A CAV network attack identification and demodulation method, device and storage medium in formation

By constructing a multi-lane formation traffic flow model PIDM and processing network attacks in stages, the problem of formation CAV network attack identification and demodulation in multi-lane scenarios is solved, effectively responding to network attacks is achieved, and the driving safety and stability of the fleet is improved.

CN115720151BActive Publication Date: 2025-05-06CHANGAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211316589.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-26
Publication Date
2025-05-06
Estimated Expiration
2042-10-26

AI Technical Summary

Technical Problem

The prior art is difficult to effectively deal with formation CAV network attacks in multi-lane scenarios, especially in the process of identification and demodulation, where there is a problem of error risk and a single response strategy.

Method used

A method of CAV network attack identification and demodulation under formation is adopted. By constructing a multi-lane formation-type traffic flow model PIDM, the communication topology structure within the vehicle fleet is determined, and network attacks are handled in stages, including cutting off error information reception, multi-vehicle collaborative correction of error information, and dynamically adjusting the impact weight in the PIDM model to reduce the adverse impact of network attacks on the fleet.

Benefits of technology

In multi-lane scenarios, effectively identifying and demodulating network attacks improves the driving safety and stability of the fleet and reduces the adverse effects of network attacks on the fleet.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115720151B_ABST
    Figure CN115720151B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, device and storage medium for identifying and demodulating network attacks on CAVs in a formation. The method includes: constructing a multi-lane formation traffic flow model PIDM, determining the communication topology structure existing in the vehicle formation; locating, identifying and alarming network attacks; and determining the network attack demodulation method in stages. The present invention identifies network attacks in a multi-lane formation scenario, eliminates the adverse effects of the preceding vehicle through step-by-step error scaling, and reduces the adverse effects of network attacks on the driving of the fleet.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of automobile intelligent safety and automatic driving, and relates to a CAV network attack identification and demodulation method, device and storage medium in a formation. Background Art

[0002] CAV has become the strategic direction for the development of the global automotive industry. The high level of connectivity and control performance provides a basis for CAV to perform platooning and other behaviors. CAVs traveling in platoons have the advantages of improving traffic efficiency and road safety, reducing fuel consumption and environmental pollution, and have received widespread attention from scholars at home and abroad.

[0003] The connectivity function provides an open communication environment for CAV formations to share status information, but CAVs are also subject to various types of cybersecurity threats. There are various types of cyberattacks, including deception and termination of communications. Between 2010 and 2018, there were 170 publicly reported car hacking incidents. A formation CAV exposed to malicious cyberattacks will not only affect its travel efficiency, but may also cause casualties and property losses. In order to ensure the safe and efficient driving of CAVs, there is a need for methods that can effectively deal with cyber attacks on formation CAVs.

[0004] Regarding the research on network attacks on platooning CAVs, Reference 1 (Xiao S, Ge X, Han QL, et al. Secure distributed adaptive platooning control of automated vehicles over vehicular ad-hoc networks under denial-of-service attacks [J]. IEEE Transactions on Cybernetics, 2021.) studied the single-lane platooning control strategy under intermittent denial of service (DoS) attacks. Reference 2 (Mokari H, Firouzmand E, Sharifi I, et al. DoS Attack Detection and Resilient Control in Platoon of Smart Vehicles [C] / / 2021 9th RSI International Conference on Robotics and Mechatronics (ICRoM). 2021.) proposed a vehicle resilience control strategy for denial of service attacks.

[0005] The above-mentioned platooning research is mainly aimed at single-lane scenarios, while in real-world scenarios, multi-lane scenarios are more common, which affect the platooning and the manifestation of network attacks, and put forward new requirements for network attacks and response strategies. In addition, in Reference 1, the vehicle only corrects the error information based on its own sensor detection results, which has a high error risk; in Reference 2, when responding to DOS attacks, the attacked vehicle is simply isolated until the attack ends. The attack response method is single, and the driving safety and stability of the platoon are poor. Summary of the invention

[0006] In order to solve the above problems, the present invention provides a CAV network attack identification and demodulation method in formation, which identifies network attacks in a multi-lane formation scenario, eliminates the adverse effects of the leading vehicle through step-by-step error scaling, reduces the adverse effects of network attacks on the driving of the fleet, and solves the problems existing in the prior art.

[0007] A second object of the present invention is to provide an electronic device.

[0008] A third object of the present invention is to provide a computer storage medium.

[0009] The technical solution adopted by the present invention is a method for identifying and demodulating CAV network attacks in formation, comprising the following steps:

[0010] Step 1: Construct a multi-lane platoon traffic flow model PIDM and determine the communication topology structure within the vehicle platoon;

[0011] The PIDM model is as follows:

[0012]

[0013] in, represents the expected following distance of vehicle i at time t, represents the desired following distance of vehicle i when parking, v i (t) represents the speed of car i at time t, represents the influence weight of the preceding vehicle k on vehicle i under the To(·) topology type, 1≤k≤i-1, and the longer the distance between the vehicle and the preceding vehicle, the smaller the weight; T i * (t) represents the headway of vehicle i at time t, Δv i (t) is the speed difference between vehicle i and the preceding vehicle at time t, represents the maximum acceleration expected by vehicle i, represents the desired comfortable deceleration of vehicle i;

[0014] Step 2: Network attack location, identification and alert;

[0015] Step 3: Determine the network attack demodulation method in stages: Before receiving the attack information, cut off the communication between other vehicles and the vehicle that sends the attack information to prevent the reception of erroneous information; during the attack information reception or processing, detect and obtain the accurate status information of the attacked vehicle and correct the attack information content, or use other lane vehicles outside the formation to assist in correcting the network attack information, and perform multi-vehicle collaborative information correction based on the trust model to ensure that the sent information is as close to the actual information as possible; after receiving the attack information, determine the type of communication flow topology after replacement through game means and according to the principle of minimum cost, and dynamically adjust the influence weight of the vehicle receiving the attack information on other vehicles in the PIDM model to weaken the impact of erroneous information.

