A collusion vehicle detection method based on fuzzy evaluation density clustering in Internet of Vehicles
By combining a reputation update mechanism with fuzzy mathematics and density clustering algorithms, the problem of detecting malicious vehicle collusion attacks in the Internet of Vehicles was solved, achieving efficient identification of colluding vehicles and improving network security.
Patent Information
- Application Number
- CN202211590100.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-12
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2042-12-12
AI Technical Summary
In the Internet of Vehicles (IoV), collusive attacks by malicious vehicles are difficult to identify and detect efficiently. In particular, the covertness and scale of collusive attacks lead to a decline in network performance and even network paralysis.
By designing a reputation update mechanism that combines fuzzy mathematics theory and an improved density clustering algorithm, vehicle reputation is evaluated using subjective recommendation trust, objective data trust, and historical reputation values. This process filters out individual malicious vehicles and detects colluding vehicles through density clustering analysis.
It improves the accuracy and recall rate of malicious vehicle detection, effectively identifies colluding vehicles, and prevents network performance degradation and security threats.
Smart Images

Figure CN115996383B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of malicious node detection in Internet of Vehicles system, and particularly relates to a collusion vehicle detection method based on fuzzy evaluation density clustering in Internet of Vehicles. BACKGROUND
[0002] Under the background of vigorously developing urban intelligent transportation, Internet of Vehicles as a key technology to support intelligent transportation has been concerned and researched by the industry early, and has begun to be gradually commercialized at the present stage. Internet of Vehicles (IoVs) refers to the vehicle's on-board equipment using new generation wireless communication technology to effectively apply relevant vehicle dynamic information in the fusion information network platform to provide various functional application services for vehicles. The fusion information network platform in Internet of Vehicles realizes "three-network fusion" of in-vehicle network, inter-vehicle network and vehicle mobile Internet to achieve vehicle-to-vehicle, vehicle-to-road, vehicle-to-person and other all-around network connection.
[0003] Internet of Vehicles has the characteristics of fast moving speed of vehicle nodes, short connection time between vehicle nodes, temporary joining or exiting of vehicle nodes, and dynamic frequent changes of network topology structure. The openness and dynamic characteristics of Internet of Vehicles make it face more serious and more difficult to detect security risks. The premise for Internet of Vehicles to effectively operate is that each vehicle node entity and road infrastructure in the network is safe and trustworthy, and they interact with each other in good faith. However, there may be abnormal vehicle nodes in the real Internet of Vehicles, which will behave differently from normal vehicle nodes due to interests or purposes. In Internet of Vehicles, the vehicle nodes that actively interact, objectively and fairly evaluate, and provide services in good faith are called normal vehicle nodes, and the vehicle nodes that have behaviors such as fabricating false messages, tampering with correct and safe messages, launching black hole attacks, Sybil attacks, intermittent attacks, collusion attacks, etc. are called malicious vehicle nodes. Malicious vehicle nodes will attack normal vehicle nodes in the network for their own interests or malicious purposes, which will destroy network order, affect network operation, and even cause safety accidents, posing a safety threat to Internet of Vehicles users.
[0004] In an open network environment, malicious vehicles will inevitably publish false messages to deceive or attack other normal vehicles, especially collusion attacks, which are more destructive and more threatening. They will seriously disrupt the traffic order, reduce the local network performance of Internet of Vehicles, and even cause network paralysis. Therefore, resisting attacks by malicious vehicles and efficiently identifying these malicious vehicles have become a hot spot in the research of vehicular ad hoc network security. SUMMARY
[0005] To solve the above problems of prior art, the application designs a reputation updating method according to subjective and objective trust values and historical reputation values, realizes strict vehicle reputation updating and effectively restricts malicious behavior of vehicles; based on fuzzy mathematics basic theory, through fuzzy operation of comprehensive evaluation matrix and weight matrix, the first round of malicious vehicle screening is performed on vehicles participating in information interaction; then, an improved density clustering algorithm is adopted, taking single malicious vehicle obtained through fuzzy comprehensive evaluation as a core point, vehicles in the communication range of the core point are traversed and it is judged whether the vehicle is a new core point vehicle, and colluding malicious vehicles of the vehicle are searched out.
