基于多源行为建模的低空协同任务安全演化预测方法

陈莹玉, 汤贵源, 张志为

集成电路与嵌入式系统 ›› 2026, Vol. 26 ›› Issue (10) : 34-44.

PDF(3967 KB)
PDF(3967 KB)
集成电路与嵌入式系统 ›› 2026, Vol. 26 ›› Issue (10) : 34-44. DOI: 10.20193/j.ices2097-4191.2026.0058
空天智联专刊:面向低空经济的集成电路与机载系统创新研究

基于多源行为建模的低空协同任务安全演化预测方法

作者信息 +

Security evolution prediction for low-altitude collaborative tasks based on multi-source behavior modeling

Author information +
文章历史 +

摘要

针对低空协同任务中多节点关系复杂、早期异常信号较弱、攻击难以及时预警等问题,提出一种基于执行-通信复合行为建模的低空协同任务安全演化预测方法。该方法利用正常任务运行数据构建执行-通信复合任务行为图,统一表示控制执行、任务资源访问、链路交互、状态反馈和任务结果等多源行为,并学习任务传播基线。在线阶段,以当前可疑行为为输入,构造异常传播上下文,筛选候选受影响节点,对候选传播路径进行评分和排序,从而预测后续可能受影响的任务对象和传播路径。基于CICAPT-IIoT 2024数据集的替代验证结果表明,该方法在在线预警任务中的预警准确率为78.35%,攻击片段覆盖率为66.67%,平均每个攻击片段产生1.40条误报,首次有效预警相对于攻击目标达成点的平均提前步率为96.7%。结果说明,该方法能够在不使用未来攻击信息的条件下对多数攻击过程形成提前预警,可为低空协同任务中的异常隔离、链路调整和任务重规划提供参考。

Abstract

To address the problems of complex multi-node relationships, weak early abnormal signals, and difficulty in timely attack warning in low-altitude collaborative tasks, this paper proposes a security evolution prediction method based on execution-communication composite behavior modeling. The method constructs an execution-communication composite task behavior graph from normal task operation data, provides a unified representation of multi-source behaviors such as control execution, task resource access, link interaction, status feedback, and task results, and learns a task propagation baseline. In the online stage, the current suspicious behavior is taken as input to construct an abnormal propagation context, screen candidate affected nodes, and score and rank candidate propagation paths, thereby predicting task objects and propagation paths that may be affected subsequently. Substitute validation based on the CICAPT-IIoT 2024 dataset shows that the proposed method achieves a warning precision of 78.35%, an attack episode coverage of 66.67%, an average of 1.40 false alarms per episode, and an average lead-step ratio of 96.7% for the first valid warning relative to the attack objective completion point. The results indicate that the method can provide early warnings for most attack processes without using future attack information, and can provide support for anomaly isolation, link adjustment, and task replanning in low-altitude collaborative tasks.

关键词

低空经济 / 低空协同任务 / 安全演化预测 / 执行-通信复合行为图 / 任务传播基线

Key words

low-altitude economy / low-altitude collaborative task / security evolution prediction / execution-communication composite behavior graph / task propagation baseline

引用本文

导出引用
陈莹玉, 汤贵源, 张志为. 基于多源行为建模的低空协同任务安全演化预测方法[J]. 集成电路与嵌入式系统. 2026, 26(10): 34-44 https://doi.org/10.20193/j.ices2097-4191.2026.0058
Chen Yingyu, Tang Guiyuan, Zhang Zhiwei. Security evolution prediction for low-altitude collaborative tasks based on multi-source behavior modeling[J]. Integrated Circuits and Embedded Systems. 2026, 26(10): 34-44 https://doi.org/10.20193/j.ices2097-4191.2026.0058
中图分类号: TP872 (远距离控制和信号、远距离控制和信号系统)   