[0016] An electronic device adopts the above method to realize CAV network attack identification and demodulation in formation.

[0017] A computer storage medium stores at least one program instruction, and the at least one program instruction is loaded and executed by a processor to implement the above-mentioned CAV network attack identification and demodulation method in formation.

[0018] The beneficial effects of the present invention are:

[0019] In more common multi-lane scenarios, a logic processor is used to process and verify the identification and reception information, and network attacks are identified by comparing and verifying timestamps and data errors. Based on the PIDM model, attack demodulation measures are used to process the erroneous information transmitted by the attacked vehicles in stages, so as to achieve the goal of safe and efficient driving of the convoy, and improve the defense performance of the vehicle formation against denial of service attacks, replay and deception attacks.

[0020] In practical applications under the background of multi-lane and networking, the technical solution based on the present invention has the following advantages: the present invention improves the following model that takes into account the influence of networking under the communication flow topology unique to the formation, focuses on the communication flow topology processing when dealing with network attacks, and practices the response strategy by improving the following model, and the method is targeted at a clear scenario. By subdividing the three attack stages before receiving, during processing, and after receiving, the corresponding phased response measures of cutting off the communication connection, multi-vehicle collaborative correction of error information, and adjusting the weight distribution of the vehicle PIDM model can act on the vehicles in the corresponding stages in a targeted manner, rather than simply applying the same response method to vehicles in different attack stages. By collaborating with multiple lanes and multi-stage mediation, the fleet can be guaranteed to respond and respond quickly to network attacks, thereby improving the driving safety and stability of the fleet. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0022] Figure 1 It is a flow chart of an embodiment of the present invention.

[0023] Figure 2 It is a communication flow topology diagram of an embodiment of the present invention.

[0024] Figure 3 Schematic diagram of network attacks under different communication flow topologies in an embodiment of the present invention.

[0025] Figure 4 It is the sensor information loading influence curve in the embodiment of the present invention. DETAILED DESCRIPTION

[0026] The following will be combined with the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0027] Example

[0028] A method for identifying and demodulating CAV network attacks in formation, such as Figure 1 As shown, please follow the steps below:

[0029] Step 1: Construct a multi-lane platoon traffic flow model PIDM based on the IDM model and determine the communication topology structure within the vehicle platoon as the basis of the traffic and communication model.

[0030] The network communication topology of a CAV formation is defined as a directed graph with a set of nodes, a set of edges, and a set of weights. There are many topologies for vehicle communication flows, and typical topologies include leader-follower following (LFF), predecessor-leader following (PLF), and all-predecessor following (APF). Figure 2 shown.

[0031] In the embodiment of the present invention, APF is used as the initial communication topology mainly to facilitate the description and display of the proposed phased strategy. APF provides a more explainable communication background for the implementation of the PIDM model, enabling the vehicle to obtain the driving information of multiple vehicles in front and comprehensively derive the driving status of the vehicle. Even if an attack information appears in a certain vehicle in front, the APF topology can still obtain the information of other normal vehicles, which is conducive to the strategy of minimizing the impact of erroneous information by adjusting the information weight.

[0032] The adjacency matrix abstracted from the topology between vehicles As shown in formula (1):

[0033]

[0034] In the formula, in the position relationship between two adjacent vehicles, vehicle n-1 is the front vehicle and vehicle n is the rear vehicle. When vehicle n receives information from vehicle n-1, The value is 1 when there is no information communication between car n and car n-1 =0; To(·) indicates the topology type followed by the fleet. Taking APF as an example, under APF It will be transformed into a lower triangular matrix with all upper triangular parts being zero.

[0035] In the platooning communication scenario, a platooning intelligent driver vehicle platooning model (PIDM) in the traffic state is constructed based on the IDM model. Before receiving a network attack, the information transmitted by all vehicles in the platoon is correct. The basic model of IDM is shown in equations (2) and (3).

[0036]

[0037]

[0038] In the formula, a i (t), v i (t), s i (t) are the acceleration, speed and following distance of vehicle i at time t, are the expected following distance and headway of vehicle i at time t, are the expected maximum acceleration, comfortable deceleration, speed, and following distance when parking for vehicle i, represents the desired following distance when parking for vehicle i, Δv i (t) is the speed difference between vehicle i and the preceding vehicle at time t, and δ is the parameter to be calibrated.

[0039] The PIDM model considering formation communication is as follows:

[0040]

[0041] Formula (4) indicates that the expected following distance of a vehicle is affected not only by the vehicle in front but also by other vehicles. represents the influence weight of the preceding vehicle k of vehicle i on vehicle i under the To(·) topology type, 1≤k≤i-1, Represents the information weight set of vehicles that communicate with vehicle i under the To(·) topology type.