[0006] The technical scheme of the collusion vehicle detection method based on fuzzy evaluation density clustering in the Internet of Vehicles provided by the application comprises:
[0007] The receiving information vehicle obtains the subjective recommendation trust, objective data trust and historical reputation value of the sending information vehicle in real time;
[0008] The three reputation values are proportionally weighted to obtain the trust relationship value of the sending information vehicle at the current time by the receiving information vehicle;
[0009] The sending vehicle node of this information interaction is updated in reputation by using the size relationship between the current trust relationship value and the trust relationship threshold value;
[0010] The three reputation values after updating are processed according to fuzzy comprehensive evaluation, the evaluation weight of the three reputation values is calculated by using entropy weight method, the sending information vehicle is screened for malicious vehicle, and single malicious vehicle is detected;
[0011] The detected single malicious vehicle is designated as a clustering core point vehicle, and the positions of the sending information vehicles at different times are analyzed by using density clustering analysis to obtain a collusion vehicle set.
[0012] The application has the following beneficial effects:
[0013] According to the subjective recommendation trust, the objective data trust and the historical reputation value, the trust relationship value of the sending information vehicle at the current time by the receiving information vehicle is obtained by proportionally weighting the three values, the reputation of the vehicle of this information interaction is updated by using the size relationship between the current trust relationship value and the trust relationship threshold value, and the real reputation value of the sending information vehicle can be reflected as much as possible. Therefore, the reputation value of the normal vehicle slowly increases with the increase of the number of normal interactions, and the reputation value of the malicious vehicle sharply decreases with the increase of the number of malicious interactions.
[0014] The application is first in the field of malicious node detection of Internet of Vehicles, based on the basic theory of fuzzy mathematics, the membership function is constructed to quantify the trust degree of subjective and objective trust values and historical reputation values, and the entropy weight method is used to calculate the evaluation weight of the three. Through the fuzzy operation of the comprehensive evaluation matrix and the weight matrix, the first round of malicious vehicle screening is carried out on the vehicles participating in information interaction, so as to comprehensively judge the trust degree of the vehicles participating in information interaction, and provide support for the second round of search collusion vehicles.
[0015] The application finds that due to the variability of the role of malicious vehicles in Internet of Vehicles, one round of detection cannot maximize the detection of malicious vehicles. Therefore, further considering that the colluding malicious vehicles have space-time accompanying nature, the application is based on the improved density clustering algorithm, taking the malicious vehicle obtained by fuzzy comprehensive evaluation as the core point, traversing the vehicles in the communication range of the core point and judging whether it is a new core point vehicle, so as to search for the colluding malicious vehicles with the vehicle. Thus, while maintaining the accuracy of malicious vehicle detection, the recall rate of detection is improved, and the malicious vehicles are maximized. BRIEF DESCRIPTION OF DRAWINGS
[0016] Figure 1 The model diagram of the collusion attack system of Internet of Vehicles used in the application is shown in the figure;
[0017] Figure 2 The flow chart of the collusion node detection scheme proposed in the application is shown in the figure;
[0018] Figure 3 The division diagram of the communication range of RSU in Internet of Vehicles proposed in the application is shown in the figure;
[0019] Figure 4 The membership function diagram proposed in the application is shown in the figure;
[0020] Figure 5 The malicious node density clustering diagram proposed in the application is shown in the figure. DETAILED DESCRIPTION
[0021] The technical solutions in the embodiments of the application will be described clearly and completely in the following with reference to the drawings in the embodiments of the application. Obviously, the described embodiments are only part of the embodiments of the application, not all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the application.
[0022] The application assumes that Figure 1The collusion attack vehicle networking communication scene system model is shown. The authorized agency, a road side unit (RSU), a normal vehicle and a malicious vehicle are composed. The authorized agency provides network information interaction authorization and revocation authorization for the vehicle according to the real identity of the vehicle; the RSU has a larger communication range and computing resources, and participates in the broadcast of the vehicle request and the related calculation of the vehicle reputation in the application; the normal vehicle participates in the information interaction in the network, and provides real information to the information requester; the malicious vehicle participates in the information interaction in the network, and provides false information to the information requester.
[0023] In particular, the malicious vehicles can jointly form a collusion group to carry out collusion attacks. Since the collusion attack has scale and concealment, it will cause greater loss than a single attack. In addition, the collusion attackers can be differentiated into attack implementers and attack cooperators, so that the collusion attack is divided into message collusion attack and reputation collusion attack.
