. The specific transformation method is as follows: First, the latitude and longitude are converted to geocentric coordinates. Then, a rotation matrix is ​​used to project the coordinates onto the northeast-sky local tangent plane centered on the reference point. Finally, the eastward, northward, and celestial position offsets relative to the reference point are obtained.

[0072] S2-3, Construct basic anomaly indicators for the signal layer and basic anomaly indicators for the data layer.

[0073] It includes one or more of the following: position-velocity consistency characteristics, velocity-acceleration consistency characteristics, trajectory trend change characteristics, velocity trend change characteristics, and inertial calculation residual characteristics.

[0074] (I) Fundamental signal layer anomaly indicators are used to characterize abnormal changes in GNSS signal propagation, antenna reception, RF front-end processing, and baseband correlation processing. The following four types of fundamental signal layer anomaly indicators are constructed:

[0075] (a) Received power cross-channel dispersion characteristics: reflecting the degree of consistency of received power among tracked satellites.

[0076] Under normal conditions, although the power of signals from different satellites reaching the receiver antenna varies, the overall distribution is relatively stable. However, when spoofing signals are injected, the power distribution between channels may change abnormally. This characteristic is calculated using the sample standard deviation of the carrier-to-noise ratio of all tracked satellites within the window.

[0077] (6)

[0078] in, Indicates the first The cross-channel dispersion characteristics of received power in each window; Indicates the first The number of valid satellites tracked within a window is calculated as the median or average of the number of visible satellites at each epoch within the window. Indicates the first The first window The carrier-to-noise ratio of each satellite; Indicates the first The average carrier-to-noise ratio of all tracked satellites within a window; Indicates satellite index.

[0079] (b) Physical consistency characteristics between code observation and carrier observation: reflecting the theoretical consistency between pseudorange change rate and carrier Doppler frequency shift.

[0080] Under normal conditions, the time rate of change of pseudorange should satisfy a deterministic physical relationship with the carrier Doppler shift; this characteristic will become abnormal when the spoofing signal disrupts the consistency between the code phase and the carrier phase. This characteristic is calculated by the root mean square of the deviation between the pseudorange rate of change and the Doppler shift within a window:

[0081] (7)

[0082] in, Indicates the first Physical consistency characteristics of code observation and carrier observation in each window; Indicates the first The number of effective satellites tracked within a window; Indicates the first The first window The temporal variation of the pseudorange of each satellite is calculated by the difference between the pseudoranges at the beginning and end of the window. This indicates the time difference between the beginning and end of the window; Indicates the first The first window Carrier Doppler shift observations of the satellites; Indicates the carrier frequency of the GNSS signal; This represents the speed of light in a vacuum.

[0083] (c) Number and geometric strength characteristics of observation satellites: reflecting the availability of GNSS observations and the quality of satellite geometric distribution.

[0084] In a deception attack, attackers may alter the number and geometric distribution of visible satellites by increasing false satellite signals or interfering with some satellite signals. This feature is constructed by combining the average number of visible satellites within a window with the Dilution of Precision (DOP).

[0085] (8)

[0086] in, Indicates the first Number of observed satellites and geometric intensity characteristics for each window; Indicates the first The number of effective satellites tracked within a window; This indicates the number of reference satellites under normal conditions, which is determined based on the visibility of the GNSS constellation in the area where the UAV is located, and is generally taken as 8 to 12. This indicates the reference precision factor under normal conditions; Indicates the first Average positioning accuracy factor for each window.

[0087] (d) Doppler frequency shift dispersion characteristics: reflecting the degree of dispersion between the Doppler frequency shifts of each satellite.

[0088] This feature is calculated using the sample standard deviation of the Doppler shift of all satellites within the window:

[0089] (9)

[0090] in, Indicates the first Doppler frequency shift discreteness characteristics of each window; Indicates the first The number of effective satellites tracked within a window; Indicates the first The first window Carrier Doppler shift observations of the satellites; Indicates the first The average value of the Doppler shift of all satellites within a window.

[0091] The first The set of basic anomaly indicators of the signal layer obtained within a window Represented as:

[0092] (10)

[0093] (II) Basic anomaly indicators at the data layer are used to characterize inconsistencies between GNSS positioning results and UAV inertial motion constraints. The following four types of basic anomaly indicators at the data layer are constructed:

[0094] (a) Slope feature of position change trend: This reflects the changing trend of the GNSS position sequence within the window. This feature is obtained by linearly fitting the GNSS position sequence within the window and taking the absolute value of its slope as the feature value:

[0095] (11)

[0096] in, Indicates the first The slope characteristics of the position change trend of each window; Indicates the first GNSS eastward position component for each epoch; Indicates the first GNSS northward position components for each epoch; Indicates the window All epochs within Perform summation; This represents the slope estimate obtained by performing a least-squares linear fit on the sequence.

[0097] The slope characteristic of position change trend represents the speed of position movement in the horizontal direction. Under drag-and-drop spoofing attacks, this characteristic may change slowly but continuously.