[0042] represents the expected headway of vehicle k+1 at time t; with the following constraints:

[0043]

[0044] It represents the influence weight of the preceding car i-1 on car i in the To(·) topology type.

[0045] Each vehicle in the fleet calculates its next driving state according to the weight. The constraint shown in formula (5) can be expanded in a certain number of fleets as shown in formula (6).

[0046]

[0047] The longer the distance between the vehicle and the vehicle in front, the smaller the weight distribution.

[0048] The classic IDM model realizes longitudinal following motion according to the status information of the leading vehicle, the desired vehicle and the maximum vehicle. The status information includes acceleration, speed (difference) and following distance.

[0049] The PIDM model constructed by the embodiment of the present invention adds multiple front vehicle states and communication flow topology weight parameters in the queue. Multiple vehicles have different influences, and the influence parameters change dynamically with network attacks. In order to adapt to the communication flow topology, the PIDM model takes into account the different influences of the driving states of multiple vehicles in front on the vehicle. The weight distribution and the degree of influence of each vehicle are different, rather than fixed and the same, which is more in line with the dynamic characteristics of networked traffic and the differentiated reality of communication flow topology. When dealing with network attacks and performing game demodulation, the weights in the PIDM model are related to the communication flow topology type and dynamically adjusted, rather than manually assigned, which reduces the impact of network attacks on the fleet, improves safety and stability, and avoids the influence of subjective factors. Enabling network attacks to affect vehicle behavior through communication is the basis for studying the impact of networked vehicles on network attacks. Communication flow topology is an objective and unique communication method for formations. Networked vehicles adjust their behavior according to the information transmitted by communication. At the same time, one of the forms of network attacks will also affect vehicle behavior by affecting communication. A model is needed to reflect the above operating environment, and only on this basis can targeted research on network attack response be carried out.

[0050] Step 2: Network attack location, identification and alert;

[0051] When a vehicle is attacked by a network attack, other vehicles communicating with it will receive erroneous information and control their own vehicles based on the erroneous information. The accumulation of erroneous information will cause the continuous amplification of abnormal driving behavior at the physical level, thus affecting the entire traffic flow. It is necessary to identify the type of attack and take corresponding measures.

[0052] The vehicles in the convoy obtain the vehicle status information with vehicle ID and timestamp sent by the vehicle in front, as well as the driving data of the adjacent rear vehicle detected. The vehicle first verifies the timestamp of the obtained information of the vehicle in front; then compares the vehicle's own driving data with the information transmitted by the vehicle in front, and the driving data of the vehicle in front measured by the vehicle with the driving data sent by the vehicle in front, verifies whether a network attack has occurred through the logic processor, locates the vehicle under network attack in time, identifies the type of network attack, and alerts the vehicles around the attacked vehicle.

[0053] In step 2.1, the vehicle receives the information transmitted by the vehicle in front and verifies the ID and timestamp of the vehicle in front. If the timestamp T(t) of the transmitted information is the same as the timestamp T(t-Δt) received previously, it is considered that a repeated attack has occurred. If the information transmitted by the vehicle in front is not received after exceeding the time threshold, it is considered that a denial of service attack has occurred.

[0054] Step 2.2, after the information is verified by the timestamp, the vehicle sensor identification data is compared with the driving data transmitted by the preceding vehicle. Taking a spoofing attack as an example, if the data gap exceeds a threshold, a spoofing attack is considered to have occurred.

[0055] Step 2.3, if the frequency of the model system's safety detection is f, then the number of detections performed within a limited time period h is p = f × h. If p0 (p0≤p) of the detection results are abnormal, a correlation analysis is performed on the value of p0.

[0056]

[0057] In the formula, is the judgment threshold of the number of error detections.

[0058] Considering the situation where the vehicle's own sensor has errors in obtaining information, the timestamp and driving status of the information provided by the vehicle in front are verified to locate, identify and warn various types of network attacks. Through timestamps and driving information, different types of attacks such as repeated attacks, deception attacks and denial of service attacks can be identified; and considering the situation where the error causes the alarm to be falsely triggered, by setting an alarm threshold for the number of abnormalities within a limited time period, the false alarm caused by information errors in a single identification can be avoided, thereby improving the reliability of identifying network attacks.

[0059] Step 3: Determine the network attack demodulation method in stages;

[0060] After identifying and obtaining the type of network attack and the affected vehicle, a communication demodulation control system is needed to help with attack demodulation to reduce the adverse effects of network attacks. The embodiment of the present invention organizes demodulation simultaneously in three stages: before receiving the attack information, during processing, and after receiving it (named Phase I, Phase II, and Phase III, respectively). Before receiving the attack information, cut off the communication between other vehicles and the vehicle that sends the attack information to prevent the reception of erroneous information and prevent the large-scale spread of network attacks; for the information that has been disseminated (during the reception or processing of the attack information), the status data of the attacked vehicle obtained through multi-vehicle measurement and processing replaces the published erroneous data to ensure that the issued information is as close to the actual information as possible; for the case where erroneous information has been received, the information weight that the vehicle relies on for driving is adjusted through game theory to weaken the impact of erroneous information, and the updating of the topology type and the adjustment of the information weight work together to achieve network attack demodulation for the fleet.