[0024] 1) Message collusion attack: refers to that the attackers jointly send the same false message to the message requester for a certain event, so as to confuse the vehicle node and make it make incorrect driving decisions, which endangers the driving safety. For example, Figure 1 As shown, the collusion vehicle nodes V2 and V3 jointly send false messages to the normal vehicle V1 in front of the accident, which endangers the driving safety of the normal vehicle V1.
[0025] 2) Reputation collusion attack: in order to prevent the collusion members from being detected by the reputation mechanism due to the low reputation value, the attackers jointly increase the reputation value of the collusion members, or lower the reputation value of the normal vehicle, so as to affect the trust judgment of other vehicles on the vehicle node. For example, Figure 1 As shown, when the vehicle V5 requests the recommended reputation of the normal vehicle V7, the normal vehicle V6 gives a fair recommended reputation according to the historical interaction with the normal vehicle V7, while the surrounding malicious collusion group members V8, V9 and V 10 provide false reputation values to reduce the trust degree of the normal vehicle V7; when the normal vehicle V 13 requests the recommended reputation of the malicious vehicle V 12 , the normal vehicle V 11 gives a fair recommended reputation according to the historical interaction with V 12 , while the surrounding malicious collusion group members V 14 , V 15 and V 16 provide false reputation values to increase the trust degree of the malicious vehicle V 12 .
[0026] For the above attack, the embodiment proposes a collusion vehicle detection method based on fuzzy evaluation density clustering in vehicle networking, as shown in Figure 2 The method comprises:
[0027] 101. The receiving vehicle obtains in real time the subjective recommendation trust, objective data trust, and historical reputation value of the sending vehicle;
[0028] 102. By weighting the reputation values of the three parties proportionally, the trust relationship value between the receiving vehicle and the sending vehicle at the current moment is obtained;
[0029] 103. Utilize the relationship between the current trust relationship value and the trust relationship threshold to update the reputation of the vehicle node that sent the information in this interaction;
[0030] 104. Based on the fuzzy comprehensive evaluation, the updated reputation values of the three parties are processed, and the evaluation weight of the reputation values of the three parties is calculated using the entropy weight method. Malicious vehicles are screened for vehicles that send information, and single malicious vehicles are detected.
[0031] 105. Designate the detected single malicious vehicle as the core clustering object, and use density clustering analysis to cluster the locations of vehicles sending information at different times to obtain the set of colluding vehicles.
[0032] In light of the above embodiments, this embodiment will provide a more detailed description of each step, specifically including the following:
[0033] Due to the highly dynamic mobility of vehicles and the constant changes in surrounding vehicles, the safety of vehicles exchanging information cannot be guaranteed. When a receiving vehicle receives information from a sending vehicle, it needs to determine the credibility of the message to obtain a trust relationship value between the vehicles. Specifically, at the current time t, the trust relationship value of the receiving vehicle i to the sending vehicle j is related to the historical reputation value of the sending vehicle j and the trustworthiness of the received data. It also considers the comprehensive judgment of other vehicles, that is, the recommended trust generated by aggregating the historical interactions between other vehicles and the sending vehicle. Therefore, the specific trust relationship value of the receiving vehicle to the sending vehicle at the current time is as shown in formula (1).
[0034]
[0035] in, Rep represents the trust relationship value between the receiving vehicle i and the sending vehicle j at time t. j (t-1) represents the historical reputation value of vehicle j that sent the information at time t-1; Trust j (data t RecT represents the trust value of the data transmitted by vehicle j at time t. j (t) represents the recommendation trust value of surrounding recommended vehicles for the information-sending vehicle j, that is, the subjective recommendation trust value for the information-sending vehicle j at time t. α i βi and gamma i are weight factors, and alpha i + beta i + gamma i = 1. According to the empirical value method, in some examples, alpha i = 0.3, beta i = 0.3, and gamma i = 0.4 can be determined.
[0036] In the vehicle networking interaction scene, there are mainly three types of vehicles:
[0037] 1) authoritative vehicle (v A ): including police vehicles, ambulance vehicles, military vehicles, etc., such vehicles have central authorization and have high credibility.
