Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

68 results about "Spoofing attack" patented technology

In the context of information security, and especially network security, a spoofing attack is a situation in which a person or program successfully identifies as another by falsifying data, to gain an illegitimate advantage.

Intelligent system and method for detecting and relieving Beidou signal deception for Internet of Vehicles

The invention relates to the technical field of Internet of Vehicles information security, and discloses an Internet of Vehicles-oriented Beidou signal spoofing detection and mitigation intelligent system and method, and the system comprises a multi-dimensional data sensing and preprocessing module, a deep learning joint detection module, and a security mitigation and reputation management module. The method comprises the following steps: firstly, extracting a physical layer signal feature and a network flow stability feature and generating a multi-dimensional feature vector; secondly, performing feature compression and preliminary screening by using an auto-encoder, analyzing a time sequence evolution rule through a long-short-term memory network, and outputting a judgment probability; and finally, executing hierarchical defense according to the judgment probability, responding to local threats by dynamically adjusting a measurement noise covariance matrix or a hard isolation strategy, evaluating network node reputation based on a path damage index, and adding abnormal nodes into a dynamic blacklist. Through the multi-dimensional feature fusion and deep learning cascade architecture, the spoofing attack detection accuracy is improved, and the diffusion of false information in the Internet of Vehicles is effectively blocked.
Owner:GANSU ELECTRIC POWER INFORMATION COMM

Positioning device, positioning method, and positioning program

To provide a positioning device that can reduce the risk of decreased positioning accuracy in an environment of spoofing attacks. [Solution] A positioning device comprising: a receiving unit that receives a first satellite signal in a first frequency band and a second satellite signal in a second frequency band different from the first frequency band transmitted from a first satellite; a positioning unit; a determination unit that compares the value of a predetermined parameter included in the first satellite information of the first satellite based on the first satellite signal with the value of the predetermined parameter included in the second satellite information of the first satellite based on the second satellite signal to determine whether or not the first satellite is spoofed; and a control unit that controls the positioning unit so as not to perform positioning using the first satellite information and the second satellite information of the first satellite when the determination unit determines that the first satellite is spoofed.
Owner:SEIKO EPSON CORP

Voice anti-cheating method and system based on double interactive query

The invention provides a voice anti-cheating method and system based on double interactive query, and relates to the technical field of voice recognition. The invention provides an audio understanding model based on double interactive query, aiming at the technical problem that the performance and the efficiency of deep counterfeit voice detection cannot be well considered in the prior art. According to the model, a local mode branch in a double-branch processing module based on cross attention is used for extracting local acoustic artifacts in forged voice, a global context branch is used for capturing global context anomalies, and meanwhile, cross attention mechanisms in the global context branch and the local mode branch are symmetrical layer by layer by using a symmetric collaborative interaction mechanism, so that the local acoustic artifacts in the forged voice are extracted. The two heterogeneous branches are subjected to deep interactive fusion, and global and local representations can be mutually complemented and jointly optimized in the whole network, so that more comprehensive feature representation for forged voice is formed, and the detection precision for known and unknown spoofing attacks is improved while the complexity of the model is remarkably reduced.
Owner:INTELLIGENT MFG INST OF HFUT

Method to protect UE from GNSS spoofing attack

PCT designated stageWO2026076559A1TransmissionSecurity arrangementAlgorithmAttack
This invention focuses on an additional error cause and an attack probability metric for UE to report spoofing attack to server. While the detection algorithm on UE and the decision algorithm on server can be open for implementations, this contribution proposes to leverage server-UE authentication mechanism and calculate the attack probability metric by the number of authentication errors within a time window.
Owner:MEDIATEK INC

Adaptive filtering method based on sliding window innovation evaluation and joint constraint