[0061] Phase I: Before the attack information is sent, take vehicle k-1 being hit as an example. When vehicle k-1 is identified as the hit vehicle and the hit type, other channels receiving the hit vehicle’s communication input are promptly cut off. The processing in the matrix is ​​as follows:

[0062]

[0063] The left matrix in formula (8) It means deleting the element at that position. After deletion, the element at the corresponding position in the right matrix becomes 0. After the communication is cut off, vehicle k-1 is in an information island state, resulting in missing elements in the motion information based on which the following behavior of the vehicle behind is based, which may easily cause safety risks. The motion information of vehicle k-1 is obtained by using sensors such as on-board millimeter-wave radar on other vehicles, and the information provided by each vehicle is integrated to obtain the accurate motion information of vehicle k-1, so as to replace the wrong information, fill in the missing elements, and determine the value of the element through subsequent game.

[0064] Phase II: Collaborative positioning based on trust value during the attack information processing process. The vehicle that is identified as being hit in the formation is regarded as a node vehicle, and the sensor detection information of other vehicles adjacent to the hit vehicle is used to correct the erroneous information. Consider that the adjacent vehicles may have been maliciously affected by the erroneous information during the process from the attack to the activation of sensor correction, that is, there is a deviation in the accuracy of sensor information of different vehicles. Based on the trust value fusion processing of the filtered hit vehicle status information of each vehicle, the driving status result p of the hit vehicle obtained by multi-vehicle collaborative monitoring is generated.

[0065]

[0066]

[0067] Where P j Represents the hit vehicle information measured by each vehicle, Represents the weight of each vehicle’s measurement information, Trust j,t-1 is the trust value of vehicle j around the hit vehicle at time t-1. The weight is determined by normalizing the trust value of each vehicle at the previous moment, α Trust is the trust normalization coefficient. At the communication level, vehicles with trust values ​​below the threshold are removed from the communication topology to avoid further spread of network attacks.

[0068] Formula (9) comprehensively processes the status information of the hit vehicle provided by multiple vehicles based on the weight, and formula (10) normalizes the trust value weight. Since the trust values ​​exceeding the threshold are all at a high level, it is not possible to significantly increase the weight of the information with higher accuracy. After processing by formula (10), the weight of the information with higher accuracy is amplified and used to calculate the corrected status information of the hit vehicle.

[0069] The driving information of the hit vehicle transmitted by each vehicle has different degrees of error in size and direction. Formulas (9) and (10) process the driving information of the hit vehicle provided by each vehicle on average, and improve it to integrate the information provided by each vehicle according to the weight corresponding to the trust value of each vehicle, and exclude the vehicle information with too low trust value. After removing the information provided by the vehicle with too large error through the trust value, the driving status of the hit vehicle is determined by integrating the information provided by multiple vehicles, which is the basis for correcting the wrong information of the hit vehicle.

[0070] Trust value j,t-1 It is the value obtained by combining the real-time reputation value and the periodic reputation value, which can evaluate the communication status of vehicle j. The calculation method is as follows:

[0071] Trust j,t-1 =(1-γ)T j,t-1 +γR j,t-1,γ∈[0,1] (11)

[0072]

[0073] Among them, γ is the calculation weight of the trust value, ρ, β and ξ are adjustment factors, ρ ≥ 0, ξ ≤ 1, β ≥ 1; the values ​​of ρ, β and ξ are determined by simulation experiments. Under the constraint of the value range, the specific value is determined by comparing the influence trend of different adjustment factor value combinations [ρ, β, ξ] on γ.

[0074] T j,t-1 represents the real-time reputation value of the information provided by vehicle j at time t-1, R j,t-1 Represents the periodic reputation value of the information provided by vehicle j at time t-1.

[0075] Since vehicle information may change significantly, including the situation that the periodic reputation value is low while the real-time reputation value suddenly increases, and the periodic reputation value is high while the real-time reputation value suddenly drops, the former needs to be confirmed whether it is an accidental situation, and the latter needs to be responded quickly to avoid affecting the information correction. Therefore, it is necessary to dynamically adjust the weight to solve such problems. Formulas (11) and (12) comprehensively consider the accuracy of vehicle information in a longer period and in real time, and dynamically adjust the calculation weight γ of the trust value to ensure that the trust value is "difficult to increase and easy to decrease", which can more sensitively perceive the change of the vehicle's communication status. When R j,t-1 -T j,t-1 ≥0, that is, the real-time reputation value T of the information provided by vehicle j at time t-1 j,t-1 Higher than the period reputation value R j,t-1 , then the information transmission at time t-1 will not account for a high proportion in the final trust value calculation, so the trust value of the node vehicle to vehicle j will slowly increase. j,t-1 -T j,t-1 When ≥0, γ will decrease, resulting in a higher proportion of real-time reputation value, causing the trust value of vehicle j to drop rapidly.

[0076] The real-time reputation is the verification rating of the data detection of vehicle j at time t-1, that is, the closeness between the data provided by the vehicle at time t-1 and the accurate data after correction at time t-1.