[0098] (b) Slope characteristic of velocity change trend: This reflects the changing trend of the GNSS velocity sequence within the window. This feature is obtained by linearly fitting the GNSS velocity sequence within the window and taking the absolute value of its slope as the feature value:

[0099] (12)

[0100] in, Indicates the first The slope characteristics of the velocity change trend in each window; Indicates the first GNSS eastward velocity components for each epoch; Indicates the first The GNSS northward velocity component of each epoch.

[0101] The slope characteristic of velocity change trend represents the rate of change of velocity in the horizontal direction. Under the slope deception attack, the velocity deviation gradually increases, resulting in an abnormal velocity trend slope.

[0102] (c) Mean Absolute Deviation of Position Residue: This feature reflects the consistency deviation between the GNSS position and the inertial-estimated position within the window. Considering that the publicly available dataset used in this embodiment does not contain complete raw IMU data, this feature is approximated by the residual of the GNSS position sequence within the window relative to its fitted trajectory.

[0103] (13)

[0104] in, Indicates the first The mean absolute deviation characteristics of the positional residuals of each window; , Indicates the first The position fitting values ​​for each epoch are obtained by performing low-order polynomial fitting or Kalman smoothing on the position sequence within the window. This indicates the number of sampling points within the window.

[0105] The mean absolute deviation of position residuals characterizes the degree of fluctuation in GNSS position sequences, and position residuals typically increase under deception attacks.

[0106] (d) Consistency between velocity and position ratio: This reflects the kinematic coordination between GNSS velocity and position changes within the window. Under normal motion conditions, the integral of velocity should remain consistent with the position change; under deception attacks, this coordination may be disrupted.

[0107] (14)

[0108] in, Indicates the first The consistency of the speed and position ratio of each window; Indicates the first The total change in GNSS position within a window, i.e. the Euclidean distance between the end position and the beginning position of the window; This indicates the time difference between the beginning and end of the window; Indicates the first The average GNSS velocity within a window.

[0109] The consistency characteristic of velocity and position ratio should be close to zero during normal uniform linear motion, but will increase significantly when a deception attack causes inconsistency between position and velocity.

[0110] The first The set of basic anomaly indicators of the data layer obtained within each window is represented as follows:

[0111] (15)

[0112] in: Indicates the first A set of basic anomaly indicators for the data layer of each window.

[0113] It should be noted that the number and specific definitions of the aforementioned basic anomaly indicators for the signal and data layers can be expanded or replaced based on the types of raw observation data available from the actual GNSS receiver and IMU. For example, on a receiver platform with complete AGC output, the total incident power variation characteristics of the RF front end can be added; on a receiver platform with multi-branch correlator outputs, correlation function morphology characteristics (such as the lead-lag correlator peak ratio, correlation peak symmetry, etc.) can be added; on a platform with a high-precision IMU, Kalman filter innovation characteristics of velocity and position residuals can be added. All of the above expansions do not change the overall process and core idea of ​​the method described in this invention.

[0114] Step S3: Based on the normal state baseline and the direction of index anomalies, convert the basic anomaly index of the signal layer into the orthogonal anomaly scoring subspace of the signal layer, and convert the basic anomaly index of the data layer into the orthogonal anomaly scoring subspace of the data layer.

[0115] The signal layer and data layer basic anomaly indices extracted in step S2 are converted into standardized orthogonal anomaly scoring subspaces. To avoid differences in dimensions, numerical scales, noise ranges, and anomaly directions among different basic anomaly indices, this invention does not directly input the basic anomaly indices into the detection model. Instead, it uses historical data under normal flight conditions to estimate the statistical distribution parameters (mean and standard deviation) of each basic anomaly index, converts each index into a standardized deviation relative to the normal baseline, and constructs orthogonal anomaly scoring subspaces for the signal layer and data layer respectively. This eliminates the differences in dimensions, numerical scales, and anomaly directions among different indices, forming scoring subspaces with clear physical meaning and strong separability.

[0116] S3-1, determine the statistical baseline of each basic abnormal indicator under normal conditions.

[0117] Continuous observation data of UAVs under known normal flight conditions (such as ≥30 minutes of normal flight data collected in an open, undisturbed environment) are selected as the offline normal sample library, or data collected before the detection is initiated are used. windows (such as) The observation data (corresponding to 250 seconds in each window) are used as the initial normal state baseline.

[0118] For any basic abnormal index The normal mean is determined based on historical normal windows or offline normal sample libraries. and normal standard deviation And calculate the standardized offset:

[0119] (16)

[0120] in, Indicates the first The first window The standardized deviation of a basic abnormal indicator represents the degree and direction of deviation of the current value of the indicator from the normal baseline. Indicates the first The first window The original values ​​of the basic abnormal indicators; Indicates the first The normal mean of the basic abnormal indicators; Indicates the first The normal state standard deviation of the basic abnormal indicators; This represents a stable term (regularization term) to prevent the denominator from being zero, and it takes a very small positive number.

[0121] Standardized deviation A positive value indicates that the current indicator value is higher than the normal average, while a negative value indicates that it is lower than the normal average. The larger the absolute value, the more significant the deviation from the normal state.