The application relates to an adaptive filtering method based on sliding window innovation evaluation and joint constraint. The method comprises the following steps: calculating the innovation covariance through parallel calculation theory and the empirical innovation covariance estimated based on the sliding window, dynamically quantifying the mismatch degree of the two, and adaptively amplifying the GNSS measurement noise covariance according to the mismatch degree, so as to suppress the weight of abnormal signals in fusion. The second module is a state prediction covariance joint constraint unit, which prevents excessive convergence of filtering by introducing a dynamic forgetting factor and applying a minimum boundary constraint related to the position state to the prediction covariance matrix, thereby ensuring that the LiDAR maintains effective state correction capability within the continuous GNSS update interval. Through the synergistic effect of the above mechanisms, the method realizes early perception and active inhibition of advanced spoofing attacks, and significantly improves the positioning safety and robustness of the multi-sensor fusion system in a complex dynamic environment.
Owner:NAT UNIV OF DEFENSE TECH

Clustering consistency control method, system and equipment for multi-agent system security

The invention discloses a clustering consistency control method, system and equipment for multi-agent system safety. The method comprises the following steps: constructing a multi-agent system clustering network and a dynamic model based on external disturbance factors; obtaining communication topology between the intelligent agents based on the clustering network; the method comprises the following steps of: constructing an adaptive event triggering strategy with a memory characteristic on a clustering network, converting a system clustering consistency problem into a convergence analysis problem of an error system, then obtaining sufficient conditions for a distributed controller to meet anti-interference performance and mean square index stability through a Lyapunov-Krasovskii functional, and finally decoupling nonlinear factors to obtain an LMI condition; and solving controller gain and specified related parameters to realize security clustering consistency control of the multi-agent system in a communication resource limited and spoofing attack environment. According to the method, the consistent achievement of multi-agent system clustering and safe and stable operation under spoofing attack and disturbance network communication can be ensured.
Owner:ANHUI UNIV

Adaptive secure consensus control method for multi-agent spatio-temporal dynamic system with unknown boundary nonlinearity under mixed attack

ActiveCN121077779BMix networkConsensus control
The application discloses a method for adaptive secure consensus control of a multi-agent spatio-temporal dynamic system with unknown boundary nonlinearity under hybrid attacks, comprising the following steps: constructing a multi-agent spatio-temporal dynamic system model with unknown boundary nonlinearity and a virtual leader model; establishing a hybrid network attack model containing deception attacks and denial of service (Dos) attacks, and using an adaptive radial basis neural network to approximate the unknown boundary nonlinearity function; defining a consensus error signal to obtain a consensus state error system; designing a composite adaptive neural network secure boundary consensus control scheme, constructing a Lyapunov function for the error system, and obtaining a sufficient condition for the error system to realize mean square secure consensus control. The application effectively solves the problem that the traditional method is difficult to simultaneously cope with complex network attacks and unknown boundary nonlinear disturbances, and significantly improves the security and robustness of the system.
Owner:BEIJING UNIV OF TECH

Preemptive and perceived cross spoofing attack detection method based on systematic residual check

The invention discloses a preemption and perception cross spoofing attack detection method based on systematic residual check. The method comprises the following steps: acquiring a damaged signal subjected to a PSCS attack; performing discrete Fourier transform on the damaged signal to obtain a plurality of resource elements, and extracting a phase gradient and an amplitude deviation for each resource element; defining a non-attack state constraint function and an attack state constraint function by using the phase gradient and the amplitude deviation corresponding to each resource element, so as to express the construction of test statistics as a minimum and maximum optimization problem; a minimum and maximum optimization problem is converted into a semi-definite programming problem through a kernel tensor completion technology, and test statistics are obtained by solving the semi-definite programming problem; based on the test statistics, calculating a detection threshold according to a false alarm probability; and calculating the current test statistic of the to-be-detected signal in the current time slot, and if the current test statistic is greater than the detection threshold, judging that the PSCS attack exists, thereby realizing the effective seizing and sensing cross spoofing attack detection method.
Owner:XIDIAN UNIV

A method and system for detecting spoofing attacks / natural electromagnetic interference