[0038] 2) public transport vehicle (v P ): including taxis, buses, etc., such vehicles have partial authorization from the local government and have relatively high credibility.
[0039] 3) general vehicle (v G ): including private cars, network platform vehicles, and vehicles registered for a short time, etc., with general credibility.
[0040] Since screening the data of each vehicle will undoubtedly consume huge computing overhead, and may even cause high latency problems, the present application converts data trust into role-oriented trust, and replaces data trust with vehicle role trust. For the first two types of vehicles, we assign higher data weights, and for the latter type of vehicle, we assign smaller data weights. When multiple types of vehicles appear at the same time, then select according to priority v A >v P >v G .
[0041] When the receiving information vehicle receives different types of event messages sent by different sending information vehicles, the event types are classified, and it is checked whether there are special vehicles (such as authoritative vehicles, public transport vehicles) participating in information interaction. If so, the vehicles with event type data consistent with the special vehicles are granted data weights consistent with the special vehicles. Therefore, the updating method of the objective data trust value of the sending information vehicle includes dividing the vehicle types into authoritative vehicles, public transport vehicles, and general vehicles; in order of decreasing data weight, the authoritative vehicles, public transport vehicles, and general vehicles are assigned different numerical values, and in a certain example, Trust j (data t ) can be calculated as formula (2).
[0042]
[0043] It can be understood that in addition to the above examples, the objective data trust value of the sending information vehicle can also select other values, as long as the values of the authoritative vehicle, the public transport vehicle and the general vehicle are between 0-1 and decrease in turn.
[0044] Due to the limited communication range of the vehicle and the collusion of the malicious vehicle, the present application is based on the RSU communication range com RSU Three areas are divided, respectively, ξ1, ξ2, ξ3, wherein As Figure 3 shown. The receiving message vehicle will need to be recommended trust evaluation vehicle, that is, the sending information vehicle sends to the RSU, and the RSU performs range expansion broadcast to reduce the advantage of the collusion vehicle in the location, and the receiving information vehicle in the RSU communication range will be randomly selected as the recommended vehicle according to different areas; the recommended vehicle of the three areas also gives an evaluation to the sending information vehicle; thereby diluting the number of collusion vehicles and improving the stability of the recommended trust system.
[0045] The updating method of the subjective recommended trust value of the sending information vehicle includes dividing the recommended vehicle evaluation into positive evaluation and negative evaluation, when the recommended trust value is greater than the trust relationship threshold Th T , it is considered as positive evaluation, otherwise as negative evaluation. The evaluations of different areas are aggregated respectively. The positive evaluation, negative evaluation and aggregated recommended trust are shown in formulas (3), (4), (5).
[0046]
[0047]
[0048]
[0049] Wherein, RecT + represents the positive evaluation given by the recommended vehicle, RecT - represents the negative evaluation given by the recommended vehicle, represents the subjective recommended trust value of the sending information vehicle j given by the kth recommended vehicle at time t, n represents the number of recommended vehicles giving positive evaluation, and m represents the number of recommended vehicles giving negative evaluation; the sum of n+m represents the number of all recommended vehicles giving recommended trust value, which is the total number of randomly selected recommended vehicles in the three areas.
[0050] Considering the strict updating mechanism of the vehicle reputation, that is, the reputation value of sending correct message grows slowly and the reputation value of sending malicious message drops rapidly. The updating method of the historical reputation value of the sending information vehicle includes comparing the current inter-node trust relationship value with the trust relationship threshold Th TThe comparison is made. The reputation increment value of the information sending vehicle is calculated, and the historical reputation value is adjusted according to the reputation increment value; the formula used is shown as formula (6).
[0051]
[0052] The reputation value update of the information sending vehicle is shown as formula (7).
[0053]
[0054] Wherein, Rep j (t) represents the historical reputation update value of the information sending vehicle j at t moment; ΔRep(j) represents the reputation increment value of the information sending vehicle j; Th T represents the trust relationship threshold value.