[0122] Based on the physical meaning and direction of the basic anomaly indicators, one or more of the following can be selected to be retained: signed standardized deviation, positive deviation, negative deviation, or absolute deviation, to avoid losing anomaly direction information during the standardization process. Specifically:

[0123] (1) For abnormally large indicators (i.e., physical quantities whose indicator values ​​increase under deception attacks, such as cross-channel dispersion of received power, position residuals, etc.), take the positive deviation amount. Or retain the signed deviation. ;

[0124] (2) For abnormally decreasing indicators (i.e., physical quantities whose indicator values ​​decrease under deception attacks, such as the number of visible satellites), take the negative deviation. The absolute value;

[0125] (3) For bidirectional anomaly indicators (i.e., physical quantities that may indicate an attack whether they are abnormally increased or abnormally decreased), take the absolute deviation. ;

[0126] (4) For trend indicators (such as position trend change, speed trend change), both the signed deviation and the absolute deviation can be retained at the same time to capture abnormal changes in different directions.

[0127] In this embodiment, to simplify implementation, a signed standardized deviation is used for all basic abnormal indicators. It retains information about the direction of anomalies, allowing subsequent branch encoders to automatically learn the discrimination patterns for anomalies in different directions.

[0128] S3-2, construct the orthogonal anomaly scoring subspace of the signal layer and the orthogonal anomaly scoring subspace of the data layer.

[0129] The normalized deviations derived from GNSS signal propagation, receiver RF front-end, and baseband correlation processing constitute the signal layer orthogonal scoring subspace:

[0130] (17)

[0131] in, Indicates the first The signal layer orthogonal scoring subspace of each window, with each dimension corresponding to the standardized deviation of each basic anomaly index of the signal layer; The received power cross-channel dispersion score dimension is represented in the th dimension. The values ​​that can be obtained from each window. The physical consistency score dimension between code observations and carrier observations is in the 1st dimension. The values ​​that can be obtained from each window. The number of observed satellites and the geometric intensity score dimension are represented in the first dimension. The values ​​that can be obtained from each window. The Doppler frequency shift dispersion feature score dimension is represented in the th order. The values ​​that can be obtained from each window.

[0132] The standardized deviations corresponding to each basic anomaly index in the data layer are used to form an orthogonal scoring subspace for the data layer:

[0133] (18)

[0134] in, Indicates the first The data layer of each window has an orthogonal scoring subspace. The slope of the position change trend score dimension is represented in the first dimension. The values ​​that can be obtained from each window. The slope rating dimension, representing the trend of velocity change, is in the 1st place. The values ​​that can be obtained from each window. The mean absolute deviation of the positional residuals is represented in the 1st dimension. The values ​​that can be obtained from each window. The rating dimension indicating the consistency between velocity and position ratio is in the 1st place. The values ​​that can be obtained from each window.

[0135] The signal layer orthogonal scoring subspace and the data layer orthogonal scoring subspace correspond to the physical process of GNSS signal reception and the kinematic consistency process of GNSS / IMU, respectively. Their role is to provide unified input for the subsequent dual-expert sub-model based on physical block coding, orthogonality index calculation, and orthogonality reward fusion. This orthogonality will be quantitatively verified and calculated in step S6.

[0136] Step S4: Input the orthogonal scoring subspace of the signal layer into the first expert sub-model (signal layer expert), and obtain the first deception confidence after multi-branch encoding and branch weight fusion; input the orthogonal scoring subspace of the data layer into the second expert sub-model (data layer expert), and obtain the second deception confidence after multi-branch encoding and branch weight fusion.

[0137] To avoid the mixing of physical meanings caused by directly inputting the signal layer orthogonal scoring subspace and the data layer orthogonal scoring subspace into a single classifier, this invention constructs a first expert sub-model and a second expert sub-model, respectively. The first expert sub-model is used to process the signal layer orthogonal scoring subspace, and the second expert sub-model is used to process the data layer orthogonal scoring subspace.

[0138] S4-1, the first expert sub-model.

[0139] The first expert sub-model divides the orthogonal scoring subspace of the signal layer into several signal anomaly scoring sub-vectors according to the physical process of GNSS signal reception. These signal anomaly scoring sub-vectors correspond to one or more anomaly sources among received power distribution, RF front-end power variation, code carrier consistency, and correlation function shape. Let the first expert sub-model... The orthogonal scoring subspace of the signal layer for each window is:

[0140] (19)

[0141] in, Indicates the first The signal layer orthogonal scoring subspace of each window Indicates the first Each signal anomaly scoring subvector Indicates the number of branches in the signal layer.

[0142] For each signal anomaly score subvector, input it into the corresponding lightweight branch encoder for encoding:

[0143] (20)

[0144] in, Indicates the first The hidden vectors output by each signal layer branch Indicates the first A lightweight branch encoder for the signal layer. Indicates the first Each signal anomaly scoring subvector This indicates a branch index.

[0145] Calculate the signal layer branch weights based on the implicit vectors of each branch:

[0146] (twenty one)

[0147] in, This represents the normalized weights of each branch of the signal layer. This represents the branch weight matrix of the signal layer. This represents the overall latent vector obtained by concatenating the latent vectors of each signal layer branch. This represents the weight bias term for the signal layer branch.