[0077] T j,t-1 =1-(ω1v j,ref +ω2d j,ref +ω3a j,ref ) (13)

[0078] In formula (13), T j,t-1 is the node vehicle, i.e. the vehicle in the formation that is identified as being hit; the real-time reputation value evaluation of vehicle j at time t-1, v j,refrepresents the relative error between the speed of the hit vehicle provided by vehicle i and the reference speed of the hit vehicle, d j,ref represents the relative error between the hit vehicle position provided by vehicle j and the hit vehicle reference position, a j,ref Represents the relative error between the acceleration of the hit vehicle provided by vehicle j and the reference acceleration of the hit vehicle, and ω1, ω2 and ω3 represent the corresponding weights. In previous studies, the vehicle state information and the accuracy of the reference state data were multiplied to obtain the real-time reputation value, but the difficulty and accuracy of obtaining and calculating the vehicle state information were not considered, and direct multiplication could not accurately indicate the reliability of the information provided by each vehicle. In the embodiment of the present invention, the relative errors of speed, position and acceleration are processed according to the weights to obtain the real-time reputation value. Considering that the magnitude of the errors generated by acceleration, speed and position are different, the weights are used to amplify or reduce the impact of their errors on the real-time reputation value, so as to meet the verification requirements for the reliability of the information of each vehicle. The errors generated by speed and position have different ranges, and the accuracy required for correcting the driving state information of the hit vehicle is different. The weights are used to amplify or reduce each error, which affects the calculation of the real-time reputation value, and find a vehicle suitable for correcting the information of the hit vehicle, so as to meet the needs of the information correction process.

[0079] Relative error j,ref , relative position error d j,ref , acceleration relative error a j,ref The calculation method is as follows:

[0080]

[0081]

[0082]

[0083]

[0084]

[0085]

[0086] In the formula, v j The speed of the vehicle hit by vehicle j, d j is the position of the vehicle hit provided by vehicle j, a j is the acceleration of the hit vehicle provided by vehicle j; λ is the weight factor; t0 is the time when the hit vehicle information is first corrected; v ref ,d ref and a ref are the reference speed, reference position and reference acceleration of the vehicle being hit respectively. When t>t0, v ref ,d ref and aref The speed, position and acceleration of the vehicle being hit in the vehicle state result p are represented; at t0-1, the vehicle state result p has not yet been obtained, and the speed provided by the vehicle being hit at t0-1 Location Acceleration The information is still correct, so the information of the vehicle hit at time t0-1 and the actual transmission time interval t between two adjacent information are obtained. s , calculate the reference speed, position and acceleration of the hit vehicle at time t0, as shown in equations (17), (18) and (19).

[0087] The periodic reputation value is introduced to reflect the accuracy of the information provided by vehicle i in a longer historical period. The calculation expression is as follows:

[0088]

[0089] In the formula, R j,t-1 is the periodic reputation value of vehicle j at time t-1, n is the cumulative number of times vehicle j transmits information, and m is the number of times vehicle j transmits information in the past time period at time t-1; when the cumulative number of times a vehicle transmits information is less than one period, the cumulative number of times information is transmitted is insufficient for calculation, and the initial value is added to it To solve, is the initial value of the vehicle.

[0090] Phase III-1: Game attack demodulation before obtaining correction information.

[0091] When the communication between the vehicle and other vehicles is cut off and the correction information of the hit vehicle has not yet been replaced, the vehicles that have received the wrong information about the hit vehicle are making decisions and controlling their driving behaviors under the wrong information, which is more likely to bring safety and volatility risks in a short period of time.

[0092] By modifying the communication flow topology to deal with attacks, different communication flow topologies have their own characteristics. When vehicles at different positions in the queue are attacked, the impact on the stability of the queue will be different; Figure 3 As shown in the figure, taking the two types of communication flow topologies, PLF and LFF, as examples, the number of affected links is larger when the PLF head vehicle is hit, while the number of affected links when the middle vehicle is hit in LFF is larger. According to the mapping relationship between the hit position and the communication flow topology type, the initial network attack demodulation is achieved by changing the communication flow topology.

[0093] In previous studies, cutting off communication with the attacked vehicle is one of the types of topology transformation. It deletes some edges in the original topology, but does not change the communication flow topology structure it relies on. Cutting off communication under attacks such as denial of service is passive. The embodiment of the present invention uses the game process shown in equations (21) to (23) to determine the final topology to be selected by gaming the costs of different replacement schemes. The selected topology can block the adverse effects of the attack as much as possible, while having a lower replacement cost. It is an active attack response measure with higher security and stability. If the attacked vehicle is not excluded from the queue, the conversion cost C(To(·) switch,1 )as follows:

[0094] C(To(·) switch,1 )=o×num lose (To(·))+c×num plus (To(·)) (21)

[0095] In the formula, num lose (To(·)) indicates the number of invalid communication links after the change, num plus (To(·)) represents the number of newly added links, o is the impact of invalid links, and c is the conversion cost of topology transformation. In the communication flow topology set To(·), the topology with the smallest adverse impact and conversion cost after the change is selected as the topology type To(·) to be replaced switch,1 .

[0096] Formula (21) shows the communication flow topology selection when the attacked vehicle is not excluded from the queue. Temporarily excluding the attacked vehicle i from the queue is another demodulation idea, which means that i+1 and the rear vehicle are independent as a new convoy. The communication flow topology in the convoy will change again. The conversion cost at this time is C(To(·) switch,2 ).