[0055] The reputation update method designed above can effectively constrain malicious vehicle behavior, but cannot accurately detect malicious vehicles and their colluding vehicles. Therefore, the present application detects single malicious nodes based on a fuzzy comprehensive evaluation method, and improves the density clustering algorithm based on single malicious nodes to realize the detection of colluding nodes, as shown in formula (8). Figure 2 When the historical reputation, recommended trust and data trust three-party data are obtained, the membership degrees of the three to the comment set are calculated through a membership function, so as to perform a round of malicious vehicle screening on the vehicles participating in information interaction. The detected single malicious node is specified as a clustering core point, and whether it is a new core point is judged by traversing the vehicles in the core point range. Based on the high dynamic change characteristics of the vehicles and the closeness and accompanying nature of the positions of the colluding vehicles, the vehicle positions at different moments are clustered and analyzed to obtain the final colluding vehicle set. According to the fuzzy mathematics theory, the fuzzy comprehensive evaluation mainly includes five steps.
[0056] Step 1: Construct the argument domain of the evaluation object, that is, the factor set U = {u1, u2, u3... u m};
[0057] Step 2: Determine the comment set V = {v1, v2, v3... v n} of the evaluation object;
[0058] Step 3: Calculate the membership degree of the factor set to the comment set, so as to construct the evaluation matrix R;
[0059] Step 4: Calculate the index weight of each factor through the entropy weight method, so as to determine the weight matrix W = (w1, w2, w3... w m );
[0060] Step 5: Construct the membership degree matrix B of each information sending vehicle belonging to the comment set through the evaluation matrix R and the index weight matrix W, and obtain the comment corresponding to the maximum value of the B matrix.
[0061] Fuzzy mathematics is used to perform fuzzy comprehensive evaluation of individual malicious nodes for vehicles participating in information exchange. Assume that at time t, the receiving vehicle receives messages from n sending vehicles, represented as I = {I1, I2, I3, ..., I...} n This invention determines the trustworthiness of each vehicle by applying fuzzy comprehensive evaluation. It primarily uses three factors—historical reputation score, objective data trust, and subjective recommendation trust—to comprehensively evaluate each vehicle, i.e., U = {historical reputation, data trust, recommendation trust}. The evaluation set is set as V = {distrust, general trust, trust}. Based on fuzzy mathematics theory, trust is a skewed indicator, requiring a skewed membership function; distrust is a skewed indicator, requiring a skewed membership function; and general trust is an intermediate indicator, requiring an intermediate membership function. Specific membership functions are as follows: Figure 4 As shown.
[0062] Calculate the membership degree of each of the three obtained factor data to the comment set according to their corresponding membership functions, thereby constructing the evaluation matrix R:
[0063]
[0064] The entropy weight method is used to calculate the weights of each factor. When n vehicles participate in information interaction and it is necessary to determine whether these n vehicles are malicious nodes, the following steps are taken: First, the weight of each sample value under each factor indicator is calculated. Second, the entropy value of each indicator is calculated based on the weights. Finally, the weight of each indicator is calculated. The formula is as follows:
[0065]
[0066] Where k = 1 / ln(n), x ij Let represent the parameters of the i-th vehicle sending information under the j-th factor set, including historical reputation value, objective data trust value, and subjective recommendation trust value; j = 1, 2, 3, which can correspond to historical reputation, data trust, and recommendation trust. From this, we can obtain the index weight matrix W = (w1, w2, w3) for the three factor sets. According to the fifth step of fuzzy comprehensive evaluation, we can obtain the membership matrix B of each vehicle belonging to the comment set.
[0067]
[0068] The maximum value in matrix B corresponds to the trust level of the vehicle, and vehicles in the set of distrustful comments are considered malicious vehicles. The set of malicious vehicle nodes selected through fuzzy comprehensive evaluation in one round is represented as M = (m1, m2, m3, ..., m...). s ), where s≤n.
[0069] When a single malicious vehicle is detected, since the colluding nodes exhibit tightness and concomitance in geographical position, the source nodes are the malicious vehicles, and the colluding vehicle nodes are searched according to the improved density clustering algorithm, as shown in Figure 5 The main idea of the density clustering algorithm is to determine two very critical parameters: neighborhood eps and minimum sample number minPts. The relevant definitions are as follows:
[0070] (1) Neighborhood: for any given vehicle x and distance ε, the sample set whose distance to vehicle x is less than ε is the neighborhood of vehicle x.
[0071] (2) Core object: refers to the neighborhood of vehicle x containing not less than minPts vehicles.
