Threat perception method and device for intrusion detection model
By identifying abnormal models through a heterogeneous intrusion detection model pool, voting algorithm, and confidence weight, and then cleaning and retraining them on a cloud platform, the vulnerability of intrusion detection models for intelligent connected vehicles is solved, thereby improving the accuracy and security of vehicle status detection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- PURPLE MOUNTAIN LAB
- Filing Date
- 2022-09-01
- Publication Date
- 2026-04-17
AI Technical Summary
Intrusion detection models for intelligent connected vehicles are vulnerable to hacker attacks, leading to abnormal detection results, affecting vehicle control functions, and threatening inherent security.
A heterogeneous intrusion detection model pool is adopted. By acquiring vehicle data, the heterogeneous intrusion detection model outputs detection results. The voting algorithm and confidence weight are used to perceive abnormal models. When an anomaly is detected, it is cleaned. The abnormal model is retrained using a cloud platform.
It improves the threat perception capability of intrusion detection models, ensures the accuracy of abnormal vehicle status detection, defends against unknown threats, and safeguards the inherent security of intelligent connected vehicles.
Smart Images

Figure CN115632808B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of artificial intelligence technology, and in particular to a threat perception method and apparatus for intrusion detection models. Background Technology
[0002] With the development of artificial intelligence technology, intelligent connected vehicles have become an important development direction in the automotive industry, bringing convenience to people's work and life. However, this has also correspondingly increased the number of Electronic Control Units (ECUs) and interfaces inside vehicles. This makes intelligent connected vehicles more vulnerable to cyberattacks. Hackers can easily intrude into the Controller Area Network (CAN), arbitrarily tamper with and forge CAN messages, and thus tamper with the ECU's control parameters, affecting vehicle control functions and even posing a risk to life. Therefore, using intrusion detection models to detect anomalies in the operating status of intelligent connected vehicles is a necessary means to ensure the inherent security of intelligent connected vehicles.
[0003] However, in practical applications, intrusion detection models that detect anomalies in the operating status of intelligent connected vehicles may also be subject to deliberate attacks by hackers, causing the intrusion detection model itself to be exposed to unknown threats, resulting in abnormal detection results and thus posing a serious threat to the inherent security of intelligent connected vehicles.
[0004] Therefore, improving the threat perception capabilities of intrusion detection models and ensuring the inherent security of intelligent connected vehicles and a safe driving environment are important issues that the industry urgently needs to address. Summary of the Invention
[0005] To address the problems existing in the prior art, the present invention provides a threat perception method and apparatus for intrusion detection models.
[0006] This invention provides a threat perception method for intrusion detection models, comprising:
[0007] Acquire vehicle data to be tested, wherein the vehicle data to be tested includes at least vehicle status, vehicle control commands, and vehicle configuration information;
[0008] The vehicle data to be detected is input into the heterogeneous intrusion detection model pool to obtain the detection results output by each heterogeneous intrusion detection model, wherein each heterogeneous intrusion detection model is trained based on vehicle data samples;
[0009] Based on the detection results, the abnormal intrusion detection models in the heterogeneous intrusion detection model pool are perceived.
[0010] Based on the detection results, the threat perception result of the heterogeneous intrusion detection model pool is determined;
[0011] If the presence of the abnormal intrusion detection model is detected in the heterogeneous intrusion detection model pool, the abnormal intrusion detection model is cleaned.
[0012] Optionally, the step of inputting the vehicle detection data into a heterogeneous intrusion detection model pool to obtain the detection results output by each heterogeneous intrusion detection model includes:
[0013] The vehicle data to be detected is copied into N independent copies;
[0014] The N independent vehicle detection data sets are input into the heterogeneous intrusion detection model pool to obtain the detection results output by each heterogeneous intrusion detection model. Each heterogeneous intrusion detection model corresponds to one vehicle detection data set, and the detection result is a numerical value used to characterize the vehicle state, where N is a positive integer.
[0015] Optionally, the step of sensing abnormal intrusion detection models in the heterogeneous intrusion detection model pool based on each of the detection results includes:
[0016] The detection results are processed using a voting algorithm to perceive the abnormal intrusion detection models in the heterogeneous intrusion detection model pool.
[0017] Optionally, determining the threat perception result of the heterogeneous intrusion detection model pool based on each of the detection results includes:
[0018] Obtain the confidence weights of each of the heterogeneous intrusion detection models;
[0019] The detection results are weighted and summed with the confidence weights, and the threat perception result of the heterogeneous intrusion detection model pool is determined based on the weighted summation result.
[0020] Optionally, the weighted summation result is calculated using the following formula (1):
[0021]
[0022] Wherein, V(A,W,t) represents the weighted summation result; This represents the detection result of the i-th heterogeneous intrusion detection model at time t; Let A represent the confidence weight of the i-th heterogeneous intrusion detection model at time t; let A represent the set of detection results of N heterogeneous intrusion detection models; and let W represent the set of confidence weights of N heterogeneous intrusion detection models.
[0023] Optionally, the cleaning process for the abnormal intrusion detection model includes:
[0024] The abnormal intrusion detection model is removed from the heterogeneous intrusion detection model pool and sent to the cloud platform so that the cloud platform can retrain the abnormal intrusion detection model.
[0025] Based on the attribute information of the heterogeneous intrusion detection model pool and each heterogeneous intrusion detection model in the cloud platform, the priority of each heterogeneous intrusion detection model in the cloud platform is determined; based on the priority, a target heterogeneous intrusion detection model in the cloud platform is determined, wherein the attribute information includes at least model type, model algorithm, model parameters, and model training data; the target heterogeneous intrusion detection model is a normal heterogeneous intrusion detection model.
[0026] Add the target heterogeneous intrusion detection model to the heterogeneous intrusion detection model pool.