The application relates to the technical field of fraud detection, and discloses a detection method and system for spoofing attacks / natural electromagnetic interference, which comprises: a first detection quantity based on absolute tracking loop output (ATLO); mobile variance filtering processing (ATLO-MV) is performed on the first detection quantity to construct a second detection quantity; and the detection probability information of the second detection quantity of ATLO-MV of multiple satellites is used to distinguish spoofing attacks, natural electromagnetic interference and no interference. Through construction of the first detection quantity based on absolute tracking loop output, subtle fluctuations in tracking loop output can be accurately captured; the second detection quantity of ATLO-MV obtained through mobile variance enhancement processing effectively improves detection sensitivity and anti-noise performance; finally, a new type of detection algorithm is constructed through multi-satellite joint processing (ATLO-MV-MSC) of ATLO-MV, the distinction between no interference, natural electromagnetic interference and spoofing attacks is realized, and the pain point of fuzzy judgment existing in traditional algorithms is solved.
Owner:SHENZHEN KUANGWEI TECH CO LTD

A method for detecting deception attacks in industrial cyber-physical systems

The application discloses a kind of industrial information physical system's deception attack detection method, comprising the following steps: step 1: the information physical system model with different security level data transmission channel is established, discrete linear time-invariant state space model is established, and the deception attack process description under this model is established;Step 2: the sparse sampling security data transmission channel is established, and the data in unreliable channel is encrypted;Step 3: residual error is constructed based on the data correlation between different channels;Step 4: the residual error change caused by deception attack is quantified, and the optimal weight matrix is established to improve the detection performance;Step 5: set detection strategy and detection threshold, calculate detection statistics, and complete deception attack detection.The application realizes deception attack detection by quantifying the change of data correlation caused by attack, and can effectively solve the problems of certain limitations of existing deception attack detection methods and application in multi-channel information physical system.
Owner:BEIHANG UNIV

Multi-source undisturbed attack detection and safe dynamic positioning method for switching unmanned ship system

The invention discloses a multi-source undisturbed attack detection and safe dynamic positioning method for switching an unmanned ship system, and the method comprises the steps: building an unmanned ship quality switching model through a hysteresis quantizer, inhibiting residual buffeting through an event triggering protocol, and transmitting a state and quality mode switching signal to a shore base; designing a multi-source undisturbed rate residual calculation model based on the state observer, and eliminating the influence of quality switching and event triggering on the residual; constructing a spoofing attack detection function, obtaining a state and modal detection result, and designing a safety controller according to the state and modal detection result; meanwhile, an event triggering and watermarking mechanism is introduced into a controller-actuator channel to resist spoofing attacks; according to the method, a closed-loop system is constructed based on a double-event triggering protocol, finally, safe dynamic positioning of the quality switching unmanned ship is achieved, detection false alarm and missing alarm caused by rate residual buffeting due to switching behaviors and data updating during triggering can be overcome, and the detection strategy is achieved to give an alarm only when a spoofing attack occurs.
Owner:DALIAN MARITIME UNIVERSITY

Liveness detection

Biometrics are increasingly used to provide authentication and / or verification of a user in many security and financial applications for example. However, “spoof attacks” through presentation of biometric artefacts that are “false” allow attackers to fool these biometric verification systems. Accordingly, it would be beneficial to further differentiate the acquired biometric characteristics into feature spaces relating to live and non-living biometrics to prevent non-living biometric credentials triggering biometric verification. The inventors have established a variety of “liveness” detection methodologies which can block either low complexity spoofs or more advanced spoofs. Such techniques may provide for monitoring of responses to challenges discretely or in combination with additional aspects such as the timing of user's responses, depth detection within acquired images, comparison of other images from other cameras with database data etc.
Owner:HAMID LAURENCE +1

