New energy automobile in-vehicle network real-time intrusion detection system based on edge calculation

Through the new energy vehicle in-vehicle network intrusion detection system with edge computing and distributed collaborative architecture, network data is monitored and analyzed in real time, and defense strategies are dynamically adjusted, which solves the problems of insufficient unknown attack detection capabilities and weak multi-vehicle collaborative defense in the existing technology, and improves the network security of intelligent connected vehicles.

CN120498761APending Publication Date: 2025-08-15CHONGQING YISHI INTELLIGENT TECHNOLOGY CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510625106.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The existing in-vehicle network intrusion detection technology of new energy vehicles has problems such as insufficient unknown attack detection capabilities, poor real-time capabilities, and weak multi-vehicle coordination defense capabilities, making it difficult to deal with network security threats in intelligent connected vehicles scenarios.

Method used

Adopting a distributed collaboration architecture based on edge computing, including in-vehicle edge computing nodes, on-vehicle communication interfaces and regional collaboration modules, through topological adaptive immune analysis, geometric manifold threat tracking, photonic state perturbation perception and causal path defense algorithms, network traffic, electronic control unit status and sensor data are monitored and analyzed in real time, and defense strategies are dynamically adjusted to realize multi-vehicle threat intelligence sharing and rapid response.

Benefits of technology

Real-time detection of unknown attacks is realized, false alarm rates and missed reports are reduced, network abnormalities are quickly responded to network exceptions, and overall security protection capabilities in intelligent connected vehicles are enhanced, cloud data transmission risks are reduced, and defense of multi-vehicle joint attacks is supported.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498761A_ABST
    Figure CN120498761A_ABST
Patent Text Reader

Abstract

The invention provides a new energy automobile in-vehicle network real-time intrusion detection system based on edge computing, which relates to the field of new energy automobile network security and intrusion detection and comprises an in-vehicle edge computing node, a vehicle-mounted communication interface and a regional collaboration module. The in-vehicle edge computing node, the vehicle-mounted communication interface and the regional collaboration module form a distributed collaboration architecture to realize in-vehicle network real-time intrusion detection and dynamic defense, and the in-vehicle edge computing node is deployed in a vehicle electronic control unit and a gateway, collects and analyzes network traffic and sensor data, executes a local defense decision, and sends the local defense decision to the regional collaboration module. The system monitors the controller local area network flow, the electronic control unit state and the sensor signal of the in-vehicle network in real time through edge calculation, network abnormity and physical attack signs can be found in time, the safety risk caused by delay detection is effectively avoided, and the efficiency and timeliness of in-vehicle network monitoring are improved. The system adopts intelligent analysis methods such as a topological immune reconstruction algorithm and a photon trajectory aggregation algorithm.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security and intrusion detection for new energy vehicles, and specifically to a real-time intrusion detection system for in-vehicle networks of new energy vehicles based on edge computing. Background Art

[0002] With the rapid development of new energy vehicles, intelligent connected vehicles (ICVs) are becoming a key trend in future transportation. The security and stability of their in-vehicle network systems directly impact vehicle operational safety and user experience. In-vehicle networks connect electronic control units, sensors, and communication modules, carrying critical functions such as autonomous driving, brake control, and Internet of Vehicles (IoV) communications. Cyberattacks can lead to vehicle loss of control, data leakage, and even accidents, seriously threatening driver safety and social stability. Therefore, accurately and promptly detecting and preventing intrusions into in-vehicle networks and mitigating cybersecurity risks have become critical issues that need to be addressed in the new energy vehicle sector.

[0003] At present, intrusion detection in new energy vehicle in-vehicle networks mainly relies on the following technical means:

[0004] Traditional rule matching detection: Through a preset attack signature library, the controller local area network data packets are monitored and matched with known attack patterns to identify abnormal behavior.

[0005] Log analysis technology: records the operation logs of electronic control units and gateways, and detects potential intrusion traces such as abnormal instructions or communication interruptions through offline analysis.

[0006] IoV cloud monitoring: Utilizing IoV technology, vehicle data is uploaded to cloud servers, and network attacks, such as forged remote commands, are detected through big data analysis.

[0007] Physical parameter monitoring: Collects physical parameters such as voltage, current, or device temperature of the electronic control unit and analyzes abnormal changes to determine whether it is under attack, such as overheating caused by electromagnetic interference.

[0008] Although existing detection technologies have played a role in protecting in-vehicle network security, they still have many shortcomings:

[0009] 1. Traditional rule-matching detection relies on a known attack signature database, making it difficult to respond to new or unknown attacks. Detection capabilities are limited by the update speed and comprehensiveness of the signature database, making it difficult to detect potential intrusions in a timely manner and unable to effectively prevent attacks.

[0010] 2. While log analysis technology and IoV cloud monitoring can provide comprehensive attack tracing capabilities, they rely on offline analysis or cloud computing, which has poor real-time performance. This often prevents a quick response in the early stages of an attack, missing the optimal defense opportunity. Furthermore, cloud-based transmission can increase the risk of data leakage.

[0011] 3. Although physical parameter monitoring can assist in detecting physical layer attacks, its ability to perceive network layer attacks is limited and it is susceptible to environmental interference. For example, temperature changes may be caused by weather rather than attacks, resulting in a high rate of false positives.

[0012] 4. Most existing technologies lack the ability to defend against multi-vehicle collaboration and are unable to cope with joint attacks by multiple vehicles, such as forging threat profiles to induce target vehicles to make incorrect decisions. This type of coordinated attack is becoming increasingly common in the context of intelligent connected vehicles, and existing single-vehicle detection methods are difficult to effectively deal with.

[0013] Therefore, a real-time intrusion detection system for new energy vehicle in-vehicle networks based on edge computing is needed to solve the above problems. Summary of the Invention

[0014] Technical problems solved

[0015] In response to the shortcomings of the existing technology, the present invention provides a real-time intrusion detection system for the in-vehicle network of new energy vehicles based on edge computing, which solves the problems in the above background technology.

[0016] Technical Solution

[0017] To achieve the above objectives, the present invention is implemented through the following technical solutions: a real-time intrusion detection system for in-vehicle networks of new energy vehicles based on edge computing, the system including in-vehicle edge computing nodes, on-board communication interfaces and regional collaboration modules, the in-vehicle edge computing nodes, on-board communication interfaces and regional collaboration modules constitute a distributed collaborative architecture to achieve real-time intrusion detection and dynamic defense of in-vehicle networks, the in-vehicle edge computing nodes are deployed in the vehicle electronic control unit and gateway, collect and analyze network traffic and sensor data, and execute local defense decisions, the on-board communication interface integrates the controller local area network, in-vehicle Ethernet and photonic communication units to ensure the secure exchange of data inside and outside the vehicle, the regional collaboration module coordinates the sharing of threat intelligence from multiple vehicles through laser communication to form a regional defense network, the in-vehicle edge computing nodes, on-board communication interfaces and regional collaboration modules operate collaboratively through hierarchical control flows, the in-vehicle edge computing nodes give priority to processing local data, the regional collaboration module integrates intelligence from multiple vehicles and dynamically adjusts defense strategies, the system achieves its goals through the following steps:

[0018] Sp1: A topology-adaptive immune parsing engine collects controller area network traffic, electronic control unit status data, and vehicle body sensor signals, and runs a topology-adaptive immune reconstruction algorithm to generate a threat signature sequence. When utilizing data, the topology-adaptive immune parsing engine stores controller area network traffic in a ring buffer as a time series, ECU status data is parsed in a key-value pair format, and sensor signals are adaptively filtered to generate feature vectors. The threat signature sequence is transmitted to the edge computing node main control unit via the in-vehicle Ethernet and encrypted using a dynamic key. The engine operates in state machine mode, sampling every 50 milliseconds. When an anomaly is detected, it switches to high-frequency sampling and jumps to Sp2.

[0019] Sp2: The geometric manifold threat tracking engine collects in-vehicle network topology and IoV communication data. Based on the threat signature sequence of Sp1, a curvature pulse tracking algorithm is run to detect topological curvature anomalies. The threat summary is broadcast using the optical pulse threat sharing protocol. Topological data is stored in an adjacency table, and IoV data is parsed into a weighted edge sequence. The threat summary is broadcast to surrounding vehicles via a laser communication unit, using pulse coding to compress the data. The engine operates in event-driven mode, prioritizing topological mutations and jumping to Sp3 upon confirmation of an anomaly.

[0020] Sp3: The photon state disturbance perception engine generates photon sequences to protect critical communication channels and runs a photon trajectory aggregation algorithm to detect trajectory deviations. Photon sequences are stored in time window encoding, and deviation data is analyzed in the form of vector sequences. Deviation anomaly data is uploaded to the regional collaboration module via a post-quantum encryption channel. The engine runs the photon trajectory aggregation algorithm at a fixed period. When an anomaly is detected, low-priority communications are suspended and the process jumps to Sp4.