[0027] The present invention also provides a threat perception device for an intrusion detection model, comprising:
[0028] The acquisition module is used to acquire vehicle data to be detected, wherein the vehicle data to be detected includes at least vehicle status, vehicle control commands and vehicle configuration information;
[0029] The input module is used to input the vehicle data to be detected into the heterogeneous intrusion detection model pool to obtain the detection results output by each heterogeneous intrusion detection model; wherein, each heterogeneous intrusion detection model is trained based on vehicle data samples;
[0030] The perception module is used to perceive the abnormal intrusion detection models in the heterogeneous intrusion detection model pool based on the detection results.
[0031] The determination module is used to determine the threat perception result of the heterogeneous intrusion detection model pool based on each of the detection results;
[0032] The processing module is used to clean the abnormal intrusion detection model when it detects the presence of the abnormal intrusion detection model in the heterogeneous intrusion detection model pool.
[0033] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the threat perception method for an intrusion detection model as described above.
[0034] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a threat perception method for an intrusion detection model as described above.
[0035] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements a threat perception method for an intrusion detection model as described above.
[0036] The threat perception method and apparatus for intrusion detection models provided by this invention can accurately determine whether a vehicle's status is abnormal by analyzing the detection results of each heterogeneous intrusion detection model in a heterogeneous intrusion detection model pool. Based on these detection results, it can proactively detect abnormal intrusion detection models in the heterogeneous intrusion detection model pool, thereby determining whether the entire heterogeneous intrusion detection model pool is under interference or network attack, thus improving the pool's ability to proactively perceive network threats. Furthermore, when abnormal intrusion detection models are detected in the heterogeneous intrusion detection model pool, these abnormal models are cleaned to prevent them from threatening the entire pool, enhancing the defense against unknown threats and ensuring the inherent security of intelligent connected vehicles. Attached Figure Description
[0037] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0038] Figure 1 This is one of the flowcharts of the threat perception method for intrusion detection models provided by the present invention;
[0039] Figure 2 This is the second flowchart of the threat perception method for intrusion detection models provided by the present invention;
[0040] Figure 3 This is a schematic diagram of the threat perception system for intrusion detection models provided by the present invention;
[0041] Figure 4 This is a schematic diagram illustrating the process of threat perception using a threat perception system targeting an intrusion detection model, as provided by the present invention.
[0042] Figure 5 This is a schematic diagram of the threat perception device for intrusion detection models provided by the present invention;
[0043] Figure 6 A schematic diagram of the physical structure of an electronic device is provided. Detailed Implementation
[0044] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0045] In recent years, with the rapid development of technologies such as intelligent transportation, autonomous driving, 5G, and cloud computing, intelligent connected vehicles have become an important development direction for the automotive industry, bringing convenience to people's work and life and providing more comfortable services through the integration and application of modern technologies. However, these conveniences and comforts increase the number of ECUs and interfaces inside vehicles, making intelligent connected vehicles more vulnerable to cyberattacks. Hackers can easily intrude into the CAN network, tamper with and forge CAN messages, thereby altering ECU control parameters, affecting vehicle control functions, and even posing risks to life. Therefore, using intrusion detection models to detect anomalies in the operating status of intelligent connected vehicles is a necessary means to ensure the inherent security of intelligent connected vehicles.
[0046] However, in practical applications, intrusion detection models that detect anomalies in the operating status of intelligent connected vehicles may also be subject to deliberate attacks by hackers, causing the intrusion detection model itself to be exposed to unknown threats, resulting in abnormal detection results and thus posing a serious threat to the inherent security of intelligent connected vehicles.
[0047] To address the aforementioned issues, this invention provides a threat perception method for intrusion detection models, thereby improving the threat perception capabilities of intrusion detection models and ensuring the inherent security of intelligent connected vehicles and a safe driving environment.
[0048] The following is combined with Figures 1-2 The threat perception method for intrusion detection models provided by this invention will be described in detail.
[0049] It should be noted that the executing entity of this invention can be any in-vehicle electronic device in an intelligent connected vehicle that has threat perception functionality against intrusion detection models. It is understood that the threat perception method against intrusion detection models provided by this invention is only illustrated using an intelligent connected vehicle as an example; the threat perception method against intrusion detection models provided by this invention can also be applied to intelligent aircraft, ships, etc.
[0050] See Figure 1 , Figure 1 This is one of the flowcharts of the threat perception method for intrusion detection models provided by the present invention, specifically including steps 101-105.
[0051] Step 101: Obtain vehicle data to be inspected.
[0052] Specifically, in this embodiment, it is first necessary to obtain vehicle detection data, which includes at least the vehicle status, vehicle control commands, and vehicle configuration information of the intelligent connected vehicle.
[0053] For example, vehicle status can be vehicle speed, acceleration, position, braking, etc.; vehicle control commands can be commands to control windows, doors, air conditioning, etc.; vehicle configuration information can be information such as vehicle log files.
[0054] It is understood that in this embodiment, the vehicle data to be detected can be acquired in real time during vehicle operation, or historical vehicle data to be detected can be acquired. The present invention does not limit the method of acquiring vehicle data to be detected.
[0055] Step 102: Input the vehicle data to be detected into the heterogeneous intrusion detection model pool to obtain the detection results output by each heterogeneous intrusion detection model; wherein, each heterogeneous intrusion detection model is trained based on vehicle data samples.
[0056] In this embodiment, after obtaining the vehicle detection data, the vehicle detection data is input into the heterogeneous intrusion detection model pool to obtain the detection results output by each heterogeneous intrusion detection model in the heterogeneous intrusion detection model pool.
[0057] Among them, the detection results output by each intrusion detection model are numerical values used to characterize the vehicle state; in practical applications, the intrusion detection results can be represented by "0" or "1", specifically, "0" indicates that the vehicle state is normal, and "1" indicates that the vehicle state is abnormal; the detection results output by each heterogeneous intrusion detection model can be represented by the following formula (2):
[0058]
[0059] in, This represents the detection result of the i-th heterogeneous intrusion detection model at time t; This represents the vehicle detection data of the i-th heterogeneous intrusion detection model at time t; Λ represents the detection function of the i-th heterogeneous intrusion detection model; i This represents the threshold range for judging whether the vehicle data to be detected is normal, generated by the i-th intrusion detection model through training on a large number of vehicle data samples.
