Abstract
In this paper, the design of fault detection filter (FDF) for a class of unmanned surface vehicle (USV) systems based on dynamic probabilistic event-triggered transmission protocol under compound cyber attacks is studied. First, the dynamic probabilistic event-triggered mechanism and numerical quantization are used to boost system performance, reduce communication resource consumption, and prevent network congestion. Considering Denial-of-service (DoS) attack and spoofing attack, a compound attack model is established, which results in the filtering error system being converted into a stochastic switching system. And the sufficient conditions of the mean-square exponential stability for the USV system are obtained by using the Lyapunov functional and linear matrix inequality (LMI) technique. The gains of the designed filter and weighting matrix are obtained by optimizing the LMIs. Finally, a practical example is given to verify the feasibility of the proposed fault detection method.
Keywords
Introduction
With the development of Global Positioning System (GPS) and automation technology, unmanned surface vehicles (USVs) have offered innovative solutions for various waterborne tasks (Hao et al., 2019; Wang et al., 2019). These autonomous or remotely controlled vessels are equipped with cutting-edge technology, including sensors, cameras, and sophisticated navigation systems, allowing them to perform a multitude of operations efficiently and safely (Liu et al., 2017, 2016). The versatility of USVs makes them applicable in numerous fields, such as environmental monitoring, maritime security, search and rescue missions, and oceanographic research (Zhou et al., 2020). Due to the multiple advantages of USVs, the motion control issues have been widely explored by researchers. Key areas of focus include path planning and trajectory tracking (Liang et al., 2020), dynamic obstacle avoidance and environmental awareness (Woo and Kim, 2020), multi-vessel cooperative control (USV formations) (Chen et al., 2018; Qi et al., 2024), and dynamic positioning control (Ma et al., 2020; Zhang et al., 2021). Among these, the dynamic positioning control has attracted the greatest attention. For instance, Zhang et al. (2021) addressed the dynamic positioning problem of nonlinear USVs under communication interruptions and DoS attacks using a Takagi–Sugeno (T-S) fuzzy system. Through the design of a switching sliding mode controller, Ma et al. (2020) studied the positioning fault tolerance control of the USV whose membership function of the T-S fuzzy model is unknown.
As the USV operates in a humid and corrosive environment over extended periods, the systems are susceptible to damage from seawater corrosion and other adverse environmental factors, causing the deterioration and wear of electrical components, mechanical parts, and external structures. These environmental influences include salt spray, high humidity from seawater, and corrosive substances in the sea air, which can expedite the degradation of metal surfaces and harm critical components like sensors, power units, and communication systems, potentially leading to malfunctions (Wang and Han, 2016). Fault detection is essential for maintaining the reliability and safety of USVs, particularly in scenarios such as long-term autonomous missions, harsh marine environments, and network-based control systems (Abid et al., 2021; Liu et al., 2022). This has driven extensive research on fault detection and control strategies for USVs. Typically, the fault detection involves creating a residual signal and comparing it to a set threshold. If the residual signal surpasses this threshold, an alert is promptly generated. For instance, Li and Park (2024) investigated the design of an event-triggered fault detection filter (FDF) tailored for USV systems in networked environments.
In recent decades, in order to optimize the utilization of resources in the communication network and reduce redundant transmission, the choice of triggering mechanism has become particularly significant (Cheng et al., 2023; Wang et al., 2022). Based on the characteristics of the triggering mechanisms, they can generally be categorized into time-triggered and event-triggered approaches. Furthermore, event-triggered mechanisms (ETMs) can be subdivided into static event-triggered and dynamic event-triggered types. The core concept of event-triggered control is to reduce the frequency of computations or communications by defining a triggering threshold. The control law updates are initiated only when specific vectors, such as system states or errors, surpass this threshold (Chen et al., 2023). The dynamic positioning control of the USV system based on event-triggered has been widely studied. Ye et al. (2021) adopted a new event-triggered mechanism for intelligent positioning control of USV systems, which was based on a novel asynchronous advantage actor-critic (A3C) learning-based event-triggered approach. Li and Park (2024) studied the fault detection of the USV system under randomly occurring injection attacks based on an adaptive event-triggered mechanism.