[0021] Sp4: The causal path defense engine collects causal interaction records from sensors to electronic control units. Based on the deviation and abnormal data in Sp3, the causal ripple prediction algorithm is used to generate an attack path sequence, triggering a dynamic isolation strategy. The causal records are stored in a time-series directed graph, and the ripple sequence is encoded in a sparse matrix. The isolation instruction is multicast to the target electronic control unit via the controller area network. The engine runs in asynchronous mode and jumps to Sp5 if the prediction fails.

[0022] Sp5: Electromagnetic radiation and heat distribution data are collected through the electromagnetic-thermal collaborative detection engine. Combined with the attack path sequence of Sp4, a cross-domain trajectory fusion algorithm is run to detect joint network and physical attacks, and a visual positioning report is generated. Electromagnetic radiation data is stored as a spectrum sequence, thermal distribution data is saved as a pixel heat map, and network traffic is integrated as a packet statistical vector. The positioning report is transmitted to the central control display screen via the in-vehicle Ethernet in an image compression format. The engine runs in a multi-threaded pipeline mode. After confirming the joint attack, an alarm is issued through the voice interaction module and the process is terminated.

[0023] Preferably, the topology adaptive immune parsing engine in Sp1 is composed of a traffic collection unit, a state parser, a sensor interface and a topology immune reconstruction algorithm inference core, and works as follows: the traffic collection unit parses the controller local area network data packet to generate a time series, the state parser extracts the voltage and load changes of the electronic control unit, the sensor interface collects acceleration and temperature signals to generate standardized vectors, and the inference core reconstructs the trust relationship by simulating node immune competition and outputs a threat feature sequence; the three types of data, namely the time series generated by the controller local area network data packet, the voltage and load change data of the electronic control unit, and the standardized vectors of the vehicle body acceleration and temperature signals, are stored in a ring buffer through time alignment, and high-risk traffic is cached first; the threat feature sequence is encrypted in a serialized format and transmitted to the geometric manifold threat tracking engine of Sp2; the engine coordinates the collection task with the main thread, and the sub-thread runs the algorithm, and triggers Sp2 when an exception occurs.

[0024] Preferably, the topology-immune reconstruction algorithm in Sp1 generates a threat feature sequence by dynamically adjusting the trust weights of network nodes, driving the curvature pulse tracking algorithm in Sp2 to analyze topology anomalies; the threat feature sequence is stored in fixed-length vector encoding; the sequence is encrypted and transmitted to the geometric manifold threat tracking engine via the in-vehicle Ethernet; the topology-immune reconstruction algorithm runs in state machine mode, switches to high-frequency sampling in the event of an anomaly, and notifies Sp2.

[0025] Preferably, the geometric manifold threat tracking engine in Sp2 is composed of a topology acquisition module, a curvature analyzer, a laser communication interface and a threat summary generator, and works as follows: the topology acquisition module updates the network adjacency relationship within the vehicle, the curvature analyzer runs the curvature pulse tracking algorithm to calculate the topological curvature offset, the summary generator compresses the offset data into a fixed-bit-length summary, and the laser communication interface broadcasts the summary to surrounding vehicles; the adjacency relationship is stored in the form of a low-rank matrix; the summary is transmitted to the engines of Sp4 and Sp5 in pulse coding format; the engine runs in event loop mode, and triggers the photon state disturbance perception engine of Sp3 when the curvature is abnormal.

[0026] Preferably, the optical pulse threat sharing protocol in Sp2 consists of a pulse encoder, a laser transmitter, a photon receiver and an error checking unit, and works as follows: the pulse encoder maps the threat profile into an interval coding sequence, the laser transmitter sends a pulse sequence, the photon receiver decodes the data, and the error checking unit verifies the data integrity; the threat profile is stored as a sparse vector; the protocol transmits data through laser communication, supports the isolation strategy of Sp4 and the joint detection of Sp5; the protocol operates in a token scheduling mode, giving priority to transmitting high-risk profiles.

[0027] Preferably, the photon state disturbance perception engine in Sp3 is composed of a photon sequence generator, a trajectory analyzer, an encrypted communication interface and an abnormal storage unit, and works as follows: the photon sequence generator assigns a pulse sequence to the autonomous driving command channel, the trajectory analyzer runs the photon trajectory aggregation algorithm to calculate the deviation vector, the encrypted communication interface uploads abnormal data, and the abnormal storage unit caches historical deviations; the deviation vector is stored in a sliding window; the abnormal data is uploaded to the regional collaboration module in a fragmented form; control flow: the engine uses a timer-driven algorithm, and triggers the causal path defense engine of Sp4 when an abnormality occurs.

[0028] Preferably, the photon trajectory aggregation algorithm in Sp3 detects communication channel anomalies by aggregating photon sequence trajectory deviations, driving the causal ripple prediction algorithm in Sp4 to generate an attack path sequence; the trajectory deviation data is stored in high-dimensional tensor encoding; the abnormal data is uploaded to the regional collaboration module through an encrypted channel; the photon trajectory aggregation algorithm runs in pipeline mode, notifying Sp4 to perform defense.

[0029] Preferably, the causal path defense engine in Sp4 consists of a causal acquisition unit, a ripple predictor, an isolation controller and a path cache, and works as follows: the causal acquisition unit parses the instruction stream from the sensor to the electronic control unit, the ripple predictor runs the causal ripple prediction algorithm to generate an attack path sequence, the isolation controller sends isolation instructions to the target electronic control unit, and the path cache stores historical paths; causal data is stored in a sparse matrix; the isolation instruction is multicast to the electromagnetic thermal collaborative detection engine of Sp5 through the controller local area network; the engine runs in asynchronous mode and triggers Sp5 when the prediction fails.

[0030] Preferably, the causal ripple prediction algorithm in Sp4 generates a path sequence by simulating the ripple diffusion of the attack path, driving the cross-domain trajectory fusion algorithm in Sp5 to locate the joint attack; the ripple sequence is stored in the form of time slices; the path sequence is encrypted and multicasted through the controller local area network; the causal ripple prediction algorithm runs in a feedback loop mode and dynamically adjusts the prediction parameters.

[0031] Preferably, the system includes the following hardware to support the coordinated operation of Sp1 to Sp5:

[0032] An integrated sensing module, including an electromagnetic radiation sensor, an infrared thermal imager, a controller area network interface, and a photon sequence generator, collects electromagnetic signals, thermal distribution data, network traffic, and photon pulses;

[0033] Edge computing unit, including field-programmable gate array accelerator, runs topology immune reconstruction algorithm, photon trajectory aggregation algorithm, and cross-domain trajectory fusion algorithm;

[0034] Laser communication module, containing laser emitters and photon detectors, to implement optical pulse threat sharing protocols;

[0035] Perception data is stored in a hierarchical cache, with high-risk signals prioritized. Hardware is interconnected via a high-speed serial bus to transmit encrypted data. Edge computing units operate in a master-slave architecture to coordinate sensor and communication tasks.

[0036] Beneficial effects

[0037] The present invention provides a real-time intrusion detection system for the in-vehicle network of new energy vehicles based on edge computing.

[0038] It has the following beneficial effects:

[0039] 1. The system uses edge computing to monitor the controller area network traffic, electronic control unit status, and sensor signals of the in-vehicle network in real time. It can promptly detect network anomalies and signs of physical attacks, effectively avoiding security risks caused by delayed detection, and improving the efficiency and timeliness of in-vehicle network monitoring. The system uses intelligent analysis methods such as topological immune reconstruction algorithm and photon trajectory aggregation algorithm to process the collected multi-source data. It can dynamically identify unknown attack patterns and determine potential causes of intrusion, reducing the probability of false alarms and missed reports. This system not only relies on a single threshold judgment, but also provides more accurate intrusion detection and defense through multi-level analysis (such as topological curvature offset, photon trajectory deviation, and cross-domain trajectory fusion).

[0040] 2. This invention achieves localized real-time processing through in-vehicle edge computing nodes, overcoming the latency issues associated with traditional cloud-based monitoring and log analysis. It can quickly respond to an attack in its early stages, shutting down counterfeit communications and isolating attacking nodes, thereby ensuring the security of critical channels (such as autonomous driving instructions and brake signals). The system utilizes laser communication units and an optical pulse threat sharing protocol to achieve multi-vehicle collaborative defense, broadcasting threat summaries to surrounding vehicles. This effectively counters multi-vehicle joint attacks and enhances overall security protection capabilities in intelligent connected vehicle scenarios.