[0072] Core point(v i )=
[0073] {v i ∈V0|distance (v, core point)<eps (10)
[0074] and v i (pts)>minPts}
[0075] Where Core point(v i ) represents that v i is a core object, i.e. a core point vehicle; v i represents an unmarked vehicle; V0 represents a set of vehicles to be classified; distance(v i ,core point) represents the distance between vehicle v i and the core point vehicle core point; eps represents the neighborhood radius of the core point vehicle; v i (pts) represents the number of vehicles in the communication range of vehicle v i ; and minPts represents the minimum number of vehicle nodes in the communication range of the colluding malicious vehicle.
[0076] (3) Density direct: if vehicle x is a core object and vehicle y is in its neighborhood eps, then vehicle y is said to be density directly reachable from vehicle x.
[0077] (4) Density reachable: if there are x1, x2...x n core point vehicles, and a=x1, b=x n , each sample is density directly reachable from its previous sample, then vehicle a is density reachable from vehicle b
[0078] (5) Density connection: if there is a vehicle z such that it is density reachable to both vehicle x and vehicle y, then vehicle x and vehicle y are density connected.
[0079] In summary, based on the basic idea of density clustering analysis, the malicious vehicle node is found out by the collusion vehicle node through fuzzy evaluation. The specific steps are as follows:
[0080] The first step is to set the neighborhood radius eps and the minimum sample number minPts, and the malicious vehicle detected in the last stage is specified as a core point vehicle and marked to join the classified vehicle set V 1, The unmarked vehicle joins the unclassified vehicle set V0, and by traversing the vehicle in the unclassified vehicle set V0, the Euclidean distance of the vehicle from the core object is calculated and it is judged whether it is a core point vehicle density direct vehicle node;
[0081] The second step is to judge whether the density direct point is a core point vehicle according to the judgment formula (10);
[0082] The third step is to mark the core point determined in the second step to join the classified vehicle set V1;
[0083] The fourth step is to repeat the second and third steps until no new core point vehicle appears, and the marked classified vehicle set V1 is output.
[0084] The fifth step is to update the position based on the dynamic mobility of the vehicle, repeat steps one, two, three and four with T as the detection time and t as the time interval, and output the collusion vehicle set CM=(cm1, cm2, cm3......cm s ).
[0085] Those skilled in the art can understand that all or part of the steps in the above embodiments can be completed by a program instructing related hardware, and the program can be stored in a computer readable storage medium, and the storage medium can include ROM, RAM, magnetic disk or optical disk, etc.
[0086] Although the embodiments of the present application have been shown and described, those skilled in the art can understand that various changes, modifications, replacements and variations can be made to the embodiments without departing from the principles and spirits of the present application, and the scope of the present application is defined by the appended claims and their equivalents.
Claims
1. A method for detecting collusive vehicles based on fuzzy evaluation density clustering in the Internet of Vehicles, characterized in that, The method includes: The receiving vehicle obtains in real time the subjective recommendation trust, objective data trust, and historical reputation value of the sending vehicle; The trust relationship value between the receiving vehicle and the sending vehicle at the current moment is obtained by weighting the three reputation values proportionally; including: ; in, Indicates in Vehicles that receive information at all times For the vehicle sending information Trust relationship value; Indicates in Vehicles that send information at all times Historical reputation value; Indicates in Vehicles that send information at all times The trust value of objective data; Indicates in Constantly monitor the vehicle sending information Subjective recommendation trust value; and It is a weighting factor, and ; The method for updating the historical reputation value of a vehicle sending information includes calculating the reputation increment value of the vehicle sending information based on the relationship between the trust relationship value and the trust relationship threshold, and adjusting the historical reputation value according to this reputation increment value; the formula used includes: ; ; in, Indicates in Vehicles that send information at all times Historical reputation update value; Indicates the vehicle sending the information The incremental value of reputation; Indicates the threshold of trust relationship; The reputation of the sending vehicle node in this information exchange is updated by using the relationship between the current trust relationship value and the trust relationship threshold. The updated reputation values of the three parties are processed based on fuzzy comprehensive evaluation. The evaluation weight of the reputation values of the three parties is calculated using the entropy weight method. Malicious vehicles are screened for vehicles that send information, and single malicious vehicles are detected. The detected single malicious vehicle is designated as the core vehicle for clustering. Density clustering analysis is used to cluster the locations of vehicles sending information at different times to obtain the set of colluding vehicles.