[0060] Specifically, the heterogeneous intrusion detection model pool utilizes the concept of ensemble learning models and is constructed from multiple heterogeneous intrusion detection models with multimodal features. Each heterogeneous intrusion detection model is independent of the others, and there is no interaction between them. When vehicle detection data is input into the heterogeneous intrusion detection model pool, each heterogeneous intrusion detection model can perform calculations on the vehicle detection data in parallel, thereby ensuring the independence between the heterogeneous intrusion detection models and avoiding threats to the entire heterogeneous intrusion detection model pool due to vehicle detection data contamination. This enhances the heterogeneous intrusion detection model pool's defense capability against unknown threats.
[0061] In practical applications, the heterogeneous intrusion detection models in the heterogeneous intrusion detection model pool can be various heterogeneous intrusion detection models such as decision trees, support vector machines, and neural networks (e.g., convolutional neural networks (CNNs) and recurrent neural networks (RNNs)). Each heterogeneous intrusion detection model is trained based on vehicle data samples. It is understood that vehicle data samples include at least the vehicle status, vehicle control commands, and vehicle configuration information of intelligent connected vehicles.
[0062] It should be noted that, due to the limited types of machine learning models such as decision trees, support vector machines, and neural networks, to further improve the heterogeneity of intrusion detection models within the heterogeneous intrusion detection model pool, for intrusion detection models of the same type, it is necessary to design and construct highly differentiated intrusion detection models from dimensions such as model training samples (i.e., vehicle data samples), learning algorithms, and parameter settings. For example, taking decision tree models as an example, different decision tree models can be constructed using different algorithms such as ID3 (Iterative Dichotomiser 3) and C4.5; different depths of decision tree models can also be set to construct multiple highly differentiated decision tree models.
[0063] Step 103: Based on the detection results, perceive the abnormal intrusion detection models in the heterogeneous intrusion detection model pool.
[0064] In this embodiment, after obtaining the detection results output by each heterogeneous intrusion detection model, it is necessary to actively perceive the abnormal intrusion detection models in the heterogeneous intrusion detection model pool based on each detection result. The abnormal intrusion detection model refers to the intrusion detection model in the heterogeneous intrusion detection model pool that has been attacked.
[0065] Understandably, since the abnormal intrusion detection model has been attacked, the detection results output by this heterogeneous intrusion detection model cannot indicate whether the vehicle status of the intelligent connected vehicle is abnormal.
[0066] Step 104: Based on the detection results, determine the threat perception results of the heterogeneous intrusion detection model pool.
[0067] In this embodiment, after obtaining the detection results output by each heterogeneous intrusion detection model, the final detection result (i.e., threat perception result) of the heterogeneous intrusion detection model pool can be determined by comprehensively evaluating each detection result. The threat perception result is used to characterize whether the entire heterogeneous intrusion detection model pool is under threat.
[0068] Step 105: If the abnormal intrusion detection model is detected in the heterogeneous intrusion detection model pool, the abnormal intrusion detection model is cleaned.
[0069] In this embodiment, when an abnormal intrusion detection model is detected in the heterogeneous intrusion detection model pool, the abnormal intrusion detection model needs to be cleaned to ensure that each heterogeneous intrusion detection model in the heterogeneous intrusion detection model pool is a normal heterogeneous intrusion detection model.
[0070] The threat perception method for intrusion detection models provided by this invention can accurately determine whether a vehicle's status is abnormal by analyzing the detection results of each heterogeneous intrusion detection model in a heterogeneous intrusion detection model pool. Based on these detection results, it can proactively detect abnormal intrusion detection models in the heterogeneous intrusion detection model pool, thereby determining whether the entire heterogeneous intrusion detection model pool is under interference or network attack, thus improving the pool's ability to proactively perceive network threats. Furthermore, when abnormal intrusion detection models are detected in the heterogeneous intrusion detection model pool, these abnormal models are cleaned to prevent them from threatening the entire pool, enhancing the defense against unknown threats and ensuring the inherent security of intelligent connected vehicles.
[0071] The following is a detailed description of the specific implementation of the threat perception method for intrusion detection models provided by this invention.
[0072] Optionally, in one possible implementation of this invention, the step of inputting the vehicle detection data into a heterogeneous intrusion detection model pool to obtain the detection results of each heterogeneous intrusion detection model can be implemented in the following way:
[0073] The vehicle data to be detected is copied into N independent copies;
[0074] The N independent vehicle detection data sets are input into the heterogeneous intrusion detection model pool to obtain the detection results output by each heterogeneous intrusion detection model. Each intrusion detection model corresponds to one vehicle detection data set, and the detection result is a numerical value used to characterize the vehicle state, where N is a positive integer.
[0075] In this embodiment, after obtaining the vehicle detection data, it is necessary to copy the vehicle detection data into N independent vehicle detection data and construct independent data transmission channel threads; then, based on the independent data transmission channel threads, the N independent vehicle detection data are input into the heterogeneous intrusion detection model to ensure the isolation of the input of each intrusion detection model.
[0076] After inputting N independent vehicle detection data into the heterogeneous intrusion detection model pool, the detection results output by each heterogeneous intrusion detection model are obtained.
[0077] In practical applications, when a heterogeneous intrusion detection model in the heterogeneous intrusion detection model pool receives vehicle data to be detected, each heterogeneous intrusion detection model can perform calculations on all the vehicle data to be detected and then output the detection results.
[0078] However, since the detection objects of each heterogeneous intrusion detection model are different, each heterogeneous intrusion detection model can also select vehicle status, vehicle control commands, vehicle configuration information and other data from the vehicle data to be detected as input data according to the different detection objects, and then output detection results.
[0079] In the above implementation, by copying the vehicle detection data into N independent copies, the isolation of the inputs of each heterogeneous intrusion detection model can be guaranteed, thus avoiding the threat to the entire heterogeneous intrusion detection model pool due to contamination of the vehicle detection data.