[0041] 3. This invention integrates electromagnetic, thermal, and network traffic data through a cross-domain trajectory fusion algorithm, accurately detecting combined cyber and physical attacks and generating visual location reports to assist drivers in quickly locating the attack source and reducing troubleshooting time. The system operates in an edge computing unit, reducing the risk of cloud data transmission and protecting the privacy and security of vehicle data. The hardware cost is manageable, making it suitable for large-scale deployment in new energy vehicles. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 It is a specific flow chart of the present invention;

[0043] Figure 2 This is a simulation diagram for analyzing the changes in electrical characteristic parameters of the present invention. DETAILED DESCRIPTION

[0044] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention. Specific embodiment one:

[0046] like Figure 1-2 Figure 2 shows a real-time intrusion detection system for new energy vehicles (NEVs) based on edge computing. This system consists of in-vehicle edge computing nodes, an on-board communication interface, and a regional collaboration module, forming a distributed collaborative architecture to achieve real-time intrusion detection and dynamic defense for in-vehicle networks. In-vehicle edge computing nodes, deployed in the vehicle's electronic control unit and gateway, collect network traffic, device status, and sensor data, analyze potential threats, and execute local defense decisions. The on-board communication interface integrates the controller area network, in-vehicle Ethernet, and photonic communication units to ensure secure data exchange between the vehicle and the outside world. The regional collaboration module coordinates threat intelligence sharing among multiple vehicles through laser communication, building a regional defense network. The system operates in a coordinated manner through a hierarchical control flow. In-vehicle edge computing nodes prioritize local data processing, while the regional collaboration module integrates intelligence from multiple vehicles and dynamically adjusts defense strategies to ensure real-time performance and security.

[0047] The workflow begins with data collection. A topology-adaptive immune parsing engine collects Controller Area Network (CAN) traffic, electronic control unit (ECU) status data, and body sensor signals. The engine comprises a traffic collection unit, a state parser, a sensor interface, and an inference core for a topology-immune reconstruction algorithm. The traffic collection unit parses CAN packets, generating time series data that are stored in a two-megabyte ring buffer. The state parser extracts ECU voltage and computational load changes, parses and stores them in a key-value format. The sensor interface collects body acceleration and temperature signals, and generates standardized feature vectors through adaptive filtering, also stored in the ring buffer. These three types of data are time-aligned, prioritizing high-frequency CAN packets for caching to ensure fast access to high-risk traffic. The inference core runs a topology-immune reconstruction algorithm, reconstructing trust relationships by simulating immune competition between network nodes, dynamically adjusting node trust weights, and generating threat signature sequences. These threat signature sequences are stored in a serialized format, encrypted with a dynamic key, and transmitted via the in-vehicle Ethernet network to the main control unit of the edge computing node. The engine operates in state machine mode, with a main thread coordinating the collection tasks of the traffic collection unit, state parser, and sensor interface, while a subthread runs the topology-immune reconstruction algorithm. Sampling is done every fifty milliseconds. When an anomaly is detected, the engine switches to a high-frequency sampling state, sampling every five milliseconds and triggering the subsequent geometric manifold threat hunting engine.

[0048] The geometric manifold threat hunting engine receives threat signature sequences and collects in-vehicle network topology and IoV communication data. It comprises a topology acquisition module, a curvature analyzer, a laser communication interface, and a threat profile generator. The topology acquisition module updates the adjacency relationships of the in-vehicle network, generates an adjacency table, and stores it in a low-rank matrix. IoV communication data is parsed to generate a weighted edge sequence, which is stored in a local cache. The curvature analyzer runs a curvature pulse tracing algorithm to calculate the curvature offset of the network topology based on the threat signature sequence and detect unusual topological mutations. The threat profile generator compresses the curvature offset data into a fixed-bit-length summary and stores it in a sparse vector format. The laser communication interface broadcasts the summary to surrounding vehicles using the optical pulse threat sharing protocol. The optical pulse threat sharing protocol consists of a pulse encoder, a laser transmitter, a photon receiver, and an error checking unit. The pulse encoder maps the threat profile into an interval-coded sequence. The laser transmitter transmits the pulse sequence, the photon receiver decodes the received data, and the error checking unit verifies data integrity to ensure transmission reliability. Threat summaries utilize pulse-coded compression, limiting the data size to under 512 bytes per packet. These summaries are transmitted at high speed via a laser communication unit to vehicles within a 300-meter radius. The engine operates in an event-driven mode, with the main thread handling topology acquisition and curvature analysis, while subthreads execute summary generation and broadcasting tasks, prioritizing topology mutation events. When a curvature anomaly is confirmed, the engine triggers the photon state disturbance perception engine.

[0049] The photon state perturbation perception engine generates photon sequences to protect critical communication channels, such as autonomous driving commands and brake signals. It comprises a photon sequence generator, a trajectory analyzer, an encrypted communication interface, and an anomaly storage unit. The photon sequence generator distributes pulse sequences to critical channels, generating 100,000 samples per second and storing them in a local cache using time-windowed encoding. The trajectory analyzer runs a photon trajectory aggregation algorithm, calculates trajectory deviations within the photon sequence, generates and stores a sequence of deviation vectors. Deviation anomaly data is encoded as high-dimensional tensors and uploaded to the regional collaboration module via a post-quantum encrypted channel. Each upload is limited to a kilobyte. The anomaly storage unit caches historical deviation data for subsequent analysis. The engine runs the photon trajectory aggregation algorithm at a fixed interval, performing trajectory deviation detection every 20 milliseconds. When an anomaly is detected, the engine suspends low-priority communication channels and triggers the causal path defense engine. The control flow is timer-driven: the main thread coordinates photon sequence generation and deviation analysis, while a subthread handles data upload tasks, ensuring real-time performance.

[0050] The causal path defense engine receives deviation anomaly data and collects causal interaction records from sensors to electronic control units. It comprises a causal acquisition unit, a ripple predictor, an isolation controller, and a path cache. The causal acquisition unit parses the instruction stream data, generating a time-series directed graph and storing it in a sparse matrix format. The ripple predictor runs a causal ripple prediction algorithm, simulating the ripple diffusion of attack paths based on the deviation anomaly data. It generates an attack path sequence and stores it in time-sliced form, with each slice limited to 50 kilobytes. The isolation controller sends isolation instructions to the target electronic control unit based on the path sequence, transmitting them via multicast on the controller area network (CAN), with the instruction data rate limited to 500 kilobits per second. The path cache stores historical attack paths and supports subsequent optimization. The engine operates in asynchronous mode, with the main thread handling causal acquisition and ripple prediction, and the child thread executing the isolation instruction transmission. If path prediction fails, the engine triggers the electromagnetic heat collaborative detection engine. The control flow utilizes a feedback loop design to dynamically adjust prediction parameters to ensure defense accuracy.

[0051] The electromagnetic and thermal collaborative detection engine collects electromagnetic radiation and heat distribution data, combining attack path sequences to detect network and physical joint attacks. It comprises an electromagnetic radiation sensor, an infrared thermal imager, a traffic parser, and an inference core for a cross-domain trajectory fusion algorithm. The electromagnetic radiation sensor collects signals with a frequency range of 100 kHz to 3 GHz, generating and storing spectrum sequences. The infrared thermal imager generates heat distribution maps with a pixel resolution of 512 by 512, which are stored in a local cache. The traffic parser extracts traffic data from the controller area network and the in-vehicle Ethernet, generating packet statistics vectors. These three types of data are fused using principal component analysis to generate a unified feature vector. The inference core runs a cross-domain trajectory fusion algorithm to analyze electromagnetic, thermal, and flow trajectory correlations, detect joint attacks, and generate a visual location report. The location report is stored in a compressed image format and transmitted to the central control display via the in-vehicle Ethernet, with data size limited to less than two megabits per frame. The engine operates in a multi-threaded pipeline mode, with a main thread coordinating sensor data collection and sub-threads performing trajectory fusion and report generation in parallel. When a joint attack is confirmed, the engine alerts the driver through the voice interaction module and terminates the process. The control flow adopts multi-threaded scheduling, giving priority to high-risk signals to ensure timely positioning.

[0052] The system hardware supports the above process and includes an integrated perception module, an edge computing unit, and a laser communication module. The integrated perception module integrates an electromagnetic radiation sensor, an infrared thermal imager, a controller area network interface, and a photon sequence generator to collect electromagnetic signals, thermal distribution data, network traffic, and photon pulses, respectively. The data is stored in a layered cache format, with high-risk signals prioritized. The edge computing unit contains a field-programmable gate array accelerator that runs a topological immune reconstruction algorithm, a photon trajectory aggregation algorithm, and a cross-domain trajectory fusion algorithm to process the collected data and generate defense instructions. The hardware is interconnected via a high-speed serial bus, transmitting encrypted data with a data volume controlled within 16 gigabytes per second. The edge computing unit operates in a master-slave architecture, with the master control unit coordinating the tasks of the sensor and communication modules, and the submodules executing specific algorithms and data processing. When an anomaly is detected, the system triggers a priority interrupt, suspending non-critical tasks and prioritizing defense decisions.