A safety control method and system for smart cockpits

PendingCN122310494ARealize refined management and controlImprove reliabilityAttackTrust level
This application discloses a security control method and system for smart cockpits. The solution acquires user authentication information, historical behavior baselines, and authentication features. It continuously collects current environmental and user behavior information, dynamically determines user trust levels based on the aforementioned information, and adjusts user operation permissions in real time according to the trust level. Upon detecting a user interaction command, it acquires multimodal signals within the corresponding time window of the command and performs multi-dimensional consistency verification on the command based on authentication features. Based on the verification results and the user's current operation permissions, it determines the command execution strategy. This application's technical solution achieves precise matching of permissions and real-time risks through dynamic trust level assessment. Relying on multimodal signal verification, it accurately identifies abnormal interactions and deception attacks, achieving refined security control of interaction commands. Through the coordinated decision-making of trust level, operation permissions, and interaction verification results, it improves the reliability and adaptability of smart cockpit security control.
Owner:NEUSOFT REACH AUTOMOBILE TECH (SHENYANG) CO LTD

A GNSS spoofing detection method based on adaptive RAIM and latent space diffusion model

PendingCN122110159ASolve detection accuracySolve detection stabilityBiological modelsSatellite radio beaconingGeometric consistencyAlgorithm
The application discloses a GNSS spoofing detection method based on adaptive RAIM and hidden space diffusion model, and relates to the fields of satellite navigation and artificial intelligence.The method comprises the following steps: constructing an adaptive pseudo-range residual feature extractor, wherein the adaptive pseudo-range residual feature extractor is composed of a weight adaptive network and a weighted least squares RAIM; the weight adaptive network is constructed by a graph convolutional neural network, can adaptively correct the pseudo-range observation weight matrix of the weighted least squares RAIM, and can enhance the sensitivity of the pseudo-range residual to the geometric consistency destruction caused by spoofing; the weighted least squares RAIM processes the pseudo-range residual on the basis to extract the multi-scale trend features; constructing a hidden space diffusion model, wherein the hidden space diffusion model is trained by using the multi-scale trend features which are not spoofed, and performs spoofing detection through a state evaluation function.The application can effectively improve the detection performance of the receiver on the GNSS spoofing attack.
Owner:DALIAN MARITIME UNIVERSITY

Face video recognition method and system

The present application provides a kind of face video identification method and system, method includes: obtaining the video frame image sequence corresponding to face video, video frame image sequence is by multiple video frame images, and video frame image is obtained by frame by frame processing to face video;According to video frame image sequence, obtain the human heart rate feature and texture feature in face video;According to human heart rate feature and texture feature, determine the authenticity of face video.The system executes the method.The present application can significantly reduce the probability of identifying fake face video as real face video, can effectively prevent face spoofing attack and fake face video attack, reduce the risk of secret information leakage.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Age deception detector

PCT designated stageWO2026132573A2RadiologyImage manipulation
There is provided a computer-implemented method for detecting a spoofing attack in an image, the method comprising: receiving an image of a user; obtaining a first image portion from the image, the first image portion being less that the whole image of the user; processing the first image portion to generate a first output indicative of a first estimated human age; processing the image of the user to generate a second output indicative of a second estimated human age; and based on the first output and the second output, determine whether the image of the user comprises the spoofing attack.
Owner:YOTI HLDG LTD

An Adaptive Control Method for Cyber-Physical Systems Against Injection and Deception Attacks

ActiveCN119937516BSmall convergence radiusGuaranteed stabilityBacksteppingCyber-attack
An adaptive control method for cyber-physical systems (CPS) subjected to injection and deception attacks includes the following steps: S1: Constructing a control system model under a cyber-physical framework; S2: Defining actuator attacks when the system's sensors and actuators are subjected to adversary injection and deception attacks; S3: Defining sensor attacks when the system is subjected to sensor attacks; S4: Rewriting the system model under cyberattacks; S5: Based on the rewritten system model, obtaining the adaptive control law u using the BackStepping method; S6: Further deriving that all signals in the closed-loop system are globally bounded based on the adaptive control law u in S5, and designing a controller by introducing Nussbaum even functions and their variable derivatives. When the system is subjected to injection and deception attacks, the control parameters are adjusted to make the adjustment error arbitrarily small. This invention can ensure that the adjustment error can be arbitrarily small under injection and deception attacks by adjusting the control parameters.
Owner:XI'AN UNIVERSITY OF ARCHITECTURE AND TECHNOLOGY

