Source-linked AI summary
Securing Cooperative Sensing in UAV Swarms Against Conformity-Driven Byzantine Attacks
Ruixing Ren, Junhui Zhao, Qiuping Li, He Fang, Jiamin Li, Dongming Wang
TL;DR
Byzantine attackers can exploit imitation-based conformity in ISAC-enabled UAV swarms, making normal-report errors dynamic and invalidating conventional independent-error fusion. The paper couples evolutionary game theory with per-node MAP estimation, deriving misinformation dynamics and an ESS while tracking errors online. The resulting mechanism achieves nearly 100% accuracy across tested conditions and remains above 99% under ±20% parameter mismatch, whereas baseline methods collapse after majority flipping.
Problem
Imitation-based conformity allows Byzantine attackers to create false consensus and dynamically amplify normal-UAV errors beyond the assumptions of conventional fusion.
Method
The paper combines graph evolutionary game theory for bounded-rational death-birth opinion dynamics with per-node MAP estimation using predicted error evolution.
Results
Nearly 100% accuracy is achieved across topologies, attack intensities, network scales, and sensing-error distributions, with accuracy above 99% under ±20% parameter mismatch.
Takeaways & Limitations
Swarm-level misinformation overwhelms the majority if and only if Pa > 1/2, while the proposed fusion mechanism remains accurate beyond the failure boundary of conventional defenses.
Abstract
from arXiv · showhide
In integrated sensing and communication (ISAC) enabled 6G unmanned aerial vehicle (UAV) swarm networks, the widely adopted imitation-based conformity cooperation mechanism can be exploited by Byzantine attackers to fabricate false consensus, causing the effective error probability of normal UAVs to evolve dynamically and far exceed their inherent sensing errors, which invalidates conventional fusion methods built on the independence assumption. This paper proposes a conformity-aware Byzantine-resilient fusion framework that couples evolutionary game theory with maximum a posteriori (MAP) estimation. First, the strategy updates of normal UAVs are characterized by bounded-rational opinion dynamics, and the evolution dynamics of the misinformation ratio together with its evolutionarily stable state (ESS) are derived under death birth updating. Three theoretical results are then established: under heterogeneous per-node sensing errors, the zeroth-order ESS depends on the error distribution only through its mean; a closed-form first-order weak-selection correction to the ESS is obtained, together with an exact mean-field fixed point valid for arbitrary selection intensity; and it is revealed that swarm level misinformation can overwhelm the majority if and only if the attack probability exceeds one half, with this threshold independent of both the sensing error and the malicious ratio. Embedding the predicted error dynamics into a per-node MAP rule, the resulting fusion mechanism achieves nearly 100% situation-inference accuracy under different network topologies, attack intensities, network scales, and sensing-error distributions, and maintains accuracy above 99% under +-20% parameter mismatch. In contrast, majority voting, reputation weighting, and independent fusion collapse completely once the majority-flip threshold is crossed.
I. INTRODUCTION
Imitation-based conformity helps UAV swarms cooperate but lets Byzantine attackers propagate false consensus through dynamically evolving normal-node errors. The paper combines evolutionary-game analysis with conformity-aware MAP fusion to characterize and mitigate this threat.
- Motivation: Imitation-based conformity lets normal UAVs switch behaviors using neighbors’ fitness, unlike unbiased quantized consensus.The paper focuses on imitation-based conformity; aggregation-weight robustness is outside its scope.
- Threat model: Under conformity, malicious UAVs can lure normal nodes into wrong strategies over repeated rounds, making effective errors dynamic and much larger than sensing errors.This creates model mismatch for fusion methods assuming constant, independent errors.
- Contributions: The paper uses graph evolutionary game theory to derive misinformation dynamics, the ESS, and the majority-flip threshold under independent fixed-intensity attacks.The framework models bounded-rational, local strategy adaptation under death-birth updating.
- Contributions: With heterogeneous sensing errors, the zeroth-order ESS depends on the error distribution only through its mean.This supports mean-field fusion design under realistic channel conditions.
- Contributions: A closed-form first-order correction and an exact arbitrary-selection fixed point extend the evolutionary analysis beyond the zeroth-order approximation.The first-order correction and exact mean-field result quantify selection effects on misinformation.
- Fusion framework: The proposed per-node MAP fusion tracks evolving normal-report errors and achieves nearly 100% accuracy across conditions, remaining above 99% under ±20% parameter mismatch.Evaluated conditions include different topologies, attack intensities, network scales, and sensing-error distributions.
IV. EVOLUTIONARY DYNAMICS AND STABLE STATE OF THE UAV SWARM
This section derives how local imitation and report outcomes determine normal UAVs’ transition from truthful to misleading strategies. The transition probability is then expanded around weak conformity to obtain the population-level evolutionary dynamics.
- Transition construction: The exact transition probability is obtained by averaging over central and neighbor errors before applying the weak-selection approximation.The construction explicitly incorporates heterogeneous central and neighbor error roles in the exact formulation.