[0053] The entire workflow is coordinated through a hierarchical control flow. In-vehicle edge computing nodes prioritize local data analysis, generate threat signature sequences, and trigger subsequent engines. Onboard communication interfaces ensure secure data exchange between the controller area network (CAN), Ethernet, and photonic communication units. Regional collaboration modules integrate multi-vehicle intelligence through laser communication to optimize defense strategies. From topologically adaptive immune analysis to electromagnetic and thermal collaborative detection, the system forms a multi-layered detection and defense chain, safeguarding the in-vehicle network from intrusion threats. Specific embodiment two:

[0055] like Figure 1-2 As shown, the key algorithms mentioned in Example 1 are analyzed in detail below, including their core mathematical formulas and explanations:

[0056] Topological immune reconstruction algorithm:

[0057]

[0058] The S in the formula t The threat signature sequence at time t is a vector used to quantify the degree of network anomaly and is analyzed by Sp2's geometric flow threat tracking engine. It is generated by comprehensive calculation of CAN traffic, electronic control unit status, and sensor signals. i is the number of the network node, ranging from 1 to N, representing an in-vehicle electronic control unit or gateway, such as a brake control unit or autonomous driving module, extracted from the CAN topology. N is the total number of nodes in the network, usually the number of in-vehicle electronic control units, defining the analysis scope to ensure coverage of all critical devices. It is determined by scanning the network topology at system startup. i is the trust weight of node i, with a value between 0 and 1, simulating immune competition. High-trust nodes such as core gateways have higher weights, while abnormal nodes have lower weights. The initial value is the average value and is dynamically adjusted based on historical behavior. iis the controller area network traffic feature of node i, which represents the frequency and size of data packets and captures traffic patterns. Abnormal traffic, such as forged instructions, will cause feature changes. It is obtained by parsing the time series generated by the traffic acquisition unit in Sp1. t is the state feature of the electronic control unit of node i, which represents the voltage and computing load changes and reflects the operating status of the device. Abnormalities such as voltage fluctuations indicate potential attacks. It comes from the key-value pair data extracted by the state parser in Sp1. i is the vehicle body sensor signal feature of node i, representing the normalized vector of acceleration and temperature, capturing changes in the physical environment. Abnormalities such as sudden temperature rise may be related to attacks and are generated by the sensor interface in Sp1 through adaptive filtering; φ(T i ,V i ,A i ) is the feature fusion function of node i, which combines traffic, state, and sensor data to simulate immune competition to evaluate the abnormality of node behavior. It is designed as a vector sum and is based on dynamic mapping of three types of data; λ is the trust adjustment coefficient, which has a value between 0 and 1. It balances the current features and historical trust to prevent misjudgment. It is set during system initialization and adjusted according to feedback during operation; U t is the global trust vector at time t, which represents the overall trust status of the network, integrates the trust of all nodes to reflect the health of the network, and is iteratively updated based on the historical threat feature sequence.

[0059] Working method:

[0060] The topology immune reconstruction algorithm runs in Sp1, and the traffic collection unit parses the controller area network data packets to generate the time series T i , the state analyzer extracts the ECU voltage and the load generation V i ,The sensor interface collects acceleration and temperature to generate vector A i The three types of data are stored in the ring buffer, with high-frequency data packets being cached first. The inference core calculates φ(T i ,V i ,A i ), fusion features, combined with trust weight w i and global trust U t , generate threat signature sequence S t The sequence is encrypted in a serialized format and transmitted to the Sp2 via the in-vehicle Ethernet. The engine operates in state machine mode, sampling every 50 milliseconds under normal conditions and switching to every 5 milliseconds when an abnormality occurs.

[0061] Curvature Pulse Chasing Algorithm:

[0062]

[0063] The C in the formula tThe topological curvature anomaly summary at time t is a compressed vector that quantifies topological changes for broadcasting by the laser communication unit to surrounding vehicles. It is calculated based on the in-vehicle network topology and the Internet of Vehicles communication data. e is an edge in the network topology, representing the communication link between nodes. Abnormal edges such as forged links will cause curvature deviation and come from the adjacency table generated by the topology acquisition module in Sp2. E is the edge set of the network topology, including all links between nodes, defining the scope of topological analysis to cover in-vehicle and Internet of Vehicles communications, and is extracted by the topology acquisition module in Sp2. e is the curvature weight of edge e, reflecting the geometric importance of the edge. Key edges such as brake command paths are more sensitive to anomalies. It is initialized and dynamically updated based on the flow and delay of the edge. e is the weighted feature of edge e, which represents the weight of the IoV communication data, such as the amount of data, and captures the communication pattern on the edge. Anomalies such as high latency indicate attacks. It is obtained by parsing the weighted edge sequence generated by the IoV data in Sp2; S t is the threat signature sequence passed in by Sp1, providing node-level anomaly information to guide edge curvature analysis, and the TIRA output from Sp1 is transmitted via the in-vehicle Ethernet; ψ(W e ,S t ) is the pulse function of edge e, which combines weighted features and threat sequences to calculate the curvature pulse on the edge to detect topological mutations. It is designed as a dynamic mapping of the feature vector; μ is the geometric adjustment coefficient, which has a value between 0 and 1 and balances the current curvature with the historical geometric state. It is set during system initialization and adjusted during operation; G t It is the global geometric vector at time t, representing the overall state of the topology, providing topological historical background to enhance detection stability, and is iteratively updated based on the historical curvature summary.

[0064] Working method:

[0065] The curvature pulse pursuit algorithm runs in Sp2, the topology acquisition module updates the adjacency table to generate E, and parses the Internet of Vehicles data to generate W e The curvature analyzer is based on S t , calculate ψ(W e ,S t ), combined with the weight κ e and global geometry G t , generate summary C t The summary is stored as a sparse vector and broadcast via the optical pulse threat sharing protocol. The protocol's pulse encoder maps the summary into an interval-coded sequence, which is transmitted by a laser transmitter, decoded by a photon receiver, and verified for integrity by an error-checking unit. The engine operates in an event-driven mode, prioritizing topology mutations and triggering Sp3 when anomalies occur.

[0066] Photon trajectory aggregation algorithm:

[0067]

[0068] The D in the formula t Represents the deviation vector at time t, quantifies the degree of abnormality of the photon sequence, and is used for trajectory analysis based on the photon sequence in Sp4 or the upload area collaboration module; k is the number of the photon pulse sample, ranging from 1 to K, identifying a single photon event within the time window, and is output by the photon sequence generator in Sp3; K is the total number of photon samples in the time window, defining the analysis range, usually 100,000 samples per second, and is configured according to channel requirements; α k is the weight of sample k, reflecting its importance, giving priority to samples with high signal strength, initialized and dynamically adjusted based on channel properties; P k is the actual photon trajectory of sample k, representing the position and time vector, capturing the real path of the photon in the channel, measured by the photon sequence generator in Sp3; Q k is the expected photon trajectory of sample k, representing the normal path, which is used as a reference for deviation detection and is pre-calculated based on historical channel data; τ(P k ,Q k ) is the trajectory deviation function of sample k, which calculates the difference between the actual and expected trajectories and is designed as a vector distance function; β is the deviation history coefficient, which has a value between 0 and 1 and balances the current deviation with the historical record. It is set during system initialization and dynamically adjusted; H t It is the historical deviation vector at time t, which stores past deviations to detect persistent anomalies and is iteratively updated by the anomaly storage unit in Sp3.

[0069] How it works:

[0070] The photon trajectory aggregation algorithm runs in Sp3, and the photon sequence generator assigns pulse sequences to channels to generate P k , stored in time window encoding. The trajectory analyzer calculates τ(P k ,Q k ), combined with the weight α k and historical deviation H t , generating D t The deviation vector is stored as a high-dimensional tensor and uploaded to the regional coordination module via a post-quantum encrypted channel. The engine runs in a 20-millisecond cycle, suspending low-priority channels and triggering Sp4 in the event of an anomaly.