Fraud attack detection method, apparatus, device, and storage medium

The present specification relates to the technical field of automatic driving, and provides a spoofing attack detection method and device, equipment and a storage medium. The method comprises: acquiring point cloud data currently collected by a laser radar of a vehicle; identifying whether an abnormal object exists in the point cloud data; when the abnormal object exists in the point cloud data, broadcasting an assistance detection request carrying point cloud data and a spatial position of the abnormal object to surrounding vehicles; receiving an assistance detection response returned by the surrounding vehicles in response to the assistance detection request; and determining whether a spoofing attack exists in the laser radar according to the assistance detection response. The embodiments of the present specification can improve the detection accuracy of spoofing attacks on the laser radar and improve the driving safety of the automatic driving vehicle.
Owner:CITY UNIV OF HONG KONG SHENZHEN RES INST

A voiceprint spoofing defense method, device and computer readable storage medium

PendingCN122372302ASound sourcesDecision model
A method, apparatus, and computer-readable storage medium for voiceprint spoofing defense include: acquiring a speech signal to be verified; extracting multi-dimensional features from the speech signal to obtain a multi-dimensional feature vector, wherein the multi-dimensional feature vector includes at least speech text content features, identity features, sound quality features representing recording or synthesis traces, liveness features representing the physiological characteristics of the sound source, and adversarial perturbation features; fusing the multi-dimensional feature vector to obtain a joint feature vector; inputting the joint feature vector into a pre-trained joint risk decision model to obtain a spoofing risk score; and determining the verification result of the speech signal to be verified based on the comparison result of the spoofing risk score and a preset threshold. This application can effectively detect multiple attack modes such as replay attacks, speech synthesis attacks, and adversarial example attacks simultaneously; and accurately detect high-quality spoofing attacks.
Owner:XIANGYANG DAAN AUTOMOBILE TEST CENT

Multi-agent system elastic consensus method and system with privacy protection capability

The invention discloses a multi-agent system elastic consensus method and system with privacy protection capability, and relates to the technical field of computers. The method comprises the steps that in an initial security window period, privacy protection of an initial state of an intelligent agent is achieved through state decomposition, sub-state mixed updating and merging operation, in an environment with spoofing attack, a conventional intelligent agent filters malicious information in a mode of sorting and removing suspicious extreme values based on a weighted mean value sub-sequence reduction algorithm, and the privacy protection of the initial state of the intelligent agent is achieved. And updating the state based on the trusted neighbor set until a consensus is reached. According to the method, the privacy of the initial state of the intelligent agent can be protected while the unconstrained spoofing attack is resisted, the communication overhead is not increased, the calculation complexity is low, the convergence speed is high, and the method is suitable for resource-limited collaborative scenes such as an unmanned aerial vehicle cluster and a wireless sensor network.
Owner:RES & DEV INST OF NORTHWESTERN POLYTECHNICAL UNIV IN SHENZHEN

A single-link manipulator system memory dynamic event trigger control method based on deception attack

ActiveCN117754564BProgramme-controlled manipulatorRobotic armMarkov transition
This invention discloses a memory-based dynamic event triggering control method for a single-link robotic arm system based on spoofing attacks. The method first establishes a Markov model of the single-link robotic arm system based on Markov jump system theory, considering a system model with a general transition rate. Next, a mode-dependent memory controller is designed to overcome the influence of spoofing attacks and external disturbances on the system. A memory-based dynamic event triggering mechanism is also designed to reduce communication transmission frequency. Compared with existing memoryless event triggering schemes, this scheme utilizes a series of recently released signals and introduces a threshold function and an internal dynamic factor, which can automatically adjust according to the triggering error. Finally, vertex separator processing is introduced to address the uncertainty in the Markov transition rate. A mode-dependent state feedback controller is designed to control the stochastic stability of a single-link robotic arm system. When applied to a single-link robotic arm system, this method ensures the normal operation of the system under spoofing attacks and disturbances.
Owner:NANJING TECH UNIV

