Protecting AI models used for lane / traffic management in autonomous systems

By using verifiable source data signature verification technology in ADAS and autonomous vehicles, lane and traffic management AI models are protected, the vulnerability of models to attacks is solved, the security and accuracy of models are improved, and the driving safety of autonomous vehicles is enhanced.

CN116158056BActive Publication Date: 2026-03-10HARMAN INT IND INC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-21
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Lane and traffic management AI models in ADAS and autonomous vehicles are vulnerable to cyberattacks, leading to potential malfunctions and safety risks.

Method used

By receiving training data from a verifiable source, using private key signatures to verify and prevent illegitimate data, the integrity of AI model data is protected during the training, testing, and deployment phases; after deployment, dynamic data is verified using public key signatures during the continuous learning phase, ensuring the security of model parameters.

Benefits of technology

It effectively prevents malicious data intrusion, ensures the accuracy and security of AI models, reduces false alarms and false negatives, and improves the driving safety of autonomous vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116158056B_ABST
    Figure CN116158056B_ABST
Patent Text Reader

Abstract

This invention provides a system and method for protecting lane and traffic management AI models used in advanced driver assistance systems (ADAS) or autonomous vehicles. Only lane and traffic management data identified from verifiable sources is permitted for testing and training the AI ​​model. All other data is blocked. The controllable parameters of the AI ​​model are encrypted before deployment. After deployment, the controllable parameters are decrypted, and only signature-verified dynamic learning data is applied to the AI ​​model for continuous learning.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference to related applications

[0002] This application claims priority to Indian Provisional Patent Application Serial No. 202011030333, filed on July 16, 2020, entitled “Securing Artificial Intelligence Models For Lane / Traffic Management In An Autonomous System”. Technical Field

[0003] This disclosure relates to protecting artificial intelligence models from cyberattacks, and more specifically, to protecting artificial intelligence models used in advanced driver assistance systems (ADAS) and / or lane / traffic management in autonomous vehicles. Background Technology

[0004] Advanced Driver Assistance Systems (ADAS) aim to improve safety and enhance the overall driving experience by automating vehicle systems. Many features of ADAS are adaptive and therefore rely on input from multiple data sources. Modern vehicles are monitored and controlled by dozens of digital computers coordinated through an internal vehicle network to provide data to / from numerous data sources both inside and outside the vehicle. Autonomous driving goes beyond simply assisting human drivers; it involves navigating roads and interpreting traffic controls without human intervention. Vehicles equipped with ADAS and / or autonomous driving capabilities may be vulnerable to cyberattacks due to their cellular and / or wireless connectivity, making them susceptible to such attacks. In the following text, ADAS and / or autonomous driving will be collectively referred to as ADAS.

[0005] Machine learning (ML), deep learning, learning, training, and preparation can be applied to artificial intelligence (AI) models for ADAS and autonomous vehicles, for example, to improve the accuracy of lane management and traffic management. AI models are developed using lane and traffic management data related to the planning and control of urban area traffic, including signals, signs, and forms built into the road, such as curbs, median strips, parking vibration strips, etc. Static training data is used to train and test the model during preparation. Once the AI ​​model is deployed, it is continuously evaluated against its desired objectives and continuously monitored and managed using periodic updates.

[0006] ADAS and autonomous vehicles make independent decisions using multiple connected AI-based systems by processing multi-sensor fusion data. The serious nature of ADAS and autonomous driving applications makes it critical that the data used to train the models is good data and that it is protected from cyber attackers. AI models need to be fully protected, especially the AI models used in lane management and traffic management in ADAS and autonomous vehicles. SUMMARY

[0007] The present subject matter proposes a system and method for protecting AI models used for lane / traffic management that can be utilized by ML systems in ADAS and autonomous vehicles. Active lane / traffic management aims to increase peak capacity and make traffic flow smooth on roads, and the AI models use standardized signals from real government agencies that can be verified. This type of data is verifiable, resulting in the insertion of multiple security solutions on vulnerable points in the ML system of AI models for lane and traffic management. Protecting vulnerable points can ensure that training, testing, and developing AI models are performed using data that has been protected from attacks.

[0008] In one or more embodiments, an example of a method for protecting lane and traffic management AI models in ADAS systems is provided, the method comprising: receiving training data to prepare lane and traffic management AI models for deployment in ADAS; identifying from the received training data data supplied by a verifiable source; performing signature verification on the data supplied by the verifiable source using a private key associated with the verifiable source; blocking data other than the signature verified data; applying the signature verified data to the AI models for training and testing prior to deployment of the AI models. The training data is lane and traffic management data supplied by a legal or government agency.

[0009] In one or more embodiments, after deployment of the AI models, the AI models are continuously monitored and dynamic learning data of lane and traffic management to be used to retrain and update the AI models is signature verified. Only signature verified data is used to retrain and update controllable parameters of the AI models, any other data will be blocked.