[0071] Causal Ripple Prediction Algorithm:

[0072]

[0073] The R in the formula trepresents the attack path sequence at time t, describing the nodes and links of the attack propagation, guiding the isolation controller to generate instructions based on causal interactions and Sp3 deviation data; p is the number of the causal interaction path, belonging to the set P, identifying the instruction flow from the sensor to the electronic control unit, extracted by the causal acquisition unit in Sp4; P is the set of causal interaction paths, covering all sensor-electronic control unit dependencies, generated based on network topology and instruction flow; p is the weight of path p, reflecting its criticality, giving priority to protecting critical paths such as brake commands, initialized based on system design and dynamically updated; I p is the instruction flow characteristic of path p, indicating the data rate and type, describing the sensor-ECU communication behavior, and obtained from the time-series directed graph parsed by the causal acquisition unit in Sp4; D t is the bias vector passed into Sp3, guiding the path prediction to highlight abnormal channels, PTAA output from Sp3; ω(I p ,D t ) is the ripple diffusion function of path p, simulating the propagation of attacks along the causal path, and is designed as a graph propagation model; δ is the path memory coefficient, which is between 0 and 1, balancing the current prediction and the historical path, and is set and dynamically adjusted during system initialization; M t It is a sequence of historical attack paths at time t, which stores past predictions to optimize the current analysis and is iteratively updated by the path cache in Sp4.

[0074] How it works:

[0075] The causal ripple prediction algorithm runs in Sp4, and the causal acquisition unit parses the instruction stream and generates a time sequence directed graph I p The ripple predictor is based on D t , calculate ω(I p ,D t ), combined with the weight γ p and historical path M t , generating R t The path sequence is stored in a sparse matrix and multicast to the ECU via the CAN. The engine runs asynchronously and triggers Sp5 when the prediction fails.

[0076] Cross-domain trajectory fusion algorithm:

[0077]

[0078] The F in the formula trepresents the fused trajectory vector at time t, describing the joint attack characteristics and generating a positioning report to show the attack location based on electromagnetic, thermal, and flow data; m is the data field number, belonging to the set M, including electromagnetic, thermal, and flow, identifying the type of signal analyzed, defined by the sensor in Sp5; M is the data field set, including electromagnetic, thermal, and flow, covering the network and physical attack surface, fixed by the system design; η m is the weight of domain m, reflecting its reliability, giving priority to stable domains such as thermal signals, initialized based on sensor calibration and dynamically adjusted; E m is the electromagnetic trajectory, only when m is the electromagnetic domain, representing the frequency spectrum, capturing electromagnetic anomalies such as equipment tampering, collected by the electromagnetic radiation sensor in Sp5; H m is the thermal trajectory, which is generated by the Sp5 mid-infrared thermal imager only when m is a thermal domain, representing a thermal map to detect overheating caused by physical attacks; t is the traffic trajectory, only when m is the traffic domain, it represents the attack path sequence of Sp4, guiding the cross-domain fusion to highlight the network attack, from the CWPA output of Sp4; χ(E m ,H m ,R t ) is the trajectory fusion function of domain m, which aligns cross-domain signals to detect associated anomalies and is designed as a tensor decomposition model; θ is the cross-domain memory coefficient, which has a value between 0 and 1 and balances the current fusion with the historical records. It is set during system initialization and dynamically adjusted; X t It is the historical fusion trajectory vector at time t, which retains the past fusion results to enhance stability and is iteratively updated by the local cache in Sp5.

[0079] How it works:

[0080] The cross-domain trajectory fusion algorithm runs in Sp5, and the electromagnetic radiation sensor collects the frequency spectrum E m ,Infrared thermal imager generates heat map H m ,Traffic parser based on R t Generate packet statistics vector. The three types of data are fused into χ(E m ,H m ,R t ), combined with the weight η m and historical trajectory X t , generate F t The fused vectors generate a compressed positioning report, which is transmitted to the central control screen via the vehicle's Ethernet. The engine operates in a multi-threaded pipeline, issuing an alarm upon confirmation of an attack. Specific embodiment three:

[0082] like Figure 1-2 The following is a description of the specific application logic steps of each module and algorithm in the real-time intrusion detection system for new energy vehicle in-vehicle networks based on edge computing:

[0083] The core modules of the system include in-vehicle edge computing nodes, on-board communication interfaces, and regional collaboration modules. They operate collaboratively through hierarchical control flows. The in-vehicle edge computing nodes prioritize local data, while the regional collaboration modules integrate multi-vehicle intelligence and dynamically adjust defense strategies. Specifically, intrusion detection and defense are achieved through five steps, Sp1 to Sp5. Each step corresponds to a module and algorithm. The application logic steps are as follows. Sp1 uses a topology adaptive immune parsing engine and a topology immune reconstruction algorithm. First, the traffic collection unit parses the controller area network data packets, extracts the sending frequency and size of the data packets, generates a time series and stores it in a ring buffer. The state parser extracts the voltage and computational load changes of the electronic control unit, generates key-value pair data, and the sensor interface collects the vehicle body acceleration and temperature signals. A standardized vector is generated through adaptive filtering. The three types of data are stored in a ring buffer through time alignment. High-frequency data packets are cached first to ensure fast access. The inference core simulates immune competition between network nodes, dynamically adjusts the node trust weight by analyzing traffic, status and sensor data, and generates a threat feature sequence. The sequence is encrypted in a serialized format and transmitted to the main control unit of the edge computing node via the in-vehicle Ethernet. The engine runs in state machine mode, sampling every fifty milliseconds under normal circumstances. When abnormal traffic or state changes are detected, it switches to a high-frequency sampling of every five milliseconds and triggers Sp2. Sp2 uses a geometric manifold threat tracking engine and a curvature pulse tracking algorithm. The topology acquisition module updates the adjacency relationship of the in-vehicle network, generates an adjacency table and stores it in the form of a low-rank matrix. At the same time, it parses the vehicle network communication data to generate a weighted edge sequence, which is stored in the local cache. The curvature analyzer receives the threat feature sequence of Sp1, analyzes the geometric characteristics of the network topology, and calculates the topology curvature offset to detect abnormal mutations, such as forged links or node isolation. The threat summary generator compresses the curvature offset data into a fixed-bit-length summary and stores it in the form of a sparse vector. The laser communication unit broadcasts the summary through the optical pulse threat sharing protocol. The pulse encoder in the protocol maps the summary into an interval coding sequence. The laser transmitter sends the pulse sequence, the photon receiver decodes the data, and the error checking unit verifies the integrity to ensure transmission reliability. The data volume is controlled within 512 bytes per packet and is broadcast to vehicles within a radius of 300 meters. The engine runs in event-driven mode. The main thread handles topology acquisition and curvature analysis, and the child thread performs summary generation and broadcasting, prioritizes topology mutations, and triggers Sp3 after confirming the anomaly.Sp3 uses a photon state perturbation perception engine and a photon trajectory aggregation algorithm. The photon sequence generator allocates pulse sequences to key channels such as autonomous driving instructions and brake signals, generating 100,000 samples per second and storing them in the local cache in the form of time window encoding. The trajectory analyzer analyzes the trajectory deviation of the photon sequence, compares the actual trajectory with the expected trajectory, generates and stores the deviation vector sequence, and encodes the deviation anomaly data in a high-dimensional tensor and uploads it to the regional collaboration module through a post-quantum encryption channel. The single upload data segmentation is controlled within one thousand bytes. The anomaly storage unit caches historical deviation data to support subsequent analysis. The engine runs at a fixed cycle and performs trajectory deviation detection every twenty milliseconds. When a deviation anomaly is detected, the low-priority communication channel is suspended and Sp4 is triggered. The control flow is driven by a timer. The main thread coordinates photon sequence generation and deviation analysis, and the child thread handles the data upload task to ensure real-time performance. Sp4 uses a causal path defense engine and a causal ripple prediction algorithm. The causal acquisition unit parses the instruction stream data from the sensor to the electronic control unit, generates a time-series directed graph and stores it in a sparse matrix format. The ripple predictor receives the deviation anomaly data from Sp3, simulates the ripple diffusion of the attack path, generates an attack path sequence, and stores it in a time-sliced form. The data volume of each slice is controlled within fifty kilobytes. The isolation controller sends isolation instructions to the target electronic control unit according to the path sequence, and transmits them through the controller local area network multicast. The instruction data volume is controlled within five hundred kilobits per second. The path cache stores historical attack paths to support subsequent optimization. The engine runs in asynchronous mode. The main thread handles causal acquisition and ripple prediction, and the child thread executes isolation instruction sending. Sp5 is triggered when the path prediction fails. The control flow adopts a feedback loop design to dynamically adjust the prediction parameters to ensure defense accuracy. Sp5 uses an electromagnetic-thermal collaborative detection engine and a cross-domain trajectory fusion algorithm. The electromagnetic radiation sensor collects signals with a frequency range of 100 kHz to 3 GHz, generates a spectrum sequence and stores it. The infrared thermal imager generates a heat distribution map with a pixel resolution of 512 by 512 and stores it in a local cache. The traffic parser extracts traffic data from the controller area network and the in-vehicle Ethernet, generates a packet statistics vector, and the three types of data are fused through principal component analysis to generate a unified feature vector. The inference core receives the attack path sequence of Sp4, analyzes the trajectory correlation of electromagnetic, thermal and traffic, detects joint network and physical attacks, and generates a visual positioning report. The report is stored in an image compression format, and the data volume is controlled within two megabits per frame. It is transmitted to the central control display via the in-vehicle Ethernet. The engine runs in a multi-threaded pipeline mode. The main thread coordinates sensor data collection, and the sub-threads perform trajectory fusion and report generation in parallel. When the joint attack is confirmed, the driver is alerted through the voice interaction module and the process is terminated. The control flow uses multi-threaded scheduling, giving priority to high-risk signals to ensure timely positioning.The entire process is coordinated through hierarchical control flows. The edge computing nodes in the vehicle prioritize analyzing local data, generating threat feature sequences and triggering subsequent engines. The on-board communication interface ensures the secure exchange of data between the controller area network, Ethernet and photonic communication units. The regional collaboration module integrates multi-vehicle intelligence through the laser communication unit and optimizes defense strategies, forming multi-level detection and defense from topology adaptive immune analysis to electromagnetic thermal collaborative detection. Specific embodiment four:

