Security evolution prediction for low-altitude collaborative tasks based on multi-source behavior modeling

Chen Yingyu, Tang Guiyuan, Zhang Zhiwei

Integrated Circuits and Embedded Systems ›› 2026, Vol. 26 ›› Issue (10) : 34-44.

PDF(3967 KB)
PDF(3967 KB)
Integrated Circuits and Embedded Systems ›› 2026, Vol. 26 ›› Issue (10) : 34-44. DOI: 10.20193/j.ices2097-4191.2026.0058
Special Issue on Air-space Intelligent Connectivity: Innovative Research on Integrated Circuits and Airborne Systems for the Low-altitude Economy

Security evolution prediction for low-altitude collaborative tasks based on multi-source behavior modeling

Author information +
History +

Abstract

To address the problems of complex multi-node relationships, weak early abnormal signals, and difficulty in timely attack warning in low-altitude collaborative tasks, this paper proposes a security evolution prediction method based on execution-communication composite behavior modeling. The method constructs an execution-communication composite task behavior graph from normal task operation data, provides a unified representation of multi-source behaviors such as control execution, task resource access, link interaction, status feedback, and task results, and learns a task propagation baseline. In the online stage, the current suspicious behavior is taken as input to construct an abnormal propagation context, screen candidate affected nodes, and score and rank candidate propagation paths, thereby predicting task objects and propagation paths that may be affected subsequently. Substitute validation based on the CICAPT-IIoT 2024 dataset shows that the proposed method achieves a warning precision of 78.35%, an attack episode coverage of 66.67%, an average of 1.40 false alarms per episode, and an average lead-step ratio of 96.7% for the first valid warning relative to the attack objective completion point. The results indicate that the method can provide early warnings for most attack processes without using future attack information, and can provide support for anomaly isolation, link adjustment, and task replanning in low-altitude collaborative tasks.

Key words

low-altitude economy / low-altitude collaborative task / security evolution prediction / execution-communication composite behavior graph / task propagation baseline

Cite this article

Download Citations
Chen Yingyu , Tang Guiyuan , Zhang Zhiwei. Security evolution prediction for low-altitude collaborative tasks based on multi-source behavior modeling[J]. Integrated Circuits and Embedded Systems. 2026, 26(10): 34-44 https://doi.org/10.20193/j.ices2097-4191.2026.0058

References

[1]
Xinhua. Low-altitude economy soars as China's new growth engine[EB/OL]. (2025-10-20)[2026-08-05].
[2]
Viasat Inc. KA-SAT network cyber attack overview[EB/OL]. (2022-03-30)[2026-08-05].
[3]
Alrefaei F, Alzahrani A, Song H, et al. A survey on the jamming and spoofing attacks on the unmanned aerial vehicle networks[C]// 2022 IEEE International IOT,Electronics and Mechatronics Conference (IEMTRONICS). Piscataway:IEEE, 2022:1-7.
[4]
Choudhary G, Sharma V, You I, et al. Intrusion detection systems for networked unmanned aerial vehicles:a survey[C]// 2018 14th International Wireless Communications & Mobile Computing Conference (IWCMC).Piscataway:IEEE, 2018:560-565.
[5]
Hu F, Wang Q, Shao Het al. Anomaly detection of UAV state data based on single-class triangular global alignment kernel extreme learning machine[J]. Computer Modeling in Engineering & Sciences, 2023, 136(3):2405-2424.
[6]
Hassler S C, Mughal U A, Ismail M. Cyber-physical intrusion detection system for unmanned aerial vehicles[J]. IEEE Transactions on Intelligent Transportation Systems, 2024, 25(6):6106-6117.
[7]
Viana J, Farkhari H, Campos L M, et al. Two methods for jamming identification in UAV networks using new synthetic dataset[C]// 2022 IEEE 95th Vehicular Technology Conference (VTC2022-Spring).Piscataway:IEEE, 2022:1-6.
[8]
Mykytyn P, Brzozowski M, Dyka Z, et al. GPS-spoofing attack detection mechanism for UAV swarms[C]// 2023 12th Mediterranean Conference on Embedded Computing (MECO).Piscataway:IEEE, 2023:1-8.
[9]
Sorbelli f B, Conti M, Pinotti C M, et al. UAVs path deviation attacks: survey and research challenges[C]// 2020 IEEE International Conference on Sensing,Communication and Networking (SECON Workshops).Piscataway:IEEE, 2020:1-6.
[10]
Husák M, Komárková J, Bou-harb E, et al. Survey of attack projection, prediction, and forecasting in cyber security[J]. IEEE Communications Surveys & Tutorials, 2019, 21(1):640-660.
[11]
Chen L, Zhang T, Ma Y Y, et al. A Bayesian-attack-graph-based security assessment method for power systems[J]. Electronics, 2024, 13(13):2628.
[12]
Albasheer H, Siraj m M, Mubarakali A, et al. Cyber-attack prediction based on network intrusion detection systems for alert correlation techniques: a survey[J]. Sensors, 2022, 22(4):1494.
[13]
Bilot T, El madhoun N, AL AGHA K, et al. Graph neural networks for intrusion detection: a survey[J]. IEEE Access, 2023, 11:49114-49139.
[14]
Han X, Pasquier T, Seltzer M. Provenance-based intrusion detection: opportunities and challenges[C/OL]// 10th USENIX Workshop on the Theory and Practice of Provenance (TaPP 2018). London:USENIX Association,2018[2026-08-05].
[15]
Ghiasvand E, Ray S, Iqbal S, et al. Resilience against APTs: a provenance-based IIoT dataset for cybersecurity research[C]// Mobile and Ubiquitous Systems: Computing, Networking and Services:21st EAI International Conference, MobiQuitous 2024.Cham:Springer, 2026:121-144.
[16]
Li S F, Dong F, Xiao X S, et al. NODLINK:an online system for fine-grained APT attack detection and investigation[C]// Proceedings of the Network and Distributed System Security Symposium. Reston: Internet Society, 2024.
[17]
Jiang B X, Bilot T, El madhoun N, et al. ORTHRUS: achieving high quality of attribution in provenance-based intrusion detection systems[C]// 34th USENIX Security Symposium. Berkeley: USENIX Association, 2025:7173-7192.
PDF(3967 KB)

Accesses

Citation

Detail

Sections
Recommended

/

〈 〉