[0080] Optionally, in one possible implementation of this invention, the step of sensing the abnormal intrusion detection model in the heterogeneous intrusion detection model pool based on each of the detection results includes:
[0081] The detection results are processed using a voting algorithm to perceive the abnormal intrusion detection models in the heterogeneous intrusion detection model pool.
[0082] In this embodiment, after obtaining the detection results output by each heterogeneous intrusion detection model, a voting algorithm can be used to actively perceive the abnormal intrusion detection models in the heterogeneous intrusion detection model pool.
[0083] For example, in the heterogeneous intrusion detection model pool, if the detection result output by heterogeneous intrusion detection model 1 is "1", the detection result output by heterogeneous intrusion detection model 2 is "1", and the detection result output by heterogeneous intrusion detection model 3 is "0", then the intrusion detection model 3 is actively perceived as an abnormal intrusion detection model based on the voting algorithm.
[0084] In the above implementation, by using a voting algorithm to process each detection result, abnormal intrusion detection models in the heterogeneous intrusion detection model pool can be actively detected, thereby improving the threat perception capability of the intrusion detection model.
[0085] Optionally, in one possible implementation of this invention, determining the threat perception result of the heterogeneous intrusion detection model pool based on each of the detection results can be achieved in the following ways:
[0086] Obtain the confidence weights of each of the heterogeneous intrusion detection models;
[0087] The detection results are weighted and summed with the confidence weights, and the threat perception result of the heterogeneous intrusion detection model pool is determined based on the weighted summation result.
[0088] In this embodiment, the confidence weights of each heterogeneous intrusion detection model need to be obtained first. Let represent the confidence weight of the i-th heterogeneous intrusion detection model at time t. The confidence weight of each heterogeneous intrusion detection model at the initial time (t=0) can be randomly generated and satisfies the following conditions: Where N represents the number of heterogeneous intrusion detection models in the heterogeneous intrusion detection model pool.
[0089] It should be noted that the confidence weight of each heterogeneous intrusion detection model is different at different times, and the confidence weight of each heterogeneous intrusion detection model at the next time step can be updated periodically using the detection accuracy of historical vehicle data samples. Specifically, the confidence weight of each heterogeneous intrusion detection model can be updated using the following formulas (3) and (4):
[0090]
[0091]
[0092] Where l represents the number of historical vehicle data samples selected to calculate the confidence weights of each heterogeneous intrusion detection model; r i,k This represents the correctness value of the detection result of the k-th vehicle data sample of the i-th heterogeneous intrusion detection model. A correct detection is marked as 1, and otherwise as 0. N represents the number of heterogeneous intrusion detection models in the heterogeneous intrusion detection model pool. This represents the updated confidence weight value of the i-th heterogeneous intrusion detection model; denoted as the normalized confidence weight of the i-th heterogeneous intrusion detection model at time t+1.
[0093] After obtaining the confidence weights of each heterogeneous intrusion detection model, the detection results are weighted and summed with the confidence weights. The threat perception result of the heterogeneous intrusion detection model pool is determined based on the weighted summation result. In other words, the entire heterogeneous intrusion detection model pool can be determined as to whether it is under threat based on the weighted summation result.
[0094] Optionally, in one possible implementation of the present invention, the weighted summation result is calculated using the following formula (1):
[0095]
[0096] Wherein, V(A,W,t) represents the weighted summation result; This represents the detection result of the i-th heterogeneous intrusion detection model at time t; Let A represent the confidence weight of the i-th heterogeneous intrusion detection model at time t; let A represent the set of detection results of N heterogeneous intrusion detection models; and let W represent the set of confidence weights of N heterogeneous intrusion detection models.
[0097] It should be noted that after weighting and summing the detection results with the confidence weights to obtain the weighted sum V(A,W,t), the threat perception result of the heterogeneous intrusion detection model pool can be expressed by the following formula (5):
[0098]
[0099] Where R(A,W,t) represents the threat perception result of the heterogeneous intrusion detection model pool; σ represents the threshold for determining that the heterogeneous intrusion detection model pool is normal.
[0100] In the above implementation, by weighting and summing each detection result with a confidence weight, and determining the threat perception result of the heterogeneous intrusion detection model pool based on the weighted summation result, it is possible to determine whether the entire heterogeneous intrusion detection model pool is under threat, thereby improving the threat perception capability of the intrusion detection model and ensuring the inherent security of intelligent connected vehicles.
[0101] Optionally, in one possible implementation of this invention, the cleaning process for the abnormal intrusion detection model is specifically implemented in the following way:
[0102] The abnormal intrusion detection model is removed from the heterogeneous intrusion detection model pool and sent to the cloud platform so that the cloud platform can retrain the abnormal intrusion detection model.
[0103] Based on the attribute information of the heterogeneous intrusion detection model pool and each heterogeneous intrusion detection model in the cloud platform, the priority of each heterogeneous intrusion detection model in the cloud platform is determined; based on the priority, a target heterogeneous intrusion detection model in the cloud platform is determined, wherein the attribute information includes at least model type, model implementation algorithm, model parameter information, and model training data; the target heterogeneous intrusion detection model is a normal heterogeneous intrusion detection model;
[0104] Add the target heterogeneous intrusion detection model to the heterogeneous intrusion detection model pool.
[0105] In this embodiment, if an abnormal intrusion detection model is detected in the heterogeneous intrusion detection model pool, the abnormal intrusion detection model also needs to be cleaned. That is, the abnormal intrusion detection model first needs to be removed from the heterogeneous intrusion detection model pool and then sent to the cloud platform so that the cloud platform can retrain the abnormal intrusion detection model.
[0106] It should be noted that the cloud platform stores a large number of normal heterogeneous intrusion detection models, as well as sample data and computing and storage resources used to train abnormal intrusion detection models. Retraining abnormal intrusion detection models using the cloud platform can effectively save the limited resources of the vehicle terminal, thereby enabling lightweight deployment of the heterogeneous intrusion detection model pool.