[0097] C(To(·) switch,2 )=c×num plus,i+1 (To(·))+p i+1 (twenty two)

[0098] In addition to the additional topological cost of the new convoy with i+1 as the head vehicle, i+1 itself is the leader of the followers, and there is an unstable vehicle in front of it. The additional monitoring cost p of i+1 itself is specially considered i+1 .

[0099] To(·) switch =argmin[C(To(·) switch,1 ),C(To(·) switch,2 )] (twenty three)

[0100] Cost C(To(·) based on two types of demodulation ideas switch,1 ) and C(To(·) switch,2 ) to conduct a game, and select the communication flow topology type To(·) corresponding to the minimum cost according to the principle of minimum cost. switch As shown in formula (23), the corresponding communication flow topology is selected to deal with the convoy topology; there are many types of communication topologies within the formation, and their applicability varies in different situations. The non-physical connection communication topology can be transformed instantly, and the transformation can achieve beneficial effects such as disconnecting the communication connection with the attacked vehicle.

[0101] Phase III-2: Game attack demodulation after obtaining the corrected information.

[0102] After receiving the correction information, the communication with the hit vehicle has not been restored. Considering the delay of adding the correction information By adjusting the weights of other vehicle information in the PIDM on which the vehicle is based, the adverse effects of the attack information can be minimized. Taking a platoon consisting of k vehicles as an example, the leading vehicle is identified as being attacked by the network, and the information weight vector of the following vehicles is The sum of the elements in will be reduced to less than 1. In order to satisfy the constraint of formula (5), the state information of the hit vehicle obtained by detection is added to the motion decision process. represents the information weight of vehicle i on the correction information of the leading vehicle, and The value of Trust i,t-1 The car-following model based on the correction information changes to:

[0103]

[0104] In the formula, use Replace (4) For vehicle 2 and The difference in the corrected information speed of the head car under the time delay is converted into Modified to The third term of the polynomial in formula (4) Modified to

[0105] Apply cooperative game theory to solve the problem of the attacked convoy With λ i1 The proportional design problem, the vector composed of the values ​​of each item in the design benefit matrix is After Gaming Based on this, the information weight distribution is readjusted to achieve control after information transmission.

[0106] After gradual error scaling, by the end of the formation or even a certain position in the formation, the adverse effect of the preceding vehicle may have dissipated, and there is no need to add vehicle sensors again; since there is a time delay of 0.1 to 0.33 seconds when acquiring sensor information, continued loading may even cause an increase in error due to the accumulation of delays, such as Figure 4 shown.

[0107] Once an attack is identified, the communication with the attacked vehicle is cut off as soon as possible, and the communication with the vehicle that sent the attack information is cut off before the attack information is sent, so as to prevent the reception of the attack information and ensure the safety of the queue. The accurate status information of the attacked vehicle is formed through the cooperative detection of trusted vehicles to replace the erroneous information caused by the original attack; for the attack information that has been sent but not yet received, the network attack information is corrected with the assistance of other lane vehicles outside the formation, and the multi-vehicle collaborative information correction is carried out based on the trust model, which reduces the impact of the insufficient accuracy of the corrected attacked vehicle information caused by factors such as detector errors, ensures that these information no longer contains erroneous or offensive information when received, and can obtain accurate driving information of the attacked vehicle. During the period of cutting off communication with the attacked vehicle and not obtaining the detection correction information, the communication flow topology is replaced by game to reduce the impact of the attack information. For vehicles that have received the erroneous information, it is divided into two attack game demodulation stages before obtaining the correction information and after obtaining the correction information. The game reduces the impact of the erroneous information on the vehicle decision, and gradually weakens the impact of the network attack on the vehicle to achieve the demodulation purpose.

[0108] The embodiment of the present invention proposes a demodulation strategy corresponding to the three stages before receiving, during processing, and after receiving the attack information. Based on the monitoring results, the attack demodulation effect of blocking the sending of attack information, suppressing the propagation of attack information, and weakening the impact of attack information is achieved. The entire demodulation process is carried out under the marshaling fleet of the communication flow topology, and the change of vehicle behavior at the physical level is realized based on the matching PIDM model. When facing a network attack, the embodiment of the present invention dynamically adjusts the communication layer weights through game theory. This adjustment acts on the actual movement of the vehicle through the PIDM model, and eliminates the adverse effects of the preceding vehicle through step-by-step error scaling, so as to reduce the adverse effects of network attacks on the driving of the fleet.

[0109] Example verification,

[0110] By comparing the model used in the method of the embodiment of the present invention with a simulation experiment of a formation scenario without a solution to counter network attacks, the parameters involved in the experiment and their corresponding values ​​and meanings are shown in Table 1.

[0111] Table 1 Simulation experiment parameters

[0112] parameter Numeric meaning <![CDATA[v0 / (m·s -1 )]]> 33.33 Maximum speed L / m 5 Vehicle length T / s 1.1 Safety headway <![CDATA[s0 / m]]> 2 Severe traffic jam distance <![CDATA[a / (m·s -2 )]]> 4 Maximum acceleration <![CDATA[b / (m·s -2 )]]> 5 Maximum safe deceleration λ 0.3 Weight coefficient

[0113] Under the parameter settings in Table 1, when a network attack is carried out on the leading vehicle of a convoy consisting of 4 vehicles, the payoff matrix corresponding to the weight vector of the 4th vehicle is as follows:

[0114] Table 2 Profit Matrix

[0115]

[0116] The vector composed of the values ​​of each item in the profit matrix is When i=4, the information weight vector of vehicle 4 is: [w 41 ,w 42 ,w 43 ]=[0.043,0.057,0.2].