[0010] In one or more embodiments, examples of a system for protecting artificial intelligence (AI) models for lane management and traffic management in a vehicle ADAS are provided. The AI models are prepared using lane and traffic management training data that is signed verified by a known, verifiable source. The signed verified data is verified using a private key associated with the verifiable source, and only the signed verified data is used to train the AI models. Prior to deployment of the AI models, data other than that supplied by the verifiable source is blocked from entering the AI models. After deployment, continuous learning data is also signed verified prior to using the continuous learning data to retrain and update the AI models. BRIEF DESCRIPTION OF DRAWINGS

[0011] Figure 1 is a bird’s eye view of an exemplary environment having a managed lane that is an object of lane management and traffic management;

[0012] Figure 2A is a general representation of the life cycle of an AI model;

[0013] Figure 2B is a general representation of the life cycle of an AI model after it is deployed;

[0014] Figure 3 is a block diagram of an in-vehicle computing system;

[0015] Figure 4 is a block diagram of an exemplary lane / traffic management AI model;

[0016] Figure 5 is a flowchart describing a detailed method for protecting an AI model prior to deployment; and

[0017] Figure 6 is a flowchart describing a detailed method for protecting an AI model after deployment of the AI model.

[0018] The elements and steps in the drawings are presented for simplicity and clarity and are not necessarily presented in any particular order. For example, steps that can be performed simultaneously or in a different order are shown in the drawings to help improve the understanding of the embodiments of the present disclosure. DETAILED DESCRIPTION

[0019] While various aspects of the present disclosure are described with reference to particular illustrative embodiments, the disclosure is not limited to these embodiments and additional modifications, applications and embodiments can be implemented without departing from the scope of the disclosure. In the drawings, like reference numerals will be used to illustrate like parts throughout the several views. Those skilled in the art will recognize that various components set forth herein can be altered, modified, or replaced without departing from the scope of the present disclosure.

[0020] One or more embodiments provide a system and method for detecting and thwarting malicious attacks on models developed and deployed for lane and traffic management of ADAS (and / or autonomous) vehicles. Protecting model parameters from attacker data ensures that models for lane and traffic management are free from bad data. If bad data is allowed to permeate the models, false positives and false negatives can result that can cause malfunctions. Such malfunctions can be serious, especially for autonomous vehicles.

[0021] The term electronic control unit (ECU) used hereinafter refers to any embedded system that controls one or more electrical systems or subsystems in a vehicle. Types of ECUs include electronic / engine control modules, powertrain control modules, transmission control modules, brake control modules, central control modules, central timing modules, general electronic control modules, body control modules, suspension control modules, control units, or control modules. A vehicle can include several independent control modules. Physical data refers to the electrical and physical specifications of a data connection. Physical data defines the characteristics between a device and a physical transmission medium. This includes pinout, voltage line impedance, cable specifications, signal timing, hubs, repeaters, network adapters, strength, frequency, gradient, amplitude of variation, modulation method, etc.

[0022] A communication channel used hereinafter refers to a physical transmission medium, such as a wired or logical connection through a multiplexed medium, such as a radio channel. A channel is used to convey an information signal, such as a digital bit stream, from one or more transmitters or receivers. A channel has a certain information-carrying capacity, usually measured in its bandwidth (in Hz) or data rate (in bits per second). A communication channel (also called a path) uses media and broadcasting. Network-based services refer to networks, physical cables, Wi-Fi, cell phones, Bluetooth, RF, and GPS.

[0023] Any one or more of the ECUs, servers, receivers, or devices described herein include computer-executable instructions that can be compiled or interpreted from computer programs created using various programming languages and / or technologies. Generally, a processor, such as a microprocessor, receives instructions, for example, from memory, computer-readable media, or the like, and executes the instructions. The processing unit includes a non-transitory computer-readable storage medium capable of executing instructions of a software program. The computer-readable storage medium can be, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. Any one or more of the devices herein can rely on firmware, which can need to be updated from time to time to ensure compatibility with operating systems, improvements and additional functionality, security updates, and the like. Connectivity and networking servers, receivers, or devices can include, but are not limited to, SATA, Wi-Fi, lightning, Ethernet, UFS, 5G, and the like. One or more servers, receivers, or devices can operate using a dedicated operating system, multiple software programs, and / or a platform for interfaces, such as graphics, audio, wireless networks, enabling applications, hardware of integrated vehicle components, systems, and external devices, such as smartphones, tablet computers, and other systems, to name a few.

[0024] Figure 1 is a bird’s eye view of an exemplary environment 100 having a managed lane that is an object of lane management and traffic management. An agency that controls the managed lane can collect and / or disseminate data. This data is used by ADAS systems and autonomous vehicles to improve the driving experience by controlling traffic flow. Lane management includes management of lanes on a highway that use restrictions to enforce traffic flow to allow certain vehicles to travel within the lane while restricting others. For example, a high-occupancy vehicle (HOV) lane (also known as a carpool lane 102) restricts lane usage to vehicles 106 having at least a minimum number of passengers. A toll lane 104 restricts usage by requiring payment of a road usage fee. Other restrictions can apply to the types of vehicles allowed in the lane and the direction of traffic flow in the lane at certain times of day. The managed lane is set up, maintained, and monitored by a planning organization of a traffic department or an authoritative government agency. Data collected by the government agency includes, but is not limited to: from various vehicle sensors, from cameras 108 detecting the number of vehicle occupants or license plate data of the vehicle, historical data related to traffic volume, fees collected by toll booths, and the like. The government agency uses the collected data and historical data to continuously update lane and traffic management to improve traffic flow.