[0107] In practical applications, cloud platforms can retrain the abnormal intrusion detection model using new or historical vehicle data samples, thereby restoring the abnormal intrusion detection model to normal operation.
[0108] When sending the abnormal intrusion detection model to the cloud platform, it is also necessary to determine the priority of each heterogeneous intrusion detection model in the cloud platform based on the heterogeneous intrusion detection model pool and the attribute information of each heterogeneous intrusion detection model in the cloud platform. The priority is used to determine the target heterogeneous intrusion detection model in the cloud platform; that is, the heterogeneous intrusion detection model with the highest priority in the cloud platform needs to be identified as the target heterogeneous intrusion detection model. It can be understood that the target heterogeneous intrusion detection model is a normal heterogeneous intrusion detection model in the cloud platform.
[0109] After the target heterogeneous intrusion detection model is determined, it is added to the heterogeneous intrusion detection model pool.
[0110] It should be noted that the priority of each heterogeneous intrusion detection model in the cloud platform is determined based on the attribute information of each heterogeneous intrusion detection model in the heterogeneous intrusion detection model pool. The purpose is to maximize the heterogeneity of each heterogeneous intrusion detection model in the heterogeneous intrusion detection model pool.
[0111] In practical applications, the attribute information of each heterogeneous intrusion detection model in the heterogeneous intrusion detection model pool and cloud platform includes at least the model type, model implementation algorithm, model parameters, and model training data. Specifically, the attribute information and priority of each heterogeneous intrusion detection model can be represented by Table 1, which shows the attribute information and priority of different heterogeneous intrusion detection models.
[0112] Table 1
[0113] Serial Number Attribute information of heterogeneous intrusion detection models Priority 1 Model type Level 1 2 Implementation Algorithm Level 2 3 Model parameters Level 3 4 Model training data Level 4
[0114] As shown in Table 1 above, when selecting a target heterogeneous intrusion detection model from the cloud platform, the attribute information of each heterogeneous intrusion detection model in the cloud platform is first compared with the attribute information of each heterogeneous intrusion detection model in the heterogeneous intrusion detection model pool. Firstly, heterogeneous intrusion detection models with different model types are selected as the target heterogeneous intrusion detection models. Secondly, heterogeneous intrusion detection models with different implementation algorithms are selected as the target heterogeneous intrusion detection models. Thirdly, heterogeneous intrusion detection models with different model parameters are selected as the target heterogeneous intrusion detection models. Finally, heterogeneous intrusion detection models with different training data are selected as the target heterogeneous intrusion detection models. This method ensures that the heterogeneity of each heterogeneous intrusion detection model in the heterogeneous intrusion detection model pool is maximized.
[0115] In the above implementation, by removing the abnormal intrusion detection model from the heterogeneous intrusion detection model pool and sending it to the cloud platform, the cloud platform can retrain the abnormal intrusion detection model, thereby preventing the abnormal intrusion detection model from threatening the entire heterogeneous intrusion detection model pool. At the same time, based on the priority of the heterogeneous intrusion detection models, the target heterogeneous intrusion detection model in the cloud platform is added to the heterogeneous intrusion detection model pool, thereby realizing the dynamic cleaning, repair and updating of the heterogeneous intrusion detection model pool under the limited resource constraints of the vehicle terminal, thus improving the defense capability against unknown network threats and ensuring the inherent security of intelligent connected vehicles.
[0116] Figure 2 This is the second flowchart of the threat perception method for intrusion detection models provided by the present invention, specifically including steps 201-208.
[0117] Step 201: Obtain vehicle data to be tested, which includes at least vehicle status, vehicle control commands, and vehicle configuration information.
[0118] Step 202: Copy the vehicle detection data into N independent vehicle detection data sets; input the N independent vehicle detection data sets into the heterogeneous intrusion detection model pool to obtain the detection results output by each heterogeneous intrusion detection model. Each heterogeneous intrusion detection model is trained based on vehicle data samples, and each heterogeneous intrusion detection model corresponds to one vehicle detection data set, where N is a positive integer.
[0119] Step 203: Process the detection results using a voting algorithm to actively perceive the abnormal intrusion detection models in the heterogeneous intrusion detection model pool (i.e., as mentioned above, perceive the abnormal intrusion detection models in the heterogeneous intrusion detection model pool based on the detection results).
[0120] Step 204: Obtain the confidence weights of each heterogeneous intrusion detection model.
[0121] Step 205: Perform a weighted summation of each detection result and the confidence weight, and determine the threat perception result of the heterogeneous intrusion detection model pool based on the weighted summation result.
[0122] Step 206: If an abnormal intrusion detection model is detected in the heterogeneous intrusion detection model pool, the abnormal intrusion detection model is removed from the heterogeneous intrusion detection model pool and sent to the cloud platform so that the cloud platform can retrain the abnormal intrusion detection model.
[0123] Step 207: Based on the attribute information of the heterogeneous intrusion detection model pool and each heterogeneous intrusion detection model in the cloud platform, determine the priority of each heterogeneous intrusion detection model in the cloud platform; determine the target heterogeneous intrusion detection model in the cloud platform based on the priority, wherein the attribute information includes at least the model type, model algorithm, model parameters and model training data; the target heterogeneous intrusion detection model is a normal heterogeneous intrusion detection model.
[0124] Step 208: Add the target heterogeneous intrusion detection model to the heterogeneous intrusion detection model pool.
[0125] The threat perception method for intrusion detection models provided by this invention can accurately determine whether a vehicle's status is abnormal by analyzing the detection results of each heterogeneous intrusion detection model in a heterogeneous intrusion detection model pool. Based on these detection results, it can proactively detect abnormal intrusion detection models in the pool, thereby determining whether the entire pool is under threat and improving its threat perception capability. Furthermore, upon detecting an abnormal intrusion detection model in the pool, it removes the abnormal model from the pool and sends it to the cloud platform, thus preventing the abnormal model from threatening the entire pool. Based on the priority of the heterogeneous intrusion detection models, it adds target heterogeneous intrusion detection models from the cloud platform to the pool, enabling dynamic cleaning, repair, and updating of the pool under the limited resource constraints of the vehicle terminal. This further enhances the threat defense capability of the pool and ensures the inherent security of intelligent connected vehicles.