A Capsule Network-Based Method for Detecting Finger Vein Impersonation Attacks

This paper proposes a method for detecting finger vein spoofing attacks based on capsule networks. Capsule networks are not only suitable for small-sample finger vein datasets, but also, by replacing neurons with vector-represented capsules on top of CNNs, they can better handle spatial information such as relative position and angle, enhancing the network's adaptability to finger offset and rotation scenarios. A Bayesian routing algorithm is proposed, incorporating the differential entropy of the capsules as a consideration in calculating activation values. During final classification, feature capsules with high activation probabilities and high concentration are selected, which helps improve the accuracy of classifying genuine and fake veins. By simulating the uncertainty of capsule parameters, training errors can be reduced, improving recognition accuracy.
Owner:NANJING UNIV OF POSTS & TELECOMM

RSU-based signal anomaly detection method and apparatus therefor

This invention provides an RSU-based signal anomaly detection device and method that uses a multi-object tracking algorithm to determine whether fluctuations are natural phenomena or the result of a spoofing attack. [Solution] Combined voxel data is generated by combining voxel data from lidar and radar installed at a roadside base station and 3D feature vectors from multiple cameras installed at the roadside base station, with voxels at corresponding locations. Based on the combined voxel data, the voxel at the first location where the fluctuation is detected is masked. The vectors for the masked voxel and the remaining voxels other than the masked voxel are input to a neural network to obtain predicted point information for the masked voxel. Based on the predicted point information for the masked voxel and the lidar voxel data, it is determined whether the fluctuation detected at the first location is due to abnormal activity.
Owner:AUTOCRYPT CO LTD

Spoofing determination based on reference signal received power measurements

In an aspect, a wireless node performs a first RSRP measurement of an RS-P based on a first set of samples within a first time window of an RS-P symbol or resource, and determines whether a spoofing attack is associated with RS-P based on the first RSRP measurement and one or more other RSRP measurements of one or more other sets of samples within one or more earlier time windows of the RS-P symbol or resource. The wireless node transmits, to a communications device (e.g., position estimation entity), an indication (e.g., in a measurement report) of the spoofing attack determination. The communications device performs at least one action based at least in part upon the indication of the spoofing attack determination.
Owner:QUALCOMM INC

A voice security test method and device for smart home based on voiceprint anti-counterfeiting

PendingCN122455011AAttackHome based
The application discloses a kind of intelligent home voice security test method and device based on voiceprint anti-counterfeiting, it is related to intelligent home security test technical field.The core of the device includes main control module, attack simulation module and response acquisition module.Attack simulation module generates multi-dimensional voice deception attack sample including replay, synthesis, conversion and countermeasure sample.Main control module is built-in dynamic countermeasure reinforcement learning algorithm, and dynamically generates digital domain control instruction and physical domain control instruction according to the response state of the device to be measured, wherein the physical domain control instruction directly drives the stepper motor of physical replay sub-module to carry out angle rotation, realizes the deep binding of algorithm strategy and physical hardware action.Response acquisition module comprehensively captures the state feedback of the device to be measured by multi-modal perception means.The device can further include environment simulation module and evaluation and output module to construct physical test space with specific acoustic characteristics and output quantitative evaluation report.The application first proposes a comprehensive test device combining software and hardware from the perspective of active attack test, which can comprehensively and automatically evaluate the voiceprint anti-counterfeiting performance of intelligent home voice control system and Internet of Things devices.
Owner:ZHEJIANG SHENLING TECHNOLOGY CO LTD

A method for detecting a spoofing attack based on signal quality monitoring

The present application relates to a kind of based on signal quality monitoring's deception attack detection method, belong to GNSS deception attack detection technical field.The present application is directed to the change of the coherent integration value distribution characteristics of E or L correlator caused by deception attack, in calibration phase, MLE is used to determine the coherent integration value rices distribution parameter;In evaluation phase, using the method based on Kolmogorov-Smirnov test respectively monitor the change of the correlation integration amplitude statistical characteristics of E and L correlator, respectively, the coherent integration sample of E, L correlator is established suitable detection statistics, two detection statistics are integrated, final decision is made based on OR principle.The present application is advantageous to analyze the difference of E and L coherent integration value distribution characteristics and then effectively detect the change of correlation peak symmetry, on the other hand, it is advantageous to detect the coherent integration amplitude characteristic change of E or L correlator caused by spoofing signal, can effectively solve the performance defect problem faced by traditional SQM technology, improve the performance and robustness of middle-level deception attack detection.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

