发表机构
Universidad de Extremadura(埃斯特雷马杜拉大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对城市行人计数系统中隐蔽虚假数据注入攻击,提出物理约束数字孪生方法,利用流量守恒残差与自适应一致性校准检测异常,在墨尔本数据上实现0.54攻击裕度。
AI 中文摘要
城市行人计数系统如今为经济指标、规划决策和安全运营提供数据支持,然而基于这些系统构建的数字孪生体将输入数据流视为地面真值。我们研究了当数据并非地面真值时会发生什么。我们形式化了城市规模行人感知中的隐蔽虚假数据注入问题,在此场景中,从潜在流量到观测的映射远比电力网络和水网中已表征的隐蔽性场景更为秩亏。我们的数字孪生体估计行人街道图上的有向流量,通过学习的图局部化增益同化计数数据,并针对耦合计量与未计量路段的流量守恒残差进行训练。检测方法将创新残差与该守恒残差相结合,报警阈值通过自适应一致性校准而非人工设定。为衡量物理约束带来的收益,我们定义了攻击裕度,即在白盒对手直接通过数字孪生体优化的情况下,估计流量场最坏情况损坏的相对减少量。在墨尔本六年的数据上,针对单个被攻陷设备,攻击裕度达到0.54;当三分之一的设备被攻陷时,攻击裕度降至0.19,而该网络中仅有1.18%的可步行路段被计量。将街道图替换为距离图后,攻击裕度骤降至0.09,这表明收益来自守恒定律而非局部性。
英文摘要
City pedestrian counting systems now feed economic indicators, planning decisions and safety operations, yet the twins built on top of them treat the incoming stream as ground truth. We study what happens when it is not. We formalise stealthy false data injection for city-scale pedestrian sensing, where the map from latent flow to observation is far more rank deficient than in the power and water networks for which stealth has been characterised. Our twin estimates directed flows on the pedestrian street graph, assimilates counts through a learned graph-localised gain, and is trained against a flow conservation residual that couples metered and unmetered segments. Detection combines the innovation with that residual, and the alarm threshold is set by adaptive conformal calibration rather than by hand. To measure what the physics buys, we define the attack margin, the relative reduction in worst-case corruption of the estimated flow field, achieved against a white-box adversary that optimises directly through the twin. On six years of Melbourne data the margin reaches 0.54 against a single compromised device and falls to 0.19 when a third of the fleet is compromised, on a network where only 1.18 per cent of walkable segments are metered. Replacing the street graph by a distance graph collapses it to 0.09, which shows that the gain comes from the conservation law rather than from locality.
Comments16 Pages, 4 Figures, 8 Tables