[0126] See Figure 3 , Figure 3 This is a schematic diagram of a threat perception system for intrusion detection models provided by the present invention. The threat perception system includes an online detection platform 301 and a cloud platform 302. The online detection platform 301 includes a data distribution module 3011, a heterogeneous intrusion detection model pool 3012, a threat perception module 3013, and an anomaly model scheduling module 3014. The cloud platform includes a cleaning module 3021.
[0127] It should be noted that the threat perception system is deployed using an "offline rolling training + online real-time detection" approach. That is, the data distribution module 3011, the heterogeneous intrusion detection model pool 3012, the threat perception module 3013, and the anomaly model scheduling module 3014 are deployed on the vehicle terminal to perform real-time detection of the vehicle status of intelligent connected vehicles. The cleaning module 3021 requires a large amount of training data to retrain the anomaly intrusion detection model. Therefore, this part needs to be deployed on the cloud platform 302 (i.e., the anomaly intrusion detection model is retrained using vehicle data samples in the cloud platform training part), thereby achieving lightweight deployment and dynamic updates of the threat perception system.
[0128] Specifically, the process of threat perception using a threat perception system targeting intrusion detection models is as follows:
[0129] The data distribution module 3011 is used to copy N independent vehicle detection data sets and distribute the N independent vehicle detection data sets to each heterogeneous intrusion detection model in the heterogeneous intrusion detection model pool 3012 to obtain the detection results of each heterogeneous intrusion detection model in the heterogeneous intrusion detection model pool 3012; and send each detection result and the confidence weight of each heterogeneous intrusion detection model to the threat perception module 3013.
[0130] The threat perception module 3013 is used to receive the detection results and confidence weights of each heterogeneous intrusion detection model sent by the data distribution module 3011; based on the detection results, it actively perceives abnormal intrusion detection models in the heterogeneous intrusion detection model pool; when it perceives the existence of abnormal intrusion detection models in the heterogeneous intrusion detection model pool, it sends the abnormal intrusion detection models to the abnormal model scheduling module 3014; and determines the threat perception result of the heterogeneous intrusion detection model pool according to the detection results and confidence weights.
[0131] In other words, the threat perception module 3013 can not only determine the abnormal intrusion detection model in the heterogeneous intrusion detection model pool based on each detection result, but also determine the threat perception result of the heterogeneous intrusion detection model pool based on each detection result and the confidence weight.
[0132] The anomaly model scheduling module 3014 is used to remove the anomaly intrusion detection model from the heterogeneous intrusion detection model pool 3012, notify the data distribution module 3011 to stop distributing the data to be detected to the anomaly intrusion detection model, and send the anomaly intrusion detection model to the cloud platform 302; and add the target heterogeneous intrusion detection model in the cloud platform 302 to the heterogeneous intrusion detection model pool 3012.
[0133] The cleaning module 3021 is used to receive the abnormal intrusion detection model sent by the abnormal model scheduling 3014 and retrain the abnormal intrusion detection model using vehicle data samples.
[0134] For ease of understanding, see Figure 4 , Figure 4 This is a schematic diagram of the process of threat perception using a threat perception system targeting an intrusion detection model provided by the present invention, specifically including steps 401 to 407.
[0135] Step 401: The data distribution module 3011 copies N independent vehicle detection data sets and distributes the N independent vehicle detection data sets to the heterogeneous intrusion detection models in the heterogeneous intrusion detection model pool 3012.
[0136] Step 402: Each heterogeneous intrusion detection model in the heterogeneous intrusion detection model pool 3012 performs independent and parallel detection based on the vehicle data to be detected, and outputs the detection results of each heterogeneous intrusion detection model.
[0137] Step 403: The threat perception module 3013 makes a decision on the detection results of each heterogeneous intrusion detection model in the heterogeneous intrusion detection model pool 3012.
[0138] Step 404: Threat perception module 3013 determines whether there is an abnormal intrusion detection model in heterogeneous intrusion detection model pool 3012. If not, return to step 401; if yes, proceed to step 405.
[0139] Step 405: The anomaly model scheduling module 3014 removes the anomaly intrusion detection model from the heterogeneous intrusion detection model pool 3012.
[0140] Step 406: The anomaly model scheduling module 3014 adds the target heterogeneous intrusion detection model in the cloud platform to the heterogeneous intrusion detection model pool 3012, and then returns to execute step 401.
[0141] Step 407: The cleaning module 3021 cleans the abnormal intrusion detection model on the cloud platform (that is, as mentioned above, the abnormal intrusion detection model is retrained on the cloud platform using vehicle data samples).
[0142] The threat perception system for intrusion detection models provided by this invention can accurately determine whether a vehicle's status is abnormal by analyzing the detection results of each heterogeneous intrusion detection model in a heterogeneous intrusion detection model pool. Based on these detection results, it can proactively detect abnormal intrusion detection models in the pool, thereby determining whether the entire pool is under threat and improving its threat perception capability. Furthermore, upon detecting an abnormal intrusion detection model in the pool, it removes the abnormal model from the pool and sends it to the cloud platform, thus preventing the abnormal model from threatening the entire pool. Based on the priority of the heterogeneous intrusion detection models, it adds target heterogeneous intrusion detection models from the cloud platform to the pool, enabling dynamic cleaning, repair, and updating of the pool under the limited resource constraints of the vehicle terminal. This improves the threat defense capability of the pool and ensures the inherent security of the intelligent connected vehicle network anomaly detection system.