[0148] The latent vectors of each branch are weighted and fused according to their branch weights to obtain the signal layer fused latent vector:

[0149] (twenty two)

[0150] in, The latent vector representing the signal layer fusion is the weighted sum of the latent vectors of each branch; Indicates the first Normalized weights of each signal layer branch Indicates the first The hidden vectors output by each signal layer branch Indicates the number of branches in the signal layer.

[0151] The first deception confidence score is output from the latent vector fusion at the signal layer:

[0152] (twenty three)

[0153] in, Indicates the first The first level of deception confidence for each window. Indicates the output weights of the signal layer. This represents the latent vector for signal layer fusion. This indicates the signal layer output bias term; This represents the sigmoid function, which compresses real numbers into the interval (0,1).

[0154] S4-2, the second expert sub-model.

[0155] The second expert sub-model uses the same multi-branch coding and branch weight fusion structure as the first expert sub-model. The difference is that the input of the second expert sub-model is the orthogonal scoring subspace of the data layer, and its branch division is based on the consistency relationship between the GNSS positioning solution and the IMU kinematics.

[0156] The second expert sub-model divides the orthogonal scoring subspace of the data layer into several data anomaly scoring sub-vectors according to the source of kinematic consistency. Let the first... The orthogonal scoring subspace of the data layer for each window is:

[0157] (twenty four)

[0158] in, Indicates the first The data layer of each window has an orthogonal scoring subspace. This represents the Nth data anomaly score vector, where N represents the number of data layer branches.

[0159] The second expert sub-model uses the same branch coding, branch weight calculation, and weighted fusion methods as the first expert sub-model to process each data anomaly scoring sub-vector, obtaining the data layer fusion latent vector. And output the second deception confidence level:

[0160] (25)

[0161] in, Indicates the first The second deception confidence level of the window. This represents the data layer fused latent vector obtained by weighting and fusing the latent vectors of each branch of the data layer according to their branch weights. Indicates the output weights of the data layer. This represents the data layer output bias term.

[0162] In this way, the first and second expert sub-models maintain consistency in network structure, but their input subspaces and physical grouping criteria differ. The first expert sub-model is used to identify anomalies in the physical process of GNSS signal reception, while the second expert sub-model is used to identify anomalies in the consistency between GNSS positioning results and IMU kinematics, thus maintaining relatively independent modeling of signal layer anomalies and data layer anomalies before entering the gated arbitration network.

[0163] Step S5: Construct a state vector based on the current flight speed and GNSS observation environment, input the state vector into the gated arbitration network, and dynamically calculate the fusion weights of the first expert sub-model and the fusion weights of the second expert sub-model.

[0164] S5-1, Constructing the first The state vector of each window .

[0165] The state vector describes the current motion state of the UAV, the reliability of the IMU, and the quality of GNSS observations, providing a basis for decision-making in the gated arbitration network. In this embodiment, the state vector is defined as:

[0166] (26)

[0167] in, Indicates the first The state vector of each window; The flight speed status indicator for the current window can be calculated from the GNSS speed modulus or the fused navigation speed modulus. This represents the reliability index of inertial estimation, used to characterize the time since the last GNSS / IMU closed-loop correction or the degree of IMU error accumulation; The quality index of GNSS observation can be obtained by normalizing the mean carrier-to-noise ratio, the number of visible satellites, the positioning accuracy factor, or the signal quality statistics. This indicates the transpose operation.

[0168] In this embodiment, GNSS observation quality indicators Construct it as follows:

[0169] (27)

[0170] in, Indicates the first The average carrier-to-noise ratio of all tracked satellites within a window. This is a reference value for the download noise ratio under normal conditions. The closer to 1, the better the signal quality; the closer to 0, the worse the signal quality.

[0171] S5-2, Calculate the fusion weights.

[0172] The state vector Input the gated arbitration network and calculate the fusion weights corresponding to the first expert sub-model:

[0173] (28)

[0174] in, Indicates the first The fusion weights of the first expert sub-model in each window; The weight parameters represent the weights of the gated arbitration network. Indicates the bias parameters of the gated arbitration network; Indicates the first The state vector of each window, This represents the sigmoid function.

[0175] The fusion weights corresponding to the second expert sub-model are:

[0176] (29)

[0177] in, Indicates the first The fusion weights of the second expert sub-model in each window; Indicates the first The fusion weights of the first expert sub-model in each window.

[0178] Through the aforementioned gating mechanism, when the UAV is in high-dynamic flight or when IMU errors accumulate significantly, the gating arbitration network increases the relative weight of the signal layer expert sub-model. In this case, the consistency constraints of the data layer become unreliable due to drift. When the GNSS observation quality deteriorates or the system is in a strong multipath environment, the gating arbitration network increases the relative weight of the data layer expert sub-model. In this case, the signal layer features are easily affected by environmental factors such as multipath. This adaptive weight allocation strategy ensures that under various flight conditions, the system prioritizes more reliable detection information sources, thereby achieving adaptive allocation of expert credibility under different flight environments.

[0179] Step S6: Determine the orthogonality index based on the statistical correlation between the signal layer orthogonal scoring subspace and the data layer orthogonal scoring subspace under normal flight conditions.