[0117] The simulation results are shown in Table 3:

[0118] Table 3 Simulation results

[0119]

[0120] It can be seen from Table 3 that the variances of various indicators under the method of the embodiment of the present invention are all smaller than the corresponding values ​​of the non-attack demodulation scenario. The application of the method of the embodiment of the present invention can better maintain the stability of the fleet.

[0121] If the method for identifying and demodulating CAV network attacks in formation described in the embodiment of the present invention is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method for identifying and demodulating CAV network attacks in formation described in the embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks or optical disks.

[0122] The above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention are included in the protection scope of the present invention.

Claims

1. A method for identifying and demodulating CAV network attacks in formation, characterized in that: The following steps are involved: Step 1: Construct a multi-lane platoon traffic flow model PIDM and determine the communication topology structure existing in the vehicle platoon; the PIDM model is as shown in formula (4): in, represents the expected following distance of vehicle i at time t, represents the desired following distance of vehicle i when parking, v i (t) represents the speed of car i at time t, represents the influence weight of the preceding vehicle k on vehicle i under the To(·) topology type, 1≤k≤i-1, and the longer the distance between the vehicle and the preceding vehicle, the smaller the weight; T i * (t) represents the headway of vehicle i at time t, Δv i (t) is the speed difference between vehicle i and the preceding vehicle at time t, represents the maximum acceleration expected by vehicle i, represents the desired comfortable deceleration of vehicle i; Step 2: Network attack location, identification and alert; Step 3: Determine the network attack demodulation method in stages: Before receiving the attack information, cut off the communication between other vehicles and the vehicle that sends the attack information to prevent the reception of erroneous information; during the attack information reception or processing, detect and obtain the accurate status information of the attacked vehicle and correct the attack information content, or use other lane vehicles outside the formation to assist in correcting the network attack information, and perform multi-vehicle collaborative information correction based on the trust model to ensure that the sent information is as close to the actual information as possible; after receiving the attack information, determine the communication flow topology type after replacement through game means according to the principle of minimum cost, and dynamically adjust the influence weight of the vehicle receiving the attack information on other vehicles in the PIDM model to weaken the impact of erroneous information; In step 1, the network communication topology of the CAV formation is defined as a directed graph with a node set, an edge set, and a weight set. There are multiple topologies of vehicle communication flows, and the topology between vehicles is abstracted into an adjacency matrix As shown in formula (1): In the formula, in the position relationship between two adjacent vehicles, vehicle n-1 is the front vehicle and vehicle n is the rear vehicle. When vehicle n receives information from vehicle n-1, The value is 1 when there is no information communication between car n and car n-1 is 0; To(·) indicates the topology type followed by the fleet; Topology types include front-and-rear vehicle topology LFF, pilot-front vehicle topology PLF, and multi-pilot vehicle topology APF; In step 2, network attack location, identification and alarm include the following steps: The vehicles in the convoy obtain the vehicle status information with vehicle ID and timestamp sent by the vehicle in front, detect the driving data of the adjacent rear vehicle, compare the data, verify whether a network attack has occurred through the logic processor, locate the vehicle under network attack in time, identify the type of network attack and alert the vehicles around the attacked vehicle; In step 3, before receiving the attack information, when vehicle k-1 is identified as the attacked vehicle, other channels receiving the communication input of the attacked vehicle are promptly cut off, and the processing in the matrix is ​​as follows: The left matrix in formula (8) Indicates deleting the element at the position. After deletion, the element at the corresponding position in the right matrix becomes 0. After the communication is cut off, vehicle k-1 is in an information island state, resulting in missing elements in the motion information based on which the following behavior of the vehicle behind is based. This may easily cause safety risks, and correct information is needed to complete the communication flow topology. In step 3, during the attack information reception or processing, Trust-based collaborative positioning The vehicle that is identified as being hit in the formation is regarded as a node vehicle, and the erroneous information is corrected through the sensor detection information of other vehicles adjacent to the hit vehicle; Considering that the adjacent vehicles may have been maliciously affected by wrong information during the process from the attack to the activation of sensor correction, that is, there is a deviation in the accuracy of sensor information of different vehicles; Based on the trust value fusion processing of the filtered attacked vehicle status information of each vehicle, the driving status result p of the attacked vehicle obtained by multi-vehicle collaborative monitoring is generated; In the formula, P j Represents the hit vehicle information measured by each vehicle, Represents the weight of each vehicle's measurement information; It is determined by normalizing the trust value of each vehicle at the previous moment. g represents the number of vehicles participating in collaborative positioning. Trust j,t-1 represents the trust value of the adjacent vehicle j of the hit vehicle at time t-1, a Trust represents the trust normalization coefficient; At the communication level, vehicles with trust values ​​below the threshold are removed from the communication topology to avoid further spread of network attacks; Trust value j,t-1 It is determined by combining the real-time reputation value and the periodic reputation value, and can evaluate the communication status of the vehicle j around the attacked vehicle. j,t-1 Calculate according to formula (11)~(12): Trust j,t-1 =(1-γ)T j,t-1 +γR j,t-1 ,γ∈[0,1] (11) Among them, γ is the calculation weight of the trust value, ρ, β and ξ are adjustment factors, ρ ≥ 0, ξ ≤ 1, β ≥ 1; T j,t-1 represents the real-time reputation value of the information provided by vehicle j at time t-1, R j,t-1 represents the periodic reputation value of the information provided by vehicle j at time t-1, and e is the base of the natural logarithm; In the step 3, after the attack information is received, it includes: demodulating the game attack before obtaining the correction information and demodulating the game attack after obtaining the correction information; The game attack demodulation before obtaining the correction information comprises the following steps: If the hit vehicle is not excluded from the queue, the conversion cost C(To(·) switch,1 ) is determined according to formula (21): C(To(·) switch,1 )=o×num lose (To(·))+c×num plus (To(·)) (21) In the formula, num lose (To(·)) indicates the number of invalid communication links after the change, num plus (To(·)) represents the number of newly added links, o is the impact of invalid links, and c is the conversion cost of topology transformation; in the communication flow topology type set To(·), the topology with the smallest adverse impact and conversion cost after the change is selected as the topology type To(·) to be replaced switch,1 ; If the attacked vehicle i is excluded from the queue, it means that vehicle i+1 and the rear vehicle become a new convoy independently, and the communication flow topology within the convoy will change again. The conversion cost at this time is C(To(·) switch,2 ), see formula (22): C(To(·) switch,2 )=c×num plus,i+1 (To(·))+p i+1 (22) In addition to the additional topological cost of the new convoy with vehicle i+1 as the head vehicle, vehicle i+1 itself is the leader of the followers, and there is an unstable vehicle in front of it. Therefore, the additional monitoring cost p of vehicle i+1 itself is considered. i+1 ; According to formula (23), the conversion cost C(To(·) switch,1 ) and C(To(·) switch,2 ) to play the game: To(·) switch =argmin[C(To(·) switch,1 ),C(To(·) switch,2 )] (23) Select the communication flow topology type To(·) corresponding to the minimum cost switch ; The game attack demodulation after obtaining the correction information comprises the following steps: The information weight vector of the following vehicles is the one that the leading vehicle is identified as being under cyber attack. The sum of the elements in the model is reduced to less than 1. In order to meet the constraints of the PIDM model, the state information of the vehicle being hit is added to the motion decision process. represents the information weight of vehicle i on the correction information of the leading vehicle, and The value of Trust i,t-1 The car-following model based on the correction information changes to: use Replace (4) For vehicle 2 and The difference in the speed of the corrected information of the head car under the time delay; the second term of the polynomial in equation (4) Modified to The third term of the polynomial in formula (4) Modified to Determine the number of people in the attacked convoy through cooperative game With λ i1 The vector composed of the values ​​of each item in the design benefit matrix is After Gaming Re-adjust information weight distribution to achieve control after information transmission.