Industrial communication networks play a crucial role in the functioning of contemporary industrial systems and are known for their open, interconnected structure. While this openness promotes seamless communication and data sharing, it also exposes the networks to a variety of cyber threats from unidentified attackers. Such cyber attacks can have devastating effects, such as reduced performance, compromised data integrity, unauthorized access, or even system failures. Consequently, securing these networks and ensuring their robustness has become a critical priority. In light of these vulnerabilities, researchers have extensively studied how to mitigate the negative impacts of cyber attacks, such as how to reduce the influence of DoS attacks (Ma et al., 2020; Qi et al., 2024; Ye et al., 2022, 2021; Zhang et al., 2021), distributed DoS attacks, deception attacks (injection attacks) (Chen et al., 2023; Li and Park, 2024), replay attacks (Liu et al., 2022; Shi et al., 2016), and hybrid attacks (Xing et al., 2025; Ye et al., 2021). Due to the limitations of the time-triggered mechanism in the presence of DoS attacks, a more elastic event-triggered approach was implemented to enhance fault detection and reduce the impact in Ma et al. (2020).
To sum up, we will complete the elastic fault detection of USV systems under hybrid cyber attacks. The main contributions of this paper are as follows: (1) by introducing the probabilistic event-triggered mechanism and considering the impact of data quantization on the system, the fault detection framework of USV system is established; (2) Considering aperiodic DoS attacks, the filtering error system is converted into a stochastic switching system; and (3) based on the Lyapunov functional and linear matrix inequality (LMI) technique, the sufficient conditions of the mean-square exponential stability for the filtering error system are obtained.
Notations
In this paper,
System description
USV modeling
In general, the USV dynamics comprise six degrees of freedom, including heave, pitch, roll, surge, sway, and yaw (Du et al., 2015). In order to facilitate the follow-up work, this paper only studies the motion of roll, sway, and yaw. The external disturbance is heave, surge, and pitch. The expression of the dynamics equation of USV system is obtained according to Wang and Han (2016):
where
Define
where
Suppose there is a state feedback controller
with
Fault weighting
In an effort to raise the power of the fault detection, in the framework of fault detection, a weighting fault function is usually contained, which can be referred to
where
Probabilistic event-triggered protocol
To conserve limited network energy, an event-triggered mechanism is proposed based on the following triggering condition:
where
We define the interval triggering threshold as
In addition, the internal dynamic variables are given as follows:
Inspired by Li et al. (2020), we convert the system into a delay system in order to better handle the measured output. So, we define:
where
The piecewise functions defined as:
and we have:
Quantization
In scenarios with restricted communication, acquiring the full original measurement signal becomes challenging. Typically, signals must undergo quantization prior to transmission. The logarithmic quantizer is represented as:
where the quantization density is
According to Wang et al. (2023), the quantization process can be represented by the following function:
Define the quantization uncertainty term is
Cyber attacks
When the information is transmitted, it constantly faces attacks from different attackers, which can lead to data loss. To overcome this obstacle, we propose a composite attack model that includes a class of power-limited DoS attacks and multi-channel spoofing attacks, which is described as follows:
where
where
When
where
Fault filter
The main purpose of this paper is to detect the failure of the system by generating residual signal under the DPETM. Therefore, the FDF is designed as follows:
where
Filtering error system
Define
where
And Figure 1 expresses the structure of the filtering error system.