[0180] To explicitly utilize the complementary relationship between the orthogonal scoring subspace of the signal layer and the orthogonal scoring subspace of the data layer, this invention calculates the statistical correlation between the two scoring subspaces based on normal flight state samples, and determines an orthogonality index to characterize the degree of approximate orthogonality between the two based on the statistical correlation.

[0181] Assume there are a total of samples in the normal state sample set. For the nth sliding window sample, for the nth Each signal layer scoring dimension and the Each data layer scoring dimension Take them respectively The values ​​are taken within a normal window, and the Pearson correlation coefficient between them is calculated:

[0182] (30)

[0183] in, Indicates the first The first signal layer scoring dimension and the first Pearson correlation coefficients between the scoring dimensions of each data layer This represents the covariance operation. This indicates the standard deviation calculation.

[0184] Calculate the overall statistical correlation index:

[0185] (31)

[0186] in, A statistical correlation index representing the overall correlation between the orthogonal anomaly scoring subspace of the signal layer and the orthogonal anomaly scoring subspace of the data layer; Indicates the number of dimensions in the signal layer score; This indicates the number of scoring dimensions in the data layer.

[0187] Define the orthogonality index ,in An orthogonality index representing the orthogonality between the signal layer orthogonal anomaly scoring subspace and the data layer orthogonal anomaly scoring subspace. . The larger the value, the weaker the statistical correlation and the stronger the positive complementarity between the two types of rating subspaces. When the value is close to 1, the two types of features are almost completely orthogonal; when When the value approaches zero, both types of features exhibit high redundancy. In this embodiment, as... Figure 2 The average absolute correlation was calculated as shown. The value is approximately 0.115, corresponding to an orthogonality index κ of approximately 0.885. This indicates that the two types of scoring subspaces have a weak statistical correlation and strong complementarity under normal conditions, which can serve as the basis for subsequent orthogonality reward terms.

[0188] In addition to the Pearson correlation coefficient, the overall statistical correlation indicators... It can also be obtained from Spearman correlation coefficient, mutual information normalized value, distance correlation coefficient or other statistical dependence measures.

[0189] Step S7: Calculate the orthogonality reward term based on the orthogonality index, the first deception confidence level, and the second deception confidence level. This reward term is used to enhance the credibility of simultaneous high-confidence alarms from two experts in subsequent fusion, while suppressing false alarms caused by anomalies from a single expert.

[0190] Orthogonal reward terms are defined as:

[0191] (32)

[0192] in, express Orthogonality reward items for each window, Indicates the first The first level of deception confidence for each window. Indicates the first The second deception confidence level of the window. This is a two-expert consensus function used to quantify the degree of consistency between the outputs of two experts in terms of "simultaneously high confidence." The function output is large when both are high and the difference between them is small; the function output is small when only one expert sub-model outputs a high deception confidence while the other outputs a low deception confidence. In this embodiment, The function is implemented as follows:

[0193] (33)

[0194] in, This indicates that the product is larger when both confidence levels are high simultaneously; It represents the absolute difference between two confidence levels, used to measure the degree of consistency between expert outputs; This represents the consistency penalty factor, which takes a maximum of 1 when two confidence levels are equal, and decreases as the difference increases. (The rest of the text is incomplete and likely refers to a separate topic.) The function's range of values ​​is The maximum value of 1 is taken when both confidence levels are 1 and equal, and the minimum value of 0 is taken when either confidence level is 0.

[0195] The orthogonality reward term effectively utilizes the complementary information between two physically orthogonal detection dimensions, improving the detection reliability of deception attacks while reducing interference from single-dimensional environments. Through this orthogonality reward term, when two detection dimensions—the signal layer and the data layer—with different physical sources and weak statistical correlation, simultaneously indicate deception, the final deception probability gains an additional gain. When only a single dimension is abnormal, the orthogonality reward term is smaller, thereby reducing the risk of false alarms caused by multipath propagation, occlusion, vibration, or short-term sensor noise.

[0196] Step S8: Calculate the final deception probability based on the first weight, the second weight, the first deception confidence, the second deception confidence, and the orthogonality reward term, and execute the three-level hierarchical response strategy based on the final deception probability.

[0197] The final probability of deception is calculated as follows:

[0198] (34)

[0199] in, Indicates the first The final probability of deception for each window. Indicates the first Fusion weights of signal layer experts in each window This indicates the first level of confidence in deception. Indicates the first The fusion weight of data layer experts in each window This indicates the second level of confidence in deception. Indicates the first Orthogonality reward items for each window, This represents the orthogonality gain factor, a positive constant, typically ranging from 0.1 to 0.3, used to adjust the strength of the influence of the orthogonality reward term on the final probability; This represents a range mapping function that ensures the weighted sum within the parentheses falls within the interval [0,1].

[0200] This embodiment uses a clipping function: if the input is greater than 1, it takes the value 1; if the input is less than 0, it takes the value 0. Through this final deception probability calculation method, this invention does not simply average the outputs of the two expert sub-models, but rather, based on dynamic gating fusion, introduces a positive interactive complementary relationship between the signal layer and the data layer to correct the deception probability.