[0143] The following is combined with Figure 5 The threat perception device for intrusion detection models provided by the present invention will be described below. The threat perception device for intrusion detection models described below can be referred to in correspondence with the threat perception method for intrusion detection models described above. Figure 5 This is a schematic diagram of the threat perception device 500 for intrusion detection models provided by the present invention.
[0144] The acquisition module 501 is used to acquire vehicle detection data, wherein the vehicle detection data includes at least vehicle status, vehicle control commands and vehicle configuration information.
[0145] The input module 502 is used to input the vehicle data to be detected into the heterogeneous intrusion detection model pool to obtain the detection results output by each heterogeneous intrusion detection model; wherein, each heterogeneous intrusion detection model is trained based on vehicle data samples;
[0146] The perception module 503 is used to perceive the abnormal intrusion detection models in the heterogeneous intrusion detection model pool based on the detection results.
[0147] The determination module 504 is used to determine the threat perception result of the heterogeneous intrusion detection model pool based on each of the detection results;
[0148] The processing module 505 is used to clean the abnormal intrusion detection model when it is detected that the abnormal intrusion detection model exists in the heterogeneous intrusion detection model pool.
[0149] The threat perception device for intrusion detection models provided by this invention can accurately determine whether a vehicle's status is abnormal by analyzing the detection results of each heterogeneous intrusion detection model in a heterogeneous intrusion detection model pool. Based on these detection results, it can proactively detect abnormal intrusion detection models in the heterogeneous intrusion detection model pool, thereby determining whether the entire heterogeneous intrusion detection model pool is under interference or network attack, thus improving the pool's ability to proactively perceive network threats. Furthermore, when abnormal intrusion detection models are detected in the pool, the device updates the pool based on these abnormal models, preventing them from threatening the entire pool and enhancing its defense capabilities against unknown threats, thus ensuring the inherent security of intelligent connected vehicles.
[0150] Optionally, the input module 502 is further used for:
[0151] The vehicle data to be detected is copied into N independent copies;
[0152] The N independent vehicle detection data sets are input into the heterogeneous intrusion detection model pool to obtain the detection results output by each heterogeneous intrusion detection model. Each intrusion detection model corresponds to one vehicle detection data set, and the detection result is a numerical value used to characterize the vehicle state, where N is a positive integer.
[0153] Optionally, the sensing module 503 is further used for:
[0154] The detection results are processed using a voting algorithm to perceive the abnormal intrusion detection models in the heterogeneous intrusion detection model pool.
[0155] Optionally, module 504 is further configured to:
[0156] Obtain the confidence weights of each of the heterogeneous intrusion detection models;
[0157] The detection results are weighted and summed with the confidence weights, and the threat perception result of the heterogeneous intrusion detection model pool is determined based on the weighted summation result.
[0158] Optionally, the weighted summation result is calculated using the following formula (1):
[0159]
[0160] Wherein, V(A,W,t) represents the weighted summation result; This represents the detection result of the i-th heterogeneous intrusion detection model at time t; Let A represent the confidence weight of the i-th heterogeneous intrusion detection model at time t; let A represent the set of detection results of N heterogeneous intrusion detection models; and let W represent the set of confidence weights of N heterogeneous intrusion detection models.
[0161] Optionally, the processing module 505 is further configured to:
[0162] The abnormal intrusion detection model is removed from the heterogeneous intrusion detection model pool and sent to the cloud platform so that the cloud platform can retrain the abnormal intrusion detection model.
[0163] Based on the attribute information of the heterogeneous intrusion detection model pool and each heterogeneous intrusion detection model in the cloud platform, the priority of each heterogeneous intrusion detection model in the cloud platform is determined; based on the priority, a target heterogeneous intrusion detection model in the cloud platform is determined, wherein the attribute information includes at least model type, model algorithm, model parameters, and model training data; the target heterogeneous intrusion detection model is a normal heterogeneous intrusion detection model.
[0164] Add the target heterogeneous intrusion detection model to the heterogeneous intrusion detection model pool.
[0165] Figure 6 An example is a schematic diagram of the physical structure of an electronic device 600, such as... Figure 6As shown, the electronic device may include a processor 610, a communications interface 620, a memory 630, and a communication bus 640, wherein the processor 610, communications interface 620, and memory 630 communicate with each other via the communication bus 640. The processor 610 can call logical instructions in the memory 630 to execute a threat perception method for an intrusion detection model. This method includes: acquiring vehicle detection data, wherein the vehicle detection data includes at least vehicle status, vehicle control commands, and vehicle configuration information; inputting the vehicle detection data into a heterogeneous intrusion detection model pool to obtain detection results output by each heterogeneous intrusion detection model; wherein each heterogeneous intrusion detection model is trained based on vehicle data samples; based on each detection result, perceiving abnormal intrusion detection models in the heterogeneous intrusion detection model pool; based on each detection result, determining the threat perception result of the heterogeneous intrusion detection model pool; and, if the presence of an abnormal intrusion detection model in the heterogeneous intrusion detection model pool is detected, performing a cleaning process on the abnormal intrusion detection model.
[0166] Furthermore, the logical instructions in the aforementioned memory 630 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0167] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the threat perception method for intrusion detection models provided by the above methods. The method includes: acquiring vehicle detection data, wherein the vehicle detection data includes at least vehicle status, vehicle control commands, and vehicle configuration information; inputting the vehicle detection data into a heterogeneous intrusion detection model pool to obtain detection results output by each heterogeneous intrusion detection model; wherein each heterogeneous intrusion detection model is trained based on vehicle data samples; perceiving abnormal intrusion detection models in the heterogeneous intrusion detection model pool based on each detection result; determining the threat perception result of the heterogeneous intrusion detection model pool based on each detection result; and cleaning the abnormal intrusion detection models when the presence of the abnormal intrusion detection models in the heterogeneous intrusion detection model pool is detected.