[0085] like Figure 1-2 As shown, the following are specific use cases of the entire solution:

[0086] Use Case 1: Detecting and Protecting Against Controller Area Network Forged Command Attacks

[0087] Attack Background:

[0088] A new energy smart car was driving on the highway. An attacker hacked into the vehicle's gateway through a remote vulnerability, disguised himself as the brake control unit, and sent high-frequency forged brake commands to the controller area network in an attempt to disrupt the vehicle's normal driving. The frequency of the forged commands was abnormally high, and the voltage behavior of the forged node deviated from the normal range.

[0089] System response steps:

[0090] After the system is started, Sp1's topology adaptive immune parsing engine starts working. The traffic collection unit parses the controller local area network data packets and finds that the data packet sending frequency of the brake control unit has increased abnormally, far exceeding the ten times per second during normal driving, reaching fifty times per second. A time series is generated and stored in a ring buffer. The state parser extracts the voltage data of the unit and finds that the voltage fluctuation is abnormal, dropping from the normal 3.3 volts to 2.8 volts. Key-value pair data is generated. The sensor interface collects the vehicle acceleration and temperature signals, and generates a standardized vector after confirming that there is no abnormality. The three types of data are stored in the ring buffer through time alignment, and high-frequency data packets are cached first. The inference core runs the topology immune reconstruction algorithm, analyzes the traffic and state data, detects that the behavior of the forged node deviates from the normal mode, reduces its trust weight, generates a threat feature sequence, and transmits it to Sp2 through the in-vehicle Ethernet encryption. Sp2's geometric manifold threat tracking engine receives the threat signature sequence. The topology acquisition module updates the network adjacency, discovers abnormal links between forged nodes and gateways, parses the IoV communication data to generate a weighted edge sequence, and the curvature analyzer runs the curvature pulse tracking algorithm to detect topological curvature offsets and confirm the existence of forged links. The threat summary generator compresses the offset data into a fixed-bit-length summary and broadcasts it to surrounding vehicles via the optical pulse threat sharing protocol. The laser communication unit sends the summary to vehicles within a radius of 300 meters, alerting other vehicles to similar attacks. After the engine confirms the anomaly, Sp3 is triggered. Sp3's photon state perturbation perception engine assigns a photon sequence to the brake command channel. The photon sequence generator generates a pulse sequence. The trajectory analyzer runs the photon trajectory aggregation algorithm, discovers photon trajectory deviations, generates a deviation vector, and uploads it to the regional collaboration module. The engine suspends low-priority communication channels, triggering Sp4. Sp4's causal path defense engine parses the instruction stream from the sensor to the brake control unit, runs a causal ripple prediction algorithm, predicts the propagation path of the forged instructions, generates an attack path sequence, and then sends an isolation command to the forged node via a multicast to the controller's local area network, severing its communications. The path cache stores the attack path, triggering Sp5. Sp5's electromagnetic and thermal collaborative detection engine collects electromagnetic radiation and heat distribution data. The electromagnetic radiation sensor detects no anomalies, but the infrared thermal imager detects a temperature rise of 60 degrees Celsius in the area of the forged node. It then runs a cross-domain trajectory fusion algorithm, confirming that the attack is a network-layer forgery. A positioning report is generated and transmitted to the central control screen via the in-vehicle Ethernet. The voice interaction module issues an alarm, prompting the driver to check network security.

[0091] Defense results:

[0092] The system successfully detected the forged command attack, isolated the forged node, cut off its communication, and prevented interference with the braking system. The positioning report showed that the source of the attack was a gateway vulnerability. The driver stopped to check based on the alarm. Surrounding vehicles received a threat summary and strengthened their defenses in advance. The vehicle resumed normal driving, and the system recorded the attack path to optimize subsequent defenses.

[0093] Use Case 2: Detecting and Protecting Against Combined Electromagnetic Interference Attacks

[0094] Attack Background:

[0095] A new energy smart car was parked at a charging station. An attacker used electromagnetic interference equipment to emit high-frequency electromagnetic waves to the vehicle's autonomous driving control unit, causing the unit to overheat. At the same time, the attacker sent forged communication data through the Internet of Vehicles in an attempt to tamper with the autonomous driving instructions and interfere with the vehicle's driving path after it was started.

[0096] System response steps:

[0097] During system operation, Sp1's topology adaptive immune parsing engine activates. The traffic collection unit parses the controller area network (CAN) data packets and finds no abnormal traffic. The state analyzer extracts the voltage and load data of the autonomous driving control unit and detects an abnormal voltage fluctuation, rising from 3.3V to 3.8V, and an increase in load to 80%. Key-value pairs are generated. The sensor interface collects vehicle acceleration and temperature signals and detects a temperature rise of 55 degrees Celsius. Normalized vectors are generated and stored in a circular buffer. The inference core runs a topology immune reconstruction algorithm, detecting anomalies in the state and sensor data, reducing the trust weight of the autonomous driving control unit, and generating a threat signature sequence. This is then encrypted and transmitted to Sp2 via the in-vehicle Ethernet. Sp2's geometric manifold threat tracking engine receives the signature sequence. The topology collection module updates adjacency relationships and finds no topological anomalies. It then parses the IoV communication data and detects forged communication packets. The curvature analyzer runs a curvature pulse tracking algorithm, detecting an anomaly in the weighted edge sequence and confirming forged communication. The threat profile generator generates a summary and broadcasts it to surrounding vehicles via the laser communication unit, alerting them to electromagnetic attacks. The engine then triggers Sp3. Sp3's photon state perturbation perception engine assigns a photon sequence to the autonomous driving command channel. The trajectory analyzer runs a photon trajectory aggregation algorithm, detects deviations in the photon trajectory, generates a deviation vector, and uploads it to the regional coordination module. This suspends low-priority channels and triggers Sp4. Sp4's causal path defense engine parses the command stream from the sensor to the autonomous driving control unit, runs a causal ripple prediction algorithm, predicts the attack path, and generates a path sequence. The isolation controller sends an isolation command to the control unit, severing the counterfeit communication and triggering Sp5. Sp5's electromagnetic and thermal collaborative detection engine collects data. The electromagnetic radiation sensor detects an abnormal electromagnetic signal at a frequency of 2.4 GHz. The infrared thermal imager confirms that the temperature in the control unit area has risen to 60 degrees Celsius. The traffic analyzer analyzes the counterfeit communication data and runs a cross-domain trajectory fusion algorithm to confirm the combined electromagnetic interference and cyberattack behavior. A location report is generated, indicating that the attack source is an external electromagnetic device and a counterfeit vehicle network. The report is transmitted to the central control screen, and the voice interaction module issues an alarm, prompting the driver to stop charging and inspect the device.

[0098] Defense results:

[0099] The system detected a combined electromagnetic interference attack and isolated the forged communications of the autonomous driving control unit. The positioning report showed that the attack came from external electromagnetic equipment and the Internet of Vehicles. The driver stopped charging and removed the interfering equipment. Surrounding vehicles received a threat summary and shut down the Internet of Vehicles communications in advance. The vehicles returned to normal. The system recorded the attack characteristics to optimize the defense strategy.

[0100] Use Case 3: Detecting and Defending Against Multi-Vehicle Coordinated Attacks

[0101] Attack Background:

[0102] A new energy smart car was driving on a city road. Three malicious vehicles around it forged threat profiles through laser communication in an attempt to deceive the target vehicle's regional collaboration module. At the same time, one of the malicious vehicles sent forged steering commands through a controller local area network vulnerability to induce the target vehicle to deviate from its lane.