[0201] Set high threshold and low threshold As a preset constant, satisfying Based on the final probability of deception Implement a three-tiered response:

[0202] Level 1 (High Confidence Deception): When When the system detects a GNSS spoofing attack, it will perform the following actions: (1) trigger an audible and visual alarm signal to notify the ground station or flight control system; (2) mark the current and subsequent GNSS data as untrusted and suspend the use of GNSS information for combined navigation; (3) immediately switch the navigation system to pure inertial navigation mode (if possible, combined with visual odometry or barometer assistance); (4) activate the preset emergency safety strategy, including but not limited to automatic hovering and waiting, returning along the original route, landing in the nearest safe area, or executing the pre-defined fault protection procedure.

[0203] Level 2 (Suspicious Status): When When the system detects a suspicious state, it does not immediately trigger an alarm, but takes the following preventative measures: (1) Suspends the use of current and subsequent GNSS data for closed-loop Kalman filtering correction of the IMU to avoid potential deceptive information contaminating the inertial navigation calculation; (2) Reduces the step size of the sliding detection window from the default value. shortened to (In this embodiment, the time is shortened from 5 seconds to 2.5 seconds) to improve the detection time resolution of subsequent windows, so as to monitor the changing trend of deception probability more intensively and facilitate the rapid confirmation or elimination of deception attacks.

[0204] Level 3 (Normal State): When When the condition is determined to be normal, the system continues to use GNSS data for integrated navigation closed-loop correction and stores the feature information of the current window (including state vector, expert output, orthogonality reward, etc.) as candidate normal samples in the rolling sample buffer for subsequent incremental online learning.

[0205] In step S9, the detection window samples that are determined to be in a normal state are written into the rolling sample buffer. When the number of samples in the buffer reaches the preset trigger threshold, only the parameters of the gated arbitration network are updated in a limited incremental manner, keeping the parameters of the first expert sub-model and the second expert sub-model unchanged.

[0206] Considering that sensor noise distribution may slowly drift with changes in temperature, vibration, and other factors during drone flight, the performance of offline pre-trained model parameters may degrade under new environments. Therefore, a secure incremental online learning mechanism is designed.

[0207] When step S8 determines that the current window is in a normal state (i.e.) When a window's complete information is encountered, it is encapsulated into a sample entry and added to the rolling sample buffer. The buffer is managed using a first-in, first-out (FIFO) queue structure with a preset maximum capacity. When the number of samples in the buffer reaches Before adding a new sample, remove the oldest sample from the head of the queue and then add the new sample to the tail.

[0208] When the number of samples in the buffer reaches a preset trigger threshold At any given time, a micro-incremental update is triggered. After the update is complete, the buffer is cleared, and the accumulation of the next batch of normal samples begins again. The key to micro-incremental updates is the safety constraint: only samples that have been determined to be trustworthy by normal criteria are used during the micro-incremental update phase.

[0209] For each sample in the buffer, freeze the signal expert and data expert parameters, and only store the state vector. The input is given to the gating network to obtain the current expert fusion weights, and the final deception probability is calculated by combining the fixed outputs of the two experts. Since the buffer samples are all considered as trustworthy normal samples and their pseudo-labels are set to 0, the mean squared error between the final deception probability and the normal label is used as the loss function, and only the gating network parameters are adjusted. and Perform a small learning rate update.

[0210] S9-1, calculate the current gating weight.

[0211] For each sample Gated input vector:

[0212] (35)

[0213] in, The flight speed of the drone; For IMU credibility; This refers to the quality indicators of GNSS signals.

[0214] The gated arbitration network generates dynamic fusion weights between the two experts based on their state vectors.

[0215] (36)

[0216] (37)

[0217] in, For the first Fusion weights of experts for each sample signal layer For the first The fusion weights of experts in each sample data layer. This is the weight matrix of the gated network; For gating network bias terms; It is the sigmoid activation function.

[0218] S9-2, calculate the final deception probability of each sample under the current gating parameters.

[0219] For the current sample, the first expert submodel and the second expert submodel respectively output the deception probability. and The final probability of fusion deception is:

[0220] (38)

[0221] in, This is a truncation function. It is an orthogonality gain factor. To perform the first under the current gating parameters The probability of deception predicted for a normal sample.

[0222] S9-3, Construct the loss function.

[0223] Since all samples in the buffer have passed the normal state determination, they are assigned pseudo-labels. Mean Squared Error (MSE) is used as the loss function:

[0224] (39)

[0225] in, For incremental update losses in the gating network, For the first The predicted final deception probability for a normal sample. It is a pseudo-tag. This represents the number of trusted samples in the buffer that participate in the update.

[0226] The loss function encourages the gating network to adjust the weight allocation so that the fusion output of the two experts (plus the reward term) on normal samples can be kept as low as possible, that is, to reduce false alarms in normal conditions.

[0227] S9-4, Gradient descent update.

[0228] The gating network parameters are updated using a gradient descent algorithm with a small learning rate.

[0229] (40)

[0230] (41)

[0231] in, This is the incremental learning rate.

[0232] Each incremental update process does not perform a single-step gradient descent, but rather a finite number of iterations. This ensures that the parameter adjustment range is controlled, avoiding drastic changes in the model due to short-term environmental fluctuations. After each micro-incremental update, the rolling sample buffer is cleared, and then the normal detection process is returned to wait for the next round of normal sample accumulation. A new incremental update will be triggered after that.