[0168] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements a threat perception method for intrusion detection models provided by the methods described above. This method includes: acquiring vehicle detection data, wherein the vehicle detection data includes at least vehicle status, vehicle control commands, and vehicle configuration information; inputting the vehicle detection data into a heterogeneous intrusion detection model pool to obtain detection results output by each heterogeneous intrusion detection model; wherein each heterogeneous intrusion detection model is trained based on vehicle data samples; based on each detection result, perceiving abnormal intrusion detection models in the heterogeneous intrusion detection model pool; based on each detection result, determining the threat perception result of the heterogeneous intrusion detection model pool; and, when an abnormal intrusion detection model is detected in the heterogeneous intrusion detection model pool, performing a cleaning process on the abnormal intrusion detection model.
[0169] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0170] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0171] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A threat perception method for an intrusion detection model, characterized in that, include: Acquire vehicle data to be tested, wherein the vehicle data to be tested includes at least vehicle status, vehicle control commands, and vehicle configuration information; The vehicle data to be detected is input into the heterogeneous intrusion detection model pool to obtain the detection results output by each heterogeneous intrusion detection model, wherein each heterogeneous intrusion detection model is trained based on vehicle data samples; Based on the detection results, the abnormal intrusion detection models in the heterogeneous intrusion detection model pool are perceived. Obtain the confidence weights of each heterogeneous intrusion detection model; wherein, the confidence weights of each heterogeneous intrusion detection model are different at different times; the confidence weights are updated periodically using the detection accuracy of historical vehicle data samples; The detection results are weighted and summed with the confidence weights, and the threat perception result of the heterogeneous intrusion detection model pool is determined based on the weighted summation result. If the abnormal intrusion detection model is detected to exist in the heterogeneous intrusion detection model pool, the abnormal intrusion detection model is removed from the heterogeneous intrusion detection model pool and sent to the cloud platform so that the cloud platform can retrain the abnormal intrusion detection model. In the case where heterogeneous intrusion detection models with target attribute information exist in the cloud platform, the heterogeneous intrusion detection model corresponding to the target attribute information is selected as the target heterogeneous intrusion detection model based on the priority of the target attribute information. The target attribute information is different from the attribute information of all heterogeneous intrusion detection models in the heterogeneous intrusion detection model pool. The attribute information includes at least model type, model algorithm, model parameters, and model training data. The priority of the model type is higher than that of the model algorithm, the priority of the model algorithm is higher than that of the model parameters, and the priority of the model parameters is higher than that of the model training data. The target heterogeneous intrusion detection model is a normal heterogeneous intrusion detection model. Add the target heterogeneous intrusion detection model to the heterogeneous intrusion detection model pool. 2.The method for threat perception for intrusion detection model according to claim 1, wherein, The step of inputting the vehicle data to be detected into the heterogeneous intrusion detection model pool to obtain the detection results output by each heterogeneous intrusion detection model includes: The vehicle data to be detected is copied into N independent copies; The N independent vehicle detection data sets are input into the heterogeneous intrusion detection model pool to obtain the detection results output by each heterogeneous intrusion detection model. Each heterogeneous intrusion detection model corresponds to one vehicle detection data set, and the detection result is a numerical value used to characterize the vehicle state, where N is a positive integer. 3.The method of claim 1, wherein, The step of perceiving abnormal intrusion detection models in the heterogeneous intrusion detection model pool based on the detection results includes: The detection results are processed using a voting algorithm to perceive the abnormal intrusion detection models in the heterogeneous intrusion detection model pool.
4. The method for threat perception for intrusion detection model as claimed in claim 3 wherein, The weighted summation result is calculated using the following formula (1): Wherein, V(A,W,t) represents the weighted summation result; This represents the detection result of the i-th heterogeneous intrusion detection model at time t; Let A represent the confidence weight of the i-th heterogeneous intrusion detection model at time t; let A represent the set of detection results of N heterogeneous intrusion detection models; and let W represent the set of confidence weights of N heterogeneous intrusion detection models.
5. A threat perception device for intrusion detection models, characterized in that, include: The acquisition module is used to acquire vehicle data to be detected, wherein the vehicle data to be detected includes at least vehicle status, vehicle control commands and vehicle configuration information; The input module is used to input the vehicle data to be detected into the heterogeneous intrusion detection model pool to obtain the detection results output by each heterogeneous intrusion detection model; wherein, each heterogeneous intrusion detection model is trained based on vehicle data samples; The perception module is used to perceive the abnormal intrusion detection models in the heterogeneous intrusion detection model pool based on the detection results. A determination module is used to obtain the confidence weights of each heterogeneous intrusion detection model; wherein, the confidence weights of each heterogeneous intrusion detection model are different at different times; the confidence weights are updated periodically using the detection accuracy of historical vehicle data samples; the detection results and the confidence weights are weighted and summed, and the threat perception result of the heterogeneous intrusion detection model pool is determined based on the weighted summation result; The processing module is configured to, upon detecting the existence of an abnormal intrusion detection model in the heterogeneous intrusion detection model pool, remove the abnormal intrusion detection model from the pool and send it to the cloud platform for retraining; if a heterogeneous intrusion detection model with target attribute information exists in the cloud platform, select the heterogeneous intrusion detection model corresponding to the target attribute information as the target heterogeneous intrusion detection model based on the priority of the target attribute information; the target attribute information is different from the attribute information of all heterogeneous intrusion detection models in the pool; wherein the attribute information includes at least model type, model algorithm, model parameters, and model training data; the priority of the model type is higher than that of the model algorithm, the priority of the model algorithm is higher than that of the model parameters, and the priority of the model parameters is higher than that of the model training data; the target heterogeneous intrusion detection model is a normal heterogeneous intrusion detection model; and add the target heterogeneous intrusion detection model to the heterogeneous intrusion detection model pool.
6. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the threat perception method for an intrusion detection model as described in any one of claims 1 to 4. 7.A non-transitory computer-readable storage medium having stored thereon a computer program. When the computer program is executed by a processor, it implements the threat perception method for an intrusion detection model as described in any one of claims 1 to 4.
8. A computer program product comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the threat perception method for an intrusion detection model as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Deep learning implementation method and system based on mimicry mechanism
CN113537284A