[0103] System response steps:

[0104] During system operation, Sp1's topology adaptive immune parsing engine activates. The traffic collection unit parses the controller area network (CAN) data packets and discovers an abnormal transmission frequency from the steering control unit, increasing from five times per second to thirty times per second. The state analyzer extracts voltage data, showing fluctuations decreasing from 3.3 volts to 3.1 volts. The sensor interface collects acceleration and temperature signals, finding no abnormalities. These three types of data are stored in a circular buffer. The inference core runs a topology immune reconstruction algorithm, detects abnormal traffic and state, reduces the trust weight of the steering control unit, generates a threat signature sequence, and transmits it to Sp2 via the in-vehicle Ethernet. Sp2's geometric manifold threat tracking engine receives the signature sequence. The topology collection module updates adjacency relationships, discovers forged links, parses IoV communication data, and receives a forged threat profile. The curvature analyzer runs a curvature pulse tracking algorithm, detects a topology curvature offset, and confirms forged communication. The threat profile generator generates a true profile and broadcasts it via the laser communication unit, overwriting the forged profile, alerting other vehicles to the coordinated attack and triggering Sp3. Sp3's photon state perturbation perception engine assigns a photon sequence to the steering command channel. The trajectory analyzer runs a photon trajectory aggregation algorithm, detects trajectory deviations, generates and uploads deviation vectors, suspends low-priority channels, and triggers Sp4. Sp4's causal path defense engine parses the command stream from the sensor to the steering control unit, runs a causal ripple prediction algorithm, predicts the attack path, generates a path sequence, isolates the controller, and cuts off communication with the forged node, triggering Sp5. Sp5's electromagnetic and thermal collaborative detection engine collects data and finds no electromagnetic or thermal anomalies. The traffic analyzer confirms the forged steering command, runs a cross-domain trajectory fusion algorithm, detects a network attack, and generates a positioning report indicating that the attack source is an external vehicle and a controller local area network vulnerability. The report is transmitted to the central control screen, and the voice interaction module issues an alarm, prompting the driver to slow down and check.

[0105] Defense results:

[0106] The system detected a multi-vehicle coordinated attack, cut off the forged steering command communication, broadcast the real threat summary, overwrote the forged information, and protected other vehicles. The positioning report showed that the attack came from an external vehicle and network vulnerability. The driver slowed down and repaired the vulnerability, and the vehicle resumed normal driving. The system recorded the attack pattern to optimize regional coordinated defense.

[0107]

[0108]

[0109] Detailed description of table data

[0110] Forged instruction attack (highway scenario):

[0111] Attack detection rate: 98.5%, Sp1 detected abnormal traffic (50 times per second, far exceeding the normal 10 times) and voltage fluctuation (2.8V lower than the normal 3.3V), and Sp2 confirmed the forged link.

[0112] False alarm rate: 1.2%, a small number of normal high-frequency instructions were misjudged.

[0113] Response time: 120 milliseconds. Sp1 detects the forged node, Sp4 isolates it, and Sp5 issues an alarm.

[0114] Data processing volume:

[0115] Sp1: 500KB, processes controller area network traffic, voltage, and sensor signals, with a large amount of traffic data.

[0116] Sp2: 300KB, processes the adjacency table and threat summary, and contains Internet of Vehicles communication data.

[0117] Sp3: 200KB, processes photon sequences and generates deviation vectors.

[0118] Sp4: 150KB, processes causal path data and generates attack path sequences.

[0119] Sp5: 100KB, generates a positioning report, involving only network layer data.

[0120] Isolation success rate: 97.0%, Sp4 isolated fake nodes, a few failed due to network delays.

[0121] Joint attack location accuracy: Not applicable, only for network layer attacks.

[0122] Broadcast coverage: 95.0%, Sp2 broadcasts threat profiles, covering 9.5 out of 10 vehicles.

[0123] Electromagnetic interference joint attack (charging station scenario):

[0124] Attack detection rate: 96.8%, Sp1 detects voltage (3.8V higher than the normal 3.3V) and temperature anomalies (60℃ higher than the normal 25℃), and Sp5 confirms electromagnetic interference.

[0125] False alarm rate: 1.5%, some temperature increases are mistakenly identified as attacks.

[0126] Response time: 150 milliseconds. Electromagnetic signal analysis takes a long time.

[0127] Data processing volume:

[0128] Sp1: 450KB, processes voltage and temperature data, with less flow data.

[0129] Sp2: 250KB, processes topology data and has a small amount of IoV communication data.

[0130] Sp3: 180KB, processes photon sequences, and has a small amount of channel data.

[0131] Sp4: 120KB, processes causal path data and has the smallest data size.

[0132] Sp5: 150KB, processes electromagnetic and thermal data, and the data volume increases due to cross-domain analysis.

[0133] Isolation success rate: 95.5%, Sp4 isolates forged communications, and a few electromagnetic interferences cause delays.

[0134] Joint attack positioning accuracy: 94.0%, Sp5 accurately locates electromagnetic and network attacks, and a few interference signals are missed.

[0135] Broadcast coverage rate: 92.0%, covering 9.2 vehicles, and some vehicles were not received due to obstruction.

[0136] Multi-vehicle coordinated attack (urban road scenario):

[0137] Attack detection rate: 97.2%, Sp1 detects traffic anomalies (30 times per second, 5 times higher than normal), and Sp2 identifies forged threat profiles.

[0138] False alarm rate: 1.0%, the attack characteristics are obvious and the false alarm rate is low.

[0139] Response time: 130 milliseconds. Sp2 broadcast coverage takes slightly longer.

[0140] Data processing volume:

[0141] Sp1: 480KB, processing traffic data, including forged instructions.

[0142] Sp2: 320KB, handles forged threat profiles, data size increases due to broadcasting.

[0143] Sp3: 210KB, processes photon sequences and has slightly more channel data.

[0144] Sp4: 160KB, processes causal path data, slightly more than the electromagnetic interference scenario.

[0145] Sp5: 110KB, generates a positioning report, involving only network layer data.

[0146] Isolation success rate: 96.5%. Sp4 isolated the forged nodes, and a few communications were not completely cut off.

[0147] Joint attack location accuracy: Not applicable, only for network layer attacks.

[0148] Broadcast coverage: 98.0%, covering 9.8 vehicles, with good communication effect in urban road environment.

[0149] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further restrictions, an element defined by the statement "comprising a reference structure" does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.

[0150] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A real-time intrusion detection system for new energy vehicle in-vehicle networks based on edge computing, characterized by: The system includes an in-vehicle edge computing node, an on-vehicle communication interface, and a regional collaboration module. The in-vehicle edge computing node, the on-vehicle communication interface, and the regional collaboration module constitute a distributed collaborative architecture to achieve real-time intrusion detection and dynamic defense of the in-vehicle network. The in-vehicle edge computing node is deployed in the vehicle electronic control unit and gateway to collect and analyze network traffic and sensor data and execute local defense decisions. The on-vehicle communication interface integrates the controller area network, the in-vehicle Ethernet, and the photonic communication unit to ensure the secure exchange of data inside and outside the vehicle. The regional collaboration module coordinates the sharing of threat intelligence among multiple vehicles through laser communication to form a regional defense network. The in-vehicle edge computing node, the on-vehicle communication interface, and the regional collaboration module operate collaboratively through hierarchical control flow. The in-vehicle edge computing node prioritizes local data. The regional collaboration module integrates multi-vehicle intelligence and dynamically adjusts the defense strategy. The system achieves its goals through the following steps: Sp1: A topology-adaptive immune parsing engine collects controller area network traffic, electronic control unit status data, and vehicle body sensor signals, and runs a topology-adaptive immune reconstruction algorithm to generate a threat signature sequence. When utilizing data, the topology-adaptive immune parsing engine stores controller area network traffic in a ring buffer as a time series, parses electronic control unit status data in a key-value pair format, and generates a feature vector through adaptive filtering of sensor signals. The threat signature sequence is transmitted to the edge computing node master unit via the in-vehicle Ethernet and encrypted with a dynamic key. The engine operates in state machine mode, sampling every 50 milliseconds. When an anomaly is detected, it switches to high-frequency sampling and jumps to Sp2. Sp2: The geometric manifold threat tracking engine collects in-vehicle network topology and IoV communication data. Based on the threat signature sequence of Sp1, a curvature pulse tracking algorithm is run to detect topological curvature anomalies. The threat summary is broadcast using the optical pulse threat sharing protocol. Topological data is stored in an adjacency table, and IoV data is parsed into a weighted edge sequence. The threat summary is broadcast to surrounding vehicles via a laser communication unit, using pulse coding to compress the data. The engine operates in event-driven mode, prioritizing topological mutations and jumping to Sp3 upon confirmation of an anomaly. Sp3: The photon state disturbance perception engine generates photon sequences to protect critical communication channels and runs a photon trajectory aggregation algorithm to detect trajectory deviations. Photon sequences are stored in time window encoding, and deviation data is analyzed in the form of vector sequences. Deviation anomaly data is uploaded to the regional collaboration module via a post-quantum encryption channel. The engine runs the photon trajectory aggregation algorithm at a fixed period. When an anomaly is detected, low-priority communications are suspended and the process jumps to Sp4. Sp4: The causal path defense engine collects causal interaction records from sensors to electronic control units, runs a causal ripple prediction algorithm based on the deviation and abnormal data of Sp3 to generate an attack path sequence, and triggers a dynamic isolation strategy; Causal records are stored as time-series directed graphs, and ripple sequences are encoded as sparse matrices; The isolation instruction is multicast to the target ECU via the CAN; the engine operates in asynchronous mode and jumps to Sp5 when the prediction fails; Sp5: It collects electromagnetic radiation and thermal distribution data through an electromagnetic-thermal collaborative detection engine. Combined with the attack path sequence of Sp4, it runs a cross-domain trajectory fusion algorithm to detect joint cyber and physical attacks and generate a visual positioning report. Electromagnetic radiation data is stored as a spectrum sequence, thermal distribution data is saved as a pixel heat map, and network traffic is integrated as a packet statistical vector. The positioning report is transmitted to the central control display screen via the in-vehicle Ethernet in image compression format; the engine runs in multi-threaded pipeline mode, and after confirming the joint attack, an alarm is issued through the voice interaction module and the process is terminated.