A model-free adaptive microgrid frequency control method against cyber attacks

PendingCN122371176AMix networkAlgorithm
This application belongs to the field of microgrid frequency control, specifically disclosing a model-free adaptive microgrid frequency control method to resist network attacks. The method includes the following steps: considering the mixed effects of denial-of-service attacks and spoofing attacks, a system output model incorporating attack coefficients is established, modeling the microgrid frequency control system as a discrete-time nonlinear system; dynamic linearization technology is used to transform the nonlinear system into an equivalent linear data model; for the linear data model, a partial pseudo-derivative estimation algorithm is designed, and a model-free adaptive control law incorporating a decay function is designed; the time-varying partial pseudo-derivative matrix is ​​iteratively updated using the partial pseudo-derivative estimation algorithm, and based on the updated partial pseudo-derivative matrix, the control input at the current moment is calculated using the model-free adaptive control law to control the microgrid frequency. This application can achieve effective frequency control even when the microgrid frequency control system model is unknown and faces mixed network attack threats.
Owner:CHINA UNIV OF GEOSCIENCES (WUHAN)

A multi-agent system privacy protection resilient average consensus method and system

PendingCN122339785APathPingAttack
This invention discloses a privacy-preserving elastic average consensus method and system for multi-agent systems, belonging to the fields of multi-agent cooperative control and network security technology. The method includes: a privacy-preserving phase, where agents decompose their initial state into public and private sub-states, introducing free non-zero parameters to ensure the global mean remains unchanged, with only public sub-states participating in interaction, thus cutting off eavesdropping paths; and an elastic consensus phase, maintaining an enhanced local information set containing the agent's and neighbors' states, true values, attack flags, and compensation inputs, rapidly detecting based on two-hop neighbor information, calculating state deviations and dynamically compensating for malicious data, and iterating according to the average consensus rule until regular nodes converge to the arithmetic mean of the global initial state. This invention simultaneously achieves initial state privacy protection and accurate elastic average consensus under the conditions that deceptive attack nodes are not adjacent and there is no attack at the initial moment, making it suitable for high-security distributed collaborative scenarios such as smart grids, unmanned clusters, and the Industrial Internet of Things.
Owner:NINGBO INST OF NORTHWESTERN POLYTECHNICAL UNIV

Process camouflage attack detection method based on kernel object causal atlas and graph neural network

The invention discloses a process camouflage attack detection method based on a kernel object causal atlas and a graph neural network, and relates to the technical field of network security and deep learning. The invention aims to solve the problem that an existing endpoint detection system seriously depends on process names and static characteristics and is difficult to identify advanced attacks such as sequence imitation and process identity disguise. The method mainly comprises the following steps: firstly, capturing an input / output request packet (IRP) of a file system in real time through a kernel-level filter driver (Minifilter), and extracting multi-dimensional features including a process identifier, an access permission mask, an I / O control code and a file object pointer (File Object Pointer); secondly, providing a causal atlas construction technology based on a file object pointer, aggregating discrete and cross-process I / O (Input / Output) operation into a logically coherent causal chain through a shared kernel object, and forcibly associating a disguised attack fragment with system background noise; and finally, constructing a graph convolutional neural network (GCN) model, performing feature aggregation and convolution calculation on graph nodes by using a time sequence edge and a causal edge, and identifying abnormal nodes of which behavior semantics are not consistent with claimed identities. According to the method, disguising of the process PID and the name can be effectively penetrated, the attack path is precisely restored through the bottom kernel logic, and the detection accuracy and robustness of ransomware, APT attacks and file-free attacks are remarkably improved.
Owner:CHONGQING UNIV OF POSTS & TELECOMM