[0233] Through the above mechanism, the gated arbitration network can continuously optimize the expert weight allocation strategy by utilizing long-term accumulated reliable normal samples, enabling the system to gradually adapt to new flight environments and sensor states. This effectively reduces the false alarm rate and improves long-term operational stability and robustness while ensuring that the deception detection capability does not decline.

[0234] Experimental verification

[0235] The experiment used publicly released GNSS smart terminal road data as the foundation. This data includes typical scenarios such as open highways, open urban roads, obstructed highways, and obstructed urban roads, reflecting the normal variation patterns of GNSS signals under different road obstruction, multipath, and motion conditions. Each trajectory includes a continuous time index, GNSS observation statistics, navigation solution results, and road scene identifiers. Since this publicly available data is not specifically designed for UAV GNSS spoofing experiments and does not fully include receiver AGC, correlator multi-branch outputs, and real IMU zero-bias observations, this embodiment uses the GNSS signal statistics and navigation kinematic statistics available in the publicly available data as representative implementations of the corresponding feature families.

[0236] First, the continuous trajectory data is processed in terms of time and divided into sliding windows. Assuming the original data sampling frequency is 1Hz, this embodiment sets the sliding detection window length T to 20s and the window step size ΔT to 5s. Therefore, each sliding detection window contains 20 epochs, with an overlap of 15 epochs between adjacent windows. For each sliding detection window, its start time, end time, start index, and end index are recorded, and this window serves as the basic processing unit for subsequent feature extraction, scoring subspace construction, expert judgment, and real-time detection.

[0237] To verify the necessity of the dual-expert-gated fusion structure of this invention, a direct concatenation comparison experiment was further conducted. This experiment used the same training samples, test samples, and window-level input features as the method of this invention. Instead of distinguishing between the signal layer scoring subspace and the data layer scoring subspace, the two were directly concatenated into a unified feature vector. The direct concatenation model was trained using a standard multilayer perceptron binary classifier, with the input being the directly concatenated feature vector and the output being the deception probability. Before training, each dimension of the features was standardized. The methods for dividing the training and test sets, constructing deception samples, and evaluating metrics were all consistent with the method of this invention.

[0238] This comparative experiment demonstrates whether directly inputting signal layer features and data layer features into a single classifier can fully utilize the complementary relationship between the two types of features. The experimental results are as follows: Figure 3 As shown, compared to the direct splicing model, this invention models signal layer experts and data layer experts separately, and combines them with a gated arbitration network and orthogonal reward terms to make more effective use of the positive interactive complementarity between signal layer anomalies and data layer anomalies.

[0239] The above embodiments are merely preferred examples of the present invention and are not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Therefore, any simple modifications, equivalent changes, and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention should fall within the protection scope of the present invention.

Claims

1. A GNSS spoofing detection method of orthogonal anomaly score and incremental gate fusion, characterized in that, Includes the following steps: Step S1: Real-time acquisition of raw GNSS receiver observation data, GNSS positioning calculation results, and inertial measurement unit (IMU) measurement data of the UAV under test during its flight. Step S2: Set a sliding detection window of length T. Within each sliding detection window, perform time synchronization and preprocessing on the collected data, and construct basic anomaly indicators for the signal layer and basic anomaly indicators for the data layer respectively. Step S3: Based on the normal state baseline and the direction of index anomalies, convert the basic anomaly index of the signal layer into the orthogonal anomaly scoring subspace of the signal layer, and convert the basic anomaly index of the data layer into the orthogonal anomaly scoring subspace of the data layer. Step S4: Input the orthogonal anomaly scoring subspace of the signal layer into the first expert sub-model, and obtain the first deception confidence after multi-branch coding and branch weight fusion; The orthogonal anomaly scoring subspace of the data layer is input into the second expert submodel, and the second deception confidence is obtained after multi-branch encoding and branch weight fusion. Step S5: Construct a state vector based on the current flight speed and GNSS observation environment, input the state vector into the gated arbitration network, and dynamically calculate the first fusion weight of the first expert sub-model and the second fusion weight of the second expert sub-model. Step S6: Determine the orthogonality index based on the statistical correlation between the signal layer orthogonal anomaly scoring subspace and the data layer orthogonal anomaly scoring subspace under normal flight conditions; Step S7: Calculate the orthogonality reward item based on the orthogonality index, the first deception confidence level, and the second deception confidence level; Step S8: Calculate the final deception probability based on the first fusion weight, the second fusion weight, the first deception confidence, the second deception confidence, and the orthogonality reward term, and execute the three-level hierarchical response strategy based on the final deception probability. In step S9, the detection window samples that are determined to be in a normal state are written into the rolling sample buffer. When the number of samples in the buffer reaches the preset trigger threshold, only the parameters of the gated arbitration network are updated in a limited incremental manner, keeping the parameters of the first expert sub-model and the second expert sub-model unchanged.

2. The GNSS spoofing detection method of claim 1, wherein, In step S2, the basic anomaly indicators of the signal layer include one or more of the following: received power cross-channel dispersion characteristics, code observation and carrier observation physical consistency characteristics, observation satellite number and geometric strength characteristics, and Doppler frequency shift dispersion characteristics; the basic anomaly indicators of the data layer include one or more of the following: position change trend slope characteristics, velocity change trend slope characteristics, position residual mean absolute deviation characteristics, and velocity and position ratio consistency characteristics.