- State Transition Probability: A UAV’s transition probability accounts separately for correct and erroneous central observations and averages over neighbor report configurations.Fitness functions are specified for both truthful and misleading strategies in each observation condition.
- State Transition Probability: The model derives the probability that a normal UAV switches from the truthful strategy to the misleading strategy under death-birth updating.The probability compares the fitness of neighbors judged opposite to the true state with total neighbor fitness.
- Weak-selection expansion: The derivation substitutes payoff-based fitness expressions into the death-birth transition rule and separates baseline and conformity-dependent terms.The weak-selection coefficient α isolates the first-order payoff contribution.
- Weak-selection expansion: The resulting expansion retains an O(1) zeroth-order term and a closed-form first-order term in α.The zeroth-order component is used for population evolution, while the first-order form is developed later.
B. Population Evolution Equation
The population equation tracks the fraction of normal UAVs adopting the misleading strategy by combining ordinary-node misinformation with malicious-neighbor attacks. Its zeroth-order equilibrium is stable under practical sensing-error and malicious-ratio conditions.
- Population Evolution Equation: The expected misleading-neighbor fraction is ko(pm + βPa), combining normal misinformation pm with malicious attack probability Pa.Here β is the malicious-to-normal UAV ratio and ko is the number of ordinary neighbors.
- Population Evolution Equation: The expected total neighborhood size is ko(1 + β), which normalizes the misleading-neighbor contribution in the population dynamics.The denominator includes ordinary and malicious neighbors.
- Zeroth-order approximation: Under weak selection, the analysis drops the higher-order αE[ϖ(km)] term and retains the zeroth-order evolution equation.This approximation treats α as very small and the payoff-dependent expectation as bounded.
- Zeroth-order approximation: The resulting population equation is a linear differential equation in pm, rewritten around the ESS using the error variable ϱ = pm − pESS.This form isolates deviations from equilibrium.
- Stability: The equilibrium is asymptotically stable because A < 0 for 0 < ε ≤ 0.5 and β > 0, causing deviations to decay exponentially.The solution is ϱ(t) = ϱ(0)e^At, so ϱ(t) approaches zero.
C. Majority-Flip Threshold
The majority-flip threshold determines when misinformation overtakes honest reports under the paper’s DB imitation model. It is independent of sensing error and malicious ratio, but depends on the attack probability.
- Pa > 1/2 is the majority-flip threshold, independent of both ε and β.
- When Pa > 1/2, aggregate swarm reports are systematically inverted and majority-trusting defenses fail.
- When Pa < 1/2, the majority remains trustworthy and classical defenses survive.
D. Exact Mean-Field Transition Probability
The paper retains the full fitness rather than using weak-selection truncation, deriving an exact mean-field transition probability and an ESS fixed point valid for arbitrary selection intensity.
- The exact transition probability retains the full fitness and makes no weak-selection truncation.
- At α = 0, the exact transition probability reduces to the zeroth-order approximation, while its Taylor coefficient is the closed-form correction G.
- The exact mean-field ESS is computed as the solution of a fixed-point equation by simple iteration.
V. MODEL REFINEMENT AND ROBUSTNESS ANALYSIS
This section refines the model by addressing heterogeneous sensing errors, weak-selection corrections, arbitrary selection intensity, and graph effects beyond mean-field analysis.
- The analysis examines ESS dependence on heterogeneous sensing-error distributions.
- It derives a first-order closed-form correction under weak selection.
- It discusses graph-structural effects beyond the mean-field approximation.
A. Heterogeneous Sensing Errors
The heterogeneous-error analysis shows that zeroth-order misinformation dynamics depend on sensing-error heterogeneity through its population mean, while per-node errors remain relevant to MAP fusion and higher-order corrections.
- A. Heterogeneous Sensing Errors: The result assumes local misinformation ratios ρi are uncorrelated with sensing errors εi.
- A. Heterogeneous Sensing Errors: Theorem 1 makes heterogeneous zeroth-order dynamics identical to homogeneous dynamics with ε = ¯ε.
- A. Heterogeneous Sensing Errors: The zeroth-order ESS depends on the sensing-error distribution only through its mean ¯ε.
- A. Heterogeneous Sensing Errors: Per-node errors εi remain relevant to the fusion likelihood and are used by the per-node MAP rule.
- A. Heterogeneous Sensing Errors: Strong coupling between channel conditions and network topology requires correction and is left for future work.
- B. First-Order Weak-Selection Closed-Form Correction: The first-order population correction is expressed as a payoff-weighted linear combination G(e, ρ) = gns uns + gnd und + gms ums + gmd umd.
- B. First-Order Weak-Selection Closed-Form Correction: The first-order ESS shift is obtained by applying the implicit function theorem around the zeroth-order ESS.
- B. First-Order Weak-Selection Closed-Form Correction: Mean-field analysis replaces local misinformation ratios with the population-average ρs, while finite-graph fluctuations can cause structural amplification and a slightly steeper descent.