2. The real-time intrusion detection system for new energy vehicle in-vehicle network based on edge computing according to claim 1 is characterized in that: The topology adaptive immune parsing engine in Sp1 consists of a traffic collection unit, a state parser, a sensor interface, and a topology immune reconstruction algorithm reasoning core. The working method is as follows: the traffic collection unit parses the controller area network data packet to generate a time series, the state parser extracts the voltage and load changes of the electronic control unit, the sensor interface collects acceleration and temperature signals to generate a standardized vector, and the reasoning core reconstructs the trust relationship by simulating node immune competition and outputs a threat feature sequence; the three types of data, namely the time series generated by the controller area network data packet, the voltage and load change data of the electronic control unit, and the standardized vectors of the vehicle body acceleration and temperature signals, are stored in a ring buffer through time alignment, and high-risk traffic is cached first; The threat signature sequence is encrypted in a serialized format and transmitted to Sp2’s geometric manifold threat hunting engine; The engine coordinates the collection tasks with the main thread, and the sub-thread runs the algorithm, triggering Sp2 when an exception occurs.

3. The real-time intrusion detection system for new energy vehicle in-vehicle network based on edge computing according to claim 1 is characterized in that: The topology immune reconstruction algorithm in Sp1 generates a threat signature sequence by dynamically adjusting the trust weights of network nodes, driving the curvature pulse tracking algorithm in Sp2 to analyze topology anomalies; The threat signature sequence is stored as a fixed-length vector encoding; the sequence is encrypted and transmitted to the geometric manifold threat tracking engine via the in-vehicle Ethernet; the topology immune reconstruction algorithm runs in state machine mode, switches to high-frequency sampling when an anomaly occurs, and notifies Sp2.

4. The real-time intrusion detection system for new energy vehicle in-vehicle network based on edge computing according to claim 1 is characterized in that: The geometric manifold threat tracking engine in Sp2 consists of a topology acquisition module, a curvature analyzer, a laser communication interface, and a threat summary generator. It works as follows: the topology acquisition module updates the network adjacency relationship within the vehicle, the curvature analyzer runs the curvature pulse tracking algorithm to calculate the topological curvature offset, the summary generator compresses the offset data into a fixed-bit-length summary, and the laser communication interface broadcasts the summary to surrounding vehicles. The adjacency relations are stored in the form of a low-rank matrix; the summary is transmitted to the engines of Sp4 and Sp5 in pulse coding format; The engine runs in event loop mode, and when the curvature is abnormal, the Sp3 photon state disturbance perception engine is triggered.

5. The real-time intrusion detection system for new energy vehicle in-vehicle network based on edge computing according to claim 1 is characterized in that: The optical pulse threat sharing protocol in Sp2 consists of a pulse encoder, a laser transmitter, a photon receiver, and an error checking unit. It works as follows: the pulse encoder maps the threat profile into an interval coding sequence, the laser transmitter sends the pulse sequence, the photon receiver decodes the data, and the error checking unit verifies the data integrity; the threat profile is stored as a sparse vector; the protocol transmits data through laser communication, supporting the isolation strategy of Sp4 and the joint detection of Sp5; the protocol operates in token scheduling mode, giving priority to transmitting high-risk profiles.

6. The real-time intrusion detection system for new energy vehicle in-vehicle network based on edge computing according to claim 1 is characterized in that: The photon state disturbance perception engine in Sp3 consists of a photon sequence generator, a trajectory analyzer, an encrypted communication interface, and an abnormality storage unit. Its working mode is as follows: the photon sequence generator allocates a pulse sequence to the autonomous driving command channel, the trajectory analyzer runs the photon trajectory aggregation algorithm to calculate the deviation vector, the encrypted communication interface uploads abnormal data, and the abnormality storage unit caches historical deviations; the deviation vector is stored in a sliding window; and the abnormal data is uploaded to the regional collaboration module in a fragmented form. Control flow: The engine uses a timer to drive the algorithm, and triggers Sp4's causal path defense engine when an exception occurs.

7. The real-time intrusion detection system for new energy vehicle in-vehicle network based on edge computing according to claim 1 is characterized in that: The photon trajectory aggregation algorithm in Sp3 detects communication channel anomalies by aggregating photon sequence trajectory deviations, driving the causal ripple prediction algorithm in Sp4 to generate an attack path sequence; trajectory deviation data is stored in high-dimensional tensor encoding; abnormal data is uploaded to the regional collaboration module through an encrypted channel; the photon trajectory aggregation algorithm runs in pipeline mode, notifying Sp4 to execute defense.

8. The real-time intrusion detection system for new energy vehicle in-vehicle network based on edge computing according to claim 1 is characterized in that: The causal path defense engine in Sp4 consists of a causal acquisition unit, a ripple predictor, an isolation controller, and a path cache. The working method is as follows: the causal acquisition unit parses the instruction stream from the sensor to the electronic control unit, the ripple predictor runs the causal ripple prediction algorithm to generate the attack path sequence, the isolation controller sends the isolation instruction to the target electronic control unit, and the path cache stores the historical path; the causal data is stored in a sparse matrix; The isolation instruction is multicast to the electromagnetic thermal collaborative detection engine of Sp5 through the controller local area network; the engine runs in asynchronous mode and triggers Sp5 when the prediction fails.

9. The real-time intrusion detection system for new energy vehicle in-vehicle network based on edge computing according to claim 1 is characterized in that: The causal ripple prediction algorithm in Sp4 generates a path sequence by simulating the ripple diffusion of the attack path, driving the cross-domain trajectory fusion algorithm in Sp5 to locate the joint attack; the ripple sequence is stored in a time-sliced form; the path sequence is encrypted and multicasted through the controller local area network; the causal ripple prediction algorithm operates in a feedback loop mode and dynamically adjusts the prediction parameters.

10. The real-time intrusion detection system for new energy vehicle in-vehicle network based on edge computing according to claim 1 is characterized in that: The system includes the following hardware to support the coordinated operation of Sp1 to Sp5: An integrated sensing module, including an electromagnetic radiation sensor, an infrared thermal imager, a controller area network interface, and a photon sequence generator, collects electromagnetic signals, thermal distribution data, network traffic, and photon pulses; Edge computing unit, including field-programmable gate array accelerator, runs topology immune reconstruction algorithm, photon trajectory aggregation algorithm, and cross-domain trajectory fusion algorithm; Laser communication module, containing laser emitters and photon detectors, to implement optical pulse threat sharing protocols; Perception data is stored in a hierarchical cache, with high-risk signals prioritized. Hardware is interconnected via a high-speed serial bus to transmit encrypted data. Edge computing units operate in a master-slave architecture to coordinate sensor and communication tasks.

Citation Information

Cited By

  • Intelligent automobile sensor data correction method and system based on safety monitoring

    CN120744795A

  • Forest disaster early warning method and system based on Internet of Things and edge calculation

    CN121121929A