3. The GNSS spoofing detection method of orthogonal abnormal score and delta gating fusion according to claim 2, characterized in that, In step S3, the signal layer basic anomaly indicators are converted into a signal layer orthogonal anomaly scoring subspace, and the data layer basic anomaly indicators are converted into a data layer orthogonal anomaly scoring subspace. Specifically, the statistical distribution parameters of each basic anomaly indicator are estimated based on historical data under normal flight conditions, and each indicator is converted into a standardized deviation relative to the normal baseline. The standardized deviations corresponding to the signal layer basic anomaly indicators form the signal layer orthogonal anomaly scoring subspace, and the standardized deviations corresponding to the data layer basic anomaly indicators form the data layer orthogonal anomaly scoring subspace.

4. The GNSS spoofing detection method of orthogonal anomaly score and delta gating fusion according to claim 3, characterized in that, In step S4, the first expert sub-model divides the signal layer orthogonal anomaly scoring subspace into several signal anomaly scoring sub-vectors according to the physical process of GNSS signal reception. Each signal anomaly scoring sub-vector is input into the corresponding lightweight branch encoder to obtain the branch latent vector. The branch weight is calculated based on the branch latent vector, and the branch latent vectors are weighted and fused to obtain the signal layer fused latent vector. The first deception confidence is output from the signal layer fused latent vector. The second expert sub-model divides the data layer orthogonal anomaly scoring subspace into several data anomaly scoring sub-vectors according to the source of kinematic consistency, and outputs the second deception confidence in the same way.

5. The GNSS spoofing detection method of orthogonal anomaly score and delta gating fusion according to claim 4, characterized in that, In step S5, the state vector includes flight speed state index, inertial calculation reliability index, and GNSS observation quality index. The state vector The input gate arbitration network calculates the fusion weight corresponding to the first expert sub-model: wherein, denotes the fusion weight of the first expert sub-model in the th window; denotes a weight parameter of the gating arbitration network; denotes a bias parameter of the gating arbitration network; denotes the state vector of the th window, denotes a sigmoid function; The fusion weights corresponding to the second expert sub-model are: in, Indicates the first The fusion weights of the second expert sub-model in each window; Indicates the first The fusion weights of the first expert sub-model in each window.

6. The GNSS spoofing detection method based on orthogonal anomaly scoring and incremental gating fusion according to claim 5, characterized in that, In step S6, the orthogonality index is calculated by measuring the overall statistical correlation between the signal layer orthogonal anomaly scoring subspace and the data layer orthogonal anomaly scoring subspace. The orthogonality index is obtained. The overall statistical correlation index It is obtained by any one of the statistical dependence measures, such as Pearson correlation coefficient, Spearman correlation coefficient, mutual information normalized value, or distance correlation coefficient.

7. The GNSS spoofing detection method based on orthogonal anomaly scoring and incremental gating fusion according to claim 6, characterized in that, In step S7, the formula for calculating the orthogonality reward term is: in, express Orthogonality reward items for each window, An orthogonality index representing the orthogonality between the signal layer orthogonal anomaly scoring subspace and the data layer orthogonal anomaly scoring subspace. Indicates the first The first level of deception confidence for each window. Indicates the first The second deception confidence level of the window. This is a two-expert consensus function.

8. The GNSS spoofing detection method based on orthogonal anomaly scoring and incremental gating fusion according to claim 7, characterized in that, In step S8, the final deception probability is calculated as follows: in, Indicates the first The final probability of deception for each window. Indicates the first Fusion weights of signal layer experts in each window This indicates the first level of confidence in deception. Indicates the first The fusion weight of data layer experts in each window This indicates the second level of confidence in deception. Indicates the first Orthogonality reward items for each window, This represents the orthogonality gain factor. This represents a range mapping function.

9. The GNSS spoofing detection method based on orthogonal anomaly scoring and incremental gating fusion according to claim 8, characterized in that, In step S8, a high threshold is set. and low threshold As a preset constant, satisfying The three-level hierarchical response strategy is specifically as follows: when the final deception probability... If the system is determined to be in a high-confidence deception state, an alarm will be triggered and the system will switch to pure inertial navigation mode; when When the condition is deemed suspicious, GNSS closed-loop correction of the IMU is suspended and the sliding detection window step size is shortened; when When the condition is normal, continue to use GNSS data for integrated navigation closed-loop correction, and store the current window information in the rolling sample buffer.

10. The GNSS spoofing detection method based on orthogonal anomaly scoring and incremental gating fusion according to claim 8, characterized in that, In step S9, the restricted incremental update specifically involves: for samples in the rolling sample buffer that are determined to be in a normal state, freezing all parameters of the first expert sub-model and the second expert sub-model, using the pseudo-labels of normal samples as supervision signals, and updating the weight parameters and bias parameters of the gated arbitration network using a small learning rate gradient descent algorithm with the sole objective of reducing the final deception probability; and clearing the rolling sample buffer after each incremental update.