参考文献

[1]
Xinhua. Low-altitude economy soars as China's new growth engine[EB/OL]. (2025-10-20)[2026-08-05].
[2]
Viasat Inc. KA-SAT network cyber attack overview[EB/OL]. (2022-03-30)[2026-08-05].
[3]
Alrefaei F, Alzahrani A, Song H, et al. A survey on the jamming and spoofing attacks on the unmanned aerial vehicle networks[C]// 2022 IEEE International IOT,Electronics and Mechatronics Conference (IEMTRONICS). Piscataway:IEEE, 2022:1-7.
[4]
Choudhary G, Sharma V, You I, et al. Intrusion detection systems for networked unmanned aerial vehicles:a survey[C]// 2018 14th International Wireless Communications & Mobile Computing Conference (IWCMC).Piscataway:IEEE, 2018:560-565.
[5]
Hu F, Wang Q, Shao Het al. Anomaly detection of UAV state data based on single-class triangular global alignment kernel extreme learning machine[J]. Computer Modeling in Engineering & Sciences, 2023, 136(3):2405-2424.
[6]
Hassler S C, Mughal U A, Ismail M. Cyber-physical intrusion detection system for unmanned aerial vehicles[J]. IEEE Transactions on Intelligent Transportation Systems, 2024, 25(6):6106-6117.
[7]
Viana J, Farkhari H, Campos L M, et al. Two methods for jamming identification in UAV networks using new synthetic dataset[C]// 2022 IEEE 95th Vehicular Technology Conference (VTC2022-Spring).Piscataway:IEEE, 2022:1-6.
[8]
Mykytyn P, Brzozowski M, Dyka Z, et al. GPS-spoofing attack detection mechanism for UAV swarms[C]// 2023 12th Mediterranean Conference on Embedded Computing (MECO).Piscataway:IEEE, 2023:1-8.
[9]
Sorbelli f B, Conti M, Pinotti C M, et al. UAVs path deviation attacks: survey and research challenges[C]// 2020 IEEE International Conference on Sensing,Communication and Networking (SECON Workshops).Piscataway:IEEE, 2020:1-6.
[10]
Husák M, Komárková J, Bou-harb E, et al. Survey of attack projection, prediction, and forecasting in cyber security[J]. IEEE Communications Surveys & Tutorials, 2019, 21(1):640-660.
[11]
Chen L, Zhang T, Ma Y Y, et al. A Bayesian-attack-graph-based security assessment method for power systems[J]. Electronics, 2024, 13(13):2628.
[12]
Albasheer H, Siraj m M, Mubarakali A, et al. Cyber-attack prediction based on network intrusion detection systems for alert correlation techniques: a survey[J]. Sensors, 2022, 22(4):1494.
[13]
Bilot T, El madhoun N, AL AGHA K, et al. Graph neural networks for intrusion detection: a survey[J]. IEEE Access, 2023, 11:49114-49139.
[14]
Han X, Pasquier T, Seltzer M. Provenance-based intrusion detection: opportunities and challenges[C/OL]// 10th USENIX Workshop on the Theory and Practice of Provenance (TaPP 2018). London:USENIX Association,2018[2026-08-05].
[15]
Ghiasvand E, Ray S, Iqbal S, et al. Resilience against APTs: a provenance-based IIoT dataset for cybersecurity research[C]// Mobile and Ubiquitous Systems: Computing, Networking and Services:21st EAI International Conference, MobiQuitous 2024.Cham:Springer, 2026:121-144.
[16]
Li S F, Dong F, Xiao X S, et al. NODLINK:an online system for fine-grained APT attack detection and investigation[C]// Proceedings of the Network and Distributed System Security Symposium. Reston: Internet Society, 2024.
[17]
Jiang B X, Bilot T, El madhoun N, et al. ORTHRUS: achieving high quality of attribution in provenance-based intrusion detection systems[C]// 34th USENIX Security Symposium. Berkeley: USENIX Association, 2025:7173-7192.

责任编辑: 薛士然
PDF(3967 KB)

Accesses

Citation

Detail

段落导航
相关文章

/

〈 〉