Exploiting Trust for Resilient Hypothesis Testing with Malicious Robots

Exploiting Trust for Resilient Hypothesis Testing with Malicious Robots
复制标题

DOI:
10.1109/icra48891.2023.10160385
复制
发表时间:
2022-09
期刊:
2023 IEEE International Conference on Robotics and Automation (ICRA)
影响因子:
--
通讯作者:
Matthew Cavorsi;Orhan Eren Akgün;M. Yemini;A. Goldsmith;Stephanie Gil
Matthew Cavorsi;Orhan Eren Akgün;M. Yemini;A. Goldsmith;Stephanie Gil
中科院分区:
其他
文献类型:
--
作者:
Matthew Cavorsi;Orhan Eren Akgün;M. Yemini;A. Goldsmith;Stephanie Gil

文献摘要

相似文献

我们开发了一个弹性的二元假设检验框架,用于对抗性多机器人群体感知任务的决策。该框架利用机器人之间的随机信任观察,在集中式融合中心(FC)处做出易于处理的弹性决策,即使i)网络中存在恶意机器人并且它们的数量可能大于合法机器人的数量,以及ii)FC使用来自所有机器人的一次性噪声测量。我们推导出两个算法来实现这一点。第一种是两阶段方法(2SA),该方法根据收到的信任观察来估计机器人的合法性,并可证明地最小化最坏情况下恶意攻击的检测错误概率。在这里,恶意机器人的比例是已知的,但是任意的。对于恶意机器人比例未知的情况,我们开发了对抗性广义似然比测试(A-GLRT),该测试同时使用报告的机器人测量结果和信任观察结果来估计机器人的可信度、其报告策略以及正确的假设。我们利用特殊的问题结构表明,这种方法仍然是计算易处理的,尽管有几个未知的问题参数。我们在硬件实验中部署了这两种算法,其中一组机器人在模拟道路网络上进行交通状况的人群感知,其精神类似于Google地图,受到Sybil攻击。我们从实际的通信信号中提取每个机器人的信任观察,这些信号提供了关于发送者的唯一性的统计信息。我们表明,即使当恶意机器人占多数,FC可以降低检测错误的概率分别为30.5%和29%的2SA和A-GLRT。
We develop a resilient binary hypothesis testing frame-work for decision making in adversarial multi-robot crowdsensing tasks. This framework exploits stochastic trust observations between robots to arrive at tractable, resilient decision making at a centralized Fusion Center (FC) even when i) there exist malicious robots in the network and their number may be larger than the number of legitimate robots, and ii) the FC uses one-shot noisy measurements from all robots. We derive two algorithms to achieve this. The first is the Two Stage Approach (2SA) that estimates the legitimacy of robots based on received trust observations, and provably minimizes the probability of detection error in the worst-case malicious attack. Here, the proportion of malicious robots is known but arbitrary. For the case of an unknown proportion of malicious robots, we develop the Adversarial Generalized Likelihood Ratio Test (A-GLRT) that uses both the reported robot measurements and trust observations to estimate the trustworthiness of robots, their reporting strategy, and the correct hypothesis simultaneously. We exploit special problem structure to show that this approach remains computationally tractable despite several unknown problem parameters. We deploy both algorithms in a hardware experiment where a group of robots conducts crowdsensing of traffic conditions on a mock-up road network similar in spirit to Google Maps, subject to a Sybil attack. We extract the trust observations for each robot from actual communication signals which provide statistical information on the uniqueness of the sender. We show that even when the malicious robots are in the majority, the FC can reduce the probability of detection error to 30.5% and 29% for the 2SA and the A-GLRT respectively.