2. The method for detecting collusive vehicles based on fuzzy evaluation density clustering in a vehicle-to-everything (V2X) network according to claim 1, characterized in that, The method for updating the objective data trust value of the vehicle sending the information includes classifying the vehicle type into authoritative vehicles, public transportation vehicles, and general vehicles; and assigning different values to authoritative vehicles, public transportation vehicles, and general vehicles in descending order of data weight.
3. The method for detecting collusive vehicles based on fuzzy evaluation density clustering in a vehicle-to-everything (V2X) network according to claim 1, characterized in that, The method for updating the subjective recommendation trust value of the information-sending vehicle includes dividing the communication range of the roadside unit into three areas, randomly selecting a portion of the information-receiving vehicles in each area as recommended vehicles; each recommended vehicle in each area provides an evaluation of the information-sending vehicle; the evaluations of the recommended vehicles are divided into positive and negative evaluations; when the subjective recommendation trust value is greater than the trust relationship threshold... A positive review is determined when the evaluation is positive, and a negative review is determined otherwise. Positive and negative reviews from different regions are aggregated separately.
4. The collusive vehicle detection method based on fuzzy evaluation density clustering in the Internet of Vehicles according to claim 1, characterized in that, The updated reputation values of the three parties are processed according to the fuzzy comprehensive evaluation, and the evaluation weight of the reputation values of the three parties is calculated using the entropy weight method. Malicious vehicles are screened for the vehicles that send information, and the detection of single malicious vehicles includes the factor set and comment set of the evaluation object. Calculate the membership degree of the factor set to the comment set, and then construct the evaluation matrix; The weights of each factor are calculated using the entropy weight method, thereby constructing a weight matrix. A membership matrix is constructed using a weight matrix and an evaluation matrix to determine the membership degree of each information-sending vehicle to the set of comments. The comments in the membership matrix represent the trust level of the vehicle, and vehicles in the set of distrust comments are considered as single malicious vehicles.
5. A method for detecting collusive vehicles based on fuzzy evaluation density clustering in a vehicle-to-everything (V2X) network according to claim 4, characterized in that, The formula for calculating the weight of each factor in the weight matrix is as follows: ; in, Indicates the first The weights of each factor's indicators , Indicates the first Under the first factor The parameters of each vehicle sending information include historical reputation value, objective data trust value, and subjective recommendation trust value; .
6. The method for detecting collusive vehicles based on fuzzy evaluation density clustering in a vehicle-to-everything (V2X) network according to claim 1, characterized in that, The detected single malicious vehicle is designated as the cluster core vehicle, and density clustering analysis is used to cluster the vehicle positions at different times to obtain the set of colluding vehicles, including a set neighborhood radius. and minimum sample size The single malicious vehicle detected in the previous stage is designated as the cluster core vehicle and marked to be added to the already classified vehicle set. Unmarked vehicles are added to the vehicle set to be classified. By traversing the set of vehicles to be classified For each vehicle in the sample, calculate its Euclidean distance from the core point vehicle and determine whether it is a sample point directly reachable by the core point vehicle density; determine whether the density directly reachable point is a core point vehicle according to the determination formula. The vehicles identified as key points are marked and added to the already classified vehicle set. ; Repeat the iteration until no new core point vehicles appear, and then mark the set of classified vehicles. Output; based on the vehicle's dynamic mobility and dynamic position updates, to For the detection time, in Repeatedly update the classified vehicle set at time intervals. and to The second clustering outputs the intersection set of the colluding vehicles.
7. A method for detecting collusive vehicles in a vehicle-to-everything (V2X) network based on fuzzy evaluation density clustering as described in claim 6, characterized in that, The determination formula is expressed as follows: ; in, express The core vehicle; Indicates unmarked vehicles; This represents the set of vehicles to be classified. Indicates vehicle With core vehicles The distance; Represents the neighborhood radius of the vehicle at the core point; Indicates vehicle Number of vehicles within the communication range; This represents the minimum number of vehicle nodes within the communication range of the conspiring malicious vehicles.
Citation Information
Patent Citations
Collusion malicious vehicle node detection method for Internet of Vehicles
CN110177370A
Vehicle-mounted edge computing task unloading method and system
CN115437792A