2. According to the method for identifying and demodulating CAV network attacks in formation in claim 1, it is characterized in that: The step 2 specifically includes the following steps: Step 2.1: The vehicle receives the information transmitted by the vehicle in front and verifies the ID and timestamp of the vehicle in front. If the timestamp T(t) of the transmitted information is the same as the timestamp T(t-Δt) received previously, it is considered that a repeated attack has occurred. If the information transmitted by the vehicle in front is not received after exceeding the time threshold, it is considered that a denial of service attack has occurred. Step 2.2, after the information is verified by the timestamp, the vehicle sensor identification data is compared with the driving data transmitted by the preceding vehicle. If the data gap exceeds the threshold, it is considered that a spoofing attack has occurred; Step 2.3: If the frequency of the model system's safety detection is f, then the number of detections performed within a limited time period h is p = f × h. If p0 of the detection results are abnormal, p0 ≤ p; then perform correlation analysis on the value of p0 according to formula (7): In the formula, is the judgment threshold of the number of error detections.

3. According to the method for identifying and demodulating CAV network attacks in formation in claim 1, it is characterized in that: The real-time reputation value T of the information provided by vehicle j at time t-1 j,t-1 According to formula (13), T j,t-1 =1-(ω1v j,ref +ω2d j,ref +ω3a j,ref ) (13) Among them, v j,ref represents the relative error between the speed of the hit vehicle provided by vehicle j and the reference speed of the hit vehicle, d j,ref represents the relative error between the hit vehicle position provided by vehicle j and the hit vehicle reference position, a j,ref It represents the relative error between the acceleration of the hit vehicle provided by vehicle j and the reference acceleration of the hit vehicle, and ω1, ω2, and ω3 represent the corresponding weights respectively.

4. An electronic device, characterized in that: The method as described in any one of claims 1 to 3 is adopted to realize the identification and demodulation of CAV network attacks in formation.

5. A computer storage medium, characterized in that: The storage medium stores at least one program instruction, and the at least one program instruction is loaded and executed by the processor to implement the CAV network attack identification and demodulation method in formation as described in any one of claims 1 to 3.

Citation Information

Patent Citations

  • Vehicle formation implementation method for detecting data tampering attack

    CN113343230A

  • V2x-based motorcade cooperative braking method and system

    WO2021197246A1