VI. CONFORMITY-AWARE MAP FUSION
The fusion framework combines evolutionary tracking of UAV report errors with per-slot MAP estimation, modeling malicious and conformity-affected normal reports separately. The resulting rule infers the true state sequence from reports under a uniform prior.
- The MAP estimator infers the true state sequence Θ from UAV reports under a uniform prior.
- Report models: The fusion likelihood marginalizes over malicious and normal node types using the malicious ratio β and conditional independence.
- Report models: Malicious UAV reports are modeled using attack probability Pa together with sensing error, yielding a report error probability.
- Report models: Normal UAV report errors evolve after the first slot according to the misinformation ratio generated by conformity dynamics.
- Online procedure: Algorithm 1 propagates per-slot error probabilities and accumulates log-likelihoods to implement the fusion procedure.
A. Per-Node Heterogeneous Fusion
The heterogeneous fusion variant uses the population mean sensing error to track misinformation dynamics while retaining individual sensing errors in the fusion likelihood. This produces the evolutionary-game-theoretic MAP fusion method and its homogeneous and per-node forms.
- Theorem 1 requires only the population mean sensing error ¯ε to predict misinformation evolution, while individual εi improve the fusion likelihood.
- Each UAV feeds back its sensing-SINR estimate so the fusion center can obtain individual εi for per-node error probabilities.
- The per-slot MAP decision uses conditional probabilities evaluated with malicious-node and normal-node error parameters.
- Combining Equation (65) with evolutionary tracking of the misinformation ratio defines EGTM fusion, including homogeneous and per-node variants.
B. Online Implementation
The implementation tracks misinformation online and evaluates the proposed fusion across topologies, sensing-error distributions, attack settings, and selection intensity. The experiments show strong robustness, while baselines fail after the majority-flip threshold is crossed.
- B. Online Implementation: The misinformation ratio is propagated online using model parameters and the payoff matrix, with a sliding window reducing enumeration complexity from 2^T to 2^τ.
- B. Online Implementation: τ = 1 achieves full accuracy with the lowest fusion latency because the normal-node error probability is predicted slot by slot.
- C. Robustness to Heterogeneous Sensing Errors: Across regular, BA, and ER networks, evolution curves nearly coincide with the theoretical ODE, indicating topology-independent dynamics under the tested settings.
- C. Robustness to Heterogeneous Sensing Errors: The steady-state misinformation ratio decreases with ε, increases with β and Pa, and reaches 0.5 at ε = 0.5 when neighbor influence vanishes.
- B. First-Order Weak-Selection Effect: The zeroth-order ESS is 0.6860 and decreases to 0.6781 at α = 0.5, while the first-order approximation deviates by less than 3 × 10^-5 at α = 0.05.
- C. Robustness to Heterogeneous Sensing Errors: With mean ¯ε = 0.1, four markedly different sensing-error distributions produce cross-distribution ESS dispersion below 0.002.
- D. Fusion Performance: For weak attacks, all fusion methods exceed 0.99 accuracy; after the strong-attack ESS crosses 1/2, majority voting, reputation methods, and independent fusion collapse.
- D. Fusion Performance: Under ε = 0.1, β = 0.5, and Pa = 0.8, misinformation crosses 0.5 within about two slots, while the proposed method maintains accuracy close to 1.0.
E. Fusion under Heterogeneous Errors
The proposed per-node fusion remains robust across malicious ratios, sensing heterogeneity, swarm sizes, SINR conditions, window lengths, and parameter mismatch. It maintains high accuracy while conventional baselines collapse under attack.
- Malicious ratio and heterogeneity: 0.83–1.0 accuracy is maintained by EGTM-pernode across β ∈[0.05, 0.5], reaching full accuracy from β = 0.2 under homogeneous errors and β = 0.3 under SNR errors.IFM and majority voting fall to 0–0.25 over the same β range, while EGTM-homog is slightly worse under SNR heterogeneity.
- Malicious ratio and heterogeneity: 0.83–0.85 accuracy is achieved at β = 0 despite conformity driving the misinformation ESS to 1/2.Majority voting and independent fusion degenerate to approximately 0.5, whereas the proposed method extracts residual statistical asymmetry.
- Robustness and parameter sensitivity: Nearly 1.0 accuracy is sustained across small to large swarm sizes and improves slightly with N, with reduced variance.The observed stabilization is attributed to the law of large numbers.
- Robustness and parameter sensitivity: Above 0.99 accuracy is retained under ±20% parameter mismatch, compared with 0.9992 from ODE prediction and 0.9995 using the true simulated error.The result indicates reliance on modeled error dynamics rather than exact parameter knowledge.
- Robustness and parameter sensitivity: 100% accuracy is approached above about 0 dB across all β, while accuracy improves with SINR and remains nearly insensitive to window length.At τ = 1, accuracy is already ≥0.99 for β ∈{0.5, 1.0}; latency grows linearly with τ.