Structure of the filtering error system.
For the convenience of subsequent research, we will introduce several key lemmas.
where
Building upon the aforementioned operations, the fault detection problem for the USV system (3) can be recast as an auxiliary
To effectively use the residual signal generated by the FDF for fault detection, we make a decision on fault occurrence by comparing the residual evaluation function
In addition, the algorithm of fault detection process is given in Figure 2.

The fault detection process.
Main results
This section introduces the filter design method of USV using probabilistic event-triggered mechanism (PETM) scheme against multiple cyber attacks. First, the sufficient conditions for the exponentially mean-square stability are obtained by constructing Lyapunov functional in Theorem 1. Second, the term containing quantized nonlinear parameters is eliminated, and an equivalent inequality is obtained in Theorem 2. Finally, the design of filter gains and weighting matrix are obtained in Theorem 3.
where
where
where
If
where
The first term on the right side of equation (35) can be further expressed as:
where
According to Lemma 1, the second term on the right side of equation (35) results in:
where
Combining equations (33)–(37), we have:
where
If
Utilizing the Schur complement, we have
Next, according to i equals two cases described by different values, we have:
where
If there exist constants
For
where
where
For
where
Defining
By equation (35), it follows that:
where
Finally, combining equations (46) and (47), we have:
In conclusion, it means that the filtering error system is exponentially mean-square stable.
Theorem 1 gives the sufficient conditions of the mean-square exponential stability for the USV system with
where
Other parameters are the same as Theorem 1.
By Lemma 2, there exist
where
This completes the proof. □
On the basis of the above theory, the gains of the filter are obtained by dividing the matrix P into blocks.
where
And then, we define
This completes the proof. □
Simulation results
In this section, the validity of the proposed method is demonstrated, and we have borrowed the actual parameters of USV from Wang and Han (2016):
Borrowing the parameters from Wang and Han (2016), we can set
The parameters of the fault weighting system are selected as follows:
We suppose
We select the dynamic probabilistic event-triggered transmission protocol parameter
By solving the LMIs in Theorem 3, we have:
The information expressed in Figure 3 expresses that the state response of the system has been severely affected by a system failure, which can lead to irreparable consequences. Figure 4 represents spoofing attacks, which follow the Benoulli distribution. The triggering sequence can be clearly seen in Figure 5. Figure 6 shows the output signal

System state responses with

Possible occurrence of

Trigger sequence.

System state output

Residual error response

Residual evaluation function
Conclusion
In this paper, the fault detection problem for USV system under compound cyber attacks has been studied under the dynamic probability-based event-triggered mechanism. In order to further improve the system performance and reduce network channel congestion, a dynamic probability-based event-triggered mechanism has been proposed. Based on compound cyber attacks, the filtering error system is converted into a stochastic switching system. By establishing the Lyapunov functional and analyzing LMIs, the sufficient conditions of the exponentially mean-square stability with a given
While the proposed fault detection method demonstrates robustness under compound cyber attacks, quantized signals, and probabilistic event-triggered communication, it also has certain limitations. First, the filter design depends on solving a set of LMIs, which may become computationally expensive for high-dimensional or large-scale systems. Second, the theoretical results rely on accurate knowledge of some attack-related parameters (e.g. probabilities, duration bounds), which may not always be fully available or measurable in real-world scenarios. Moreover, the current framework assumes fixed filter gains, which are not adaptively updated during runtime.
Looking ahead, several extensions are possible. Future work could explore adaptive or learning-based filter designs that can adjust to unknown or time-varying attack characteristics. The method could also be extended to multi-agent USV systems or heterogeneous autonomous platforms operating collaboratively under network constraints. Moreover, while this study—like most existing works—focuses primarily on communication-induced delays, another valuable direction would be to explicitly model and analyze the effects of inherent system delays arising from sensing, computation, or actuation processes in the USV dynamics. Incorporating such physical delays would further enhance the practical applicability of the approach in real-world settings. As for applications, the proposed strategy is particularly well suited to autonomous maritime systems involved in offshore surveillance, environmental monitoring, or long-duration missions in adversarial environments. It may also find relevance in broader cyber-physical systems such as industrial automation and smart sensor networks where communication is constrained and security threats are present.
Footnotes
Declaration of conflicting interests
The author(s) declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Funding
The author(s) disclosed receipt of the following financial support for the research, authorship, and/or publication of this article: This work was partly supported by the National Natural Science Foundation of China under grants 62173174 and 62203248 and the Natural Science Foundation of Shandong Province under grants ZR2021MF087, ZR2022MF252, ZR2022MF297, and ZR2024MF081.
Data availability statement
Data sharing is not applicable to this article as no datasets were generated or analyzed during the current study