[0025] Lane and traffic management data are used in ML systems to train / test / deploy AI models, which are continuously learned within the ML system for use in ADAS and traffic assistance in autonomous vehicles. Machine learning (ML) and deep learning systems use artificial intelligence (AI) models based on training data to make predictions, rather than necessarily through programming. The process of preparing the model involves training an algorithm with training data to generate model weights and biases, which carry learned information about patterns in the data. Once the model has been trained and tested, it is deployed. After deployment, hyperparameters are used to evaluate and tune the model's performance so that the model learns effectively from the data on a continuous learning basis. Hyperparameters are learnable parameters that are continuously tuned to values ​​with correct outputs when presented during training. The combination of model parameters from the preparation phase and hyperparameters from the continuous learning phase is assembled together in the deployed model.

[0026] In AI models, training data is static and primarily responsible for defining the patterns the algorithm learns based on data with specific requirements. Hyperparameters, or learnable data, are dynamic and used during the training process after deployment to help the model learn and adapt to needs by continuously changing the model's weights and biases until a minimum error is achieved. Several points exist in the ML process that introduce the possibility of feeding malicious data into the model's training and continuous update phases.

[0027] Figure 2A This is a general representation of the AI ​​model lifecycle 200, which begins with data collection 202, data visualization 204, data exploration 206, model planning 208, model building 210, model training 212, model testing 214, model deployment 216, and model management 218. Before model deployment, steps such as collection, visualization, exploration, planning, building, training, and testing are typically performed locally, making them less susceptible to security vulnerabilities. Data at this stage is considered static data.

[0028] Once the model is deployed 216 and managed 218, it is continuously updated using ML and deep learning based on the dynamic data input to the model. The deployment of AI models is carried out using sophisticated tools across multiple platforms, such as the cloud, applications, embedded controllers, etc. Figure 2B This is a general representation of the lifecycle of an AI model after it is deployed and managed 218. The model is continuously evaluated 220 and monitored. Management 226 involves setting parameters and hyperparameters through continuous learning to continuously improve the model using updates. 216 The updated model is deployed, and the cycle continues.

[0029] For ADAS and autonomous vehicles, data transmission in ML systems with AI models for lane and traffic management can be achieved through continuous broadcasting, telematics or request-based transmission, sensor data, cameras, radar, and lidar. Examples of data transmission protocols include wireless communication links, network transmissions, and direct wired links. This makes the data vulnerable to cyberattacks. The model and ML environment must incorporate sufficient safety measures for use in ADAS and autonomous vehicles.

[0030] For ADAS and autonomous vehicles, ML systems and AI models can be manipulated by vehicle-based computing systems. Figure 3 This is a block diagram 300 of a vehicle 302, which has an in-vehicle computing system 304 that communicates with a vehicle control system 306 inside the vehicle 302 and with devices 308 outside the vehicle 302. External devices 308 may include mobile devices 310, such as smartphones and tablets, which, although not integrated into the vehicle, are operable and connectable within the vehicle 302. External devices 308 may also include one or more external services 312, each with an application 318. Other examples of external devices 308 may include, but are not limited to, Bluetooth devices 319 and external storage devices 320 such as Universal Serial Bus (USB). External devices 308 may have an application (app) 318 running on the device. The application 318 collects and transmits data between the external device and the in-vehicle computing system 304 by means of an interface processor 320. The interface processor 320 may include an external communication module 321 for communicating with the external device 308 and an in-vehicle communication processor 322 for communicating with the vehicle control system 308 integrated with the vehicle. The vehicle control system 308 may include a vehicle system 324 such as audio 326 and a vehicle control 328 such as steering control 330, brake control 332, lighting control 334, etc.

[0031] The in-vehicle computing system 304 includes various sensors, including but not limited to one or more microphones 336, antennas 338, and camera sensors 340. In-vehicle systems such as navigation systems 342 are also included in the in-vehicle computing system 304. The in-vehicle computing system 304 includes a user interface 344, such as a touchscreen 346. Sensors and systems interface with each other and with the computing system 304 to receive and process signals and data.

[0032] The in-vehicle computing system 304 includes a processor 346 and a memory 348, the memory including a non-volatile storage device 350, which enables the in-vehicle computing system 304 to send and receive data from various sensors, vehicle systems, external devices, external services, etc., making them operable to execute instructions, particularly for collecting data for developing, deploying, and maintaining AI models for lane / traffic management associated with ADAS.

[0033] Figure 4 This is a block diagram 400 of an exemplary lane / traffic management AI model 402 for ADAS / autonomous vehicles. The AI ​​model 402 receives training data 404 managed by the AI ​​model 402 for training, testing, and deploying the model. Once deployed, the model also receives data 406 in real time. Real-time data is dynamic learning data sent from sources inside or outside the vehicle. For example, external sources could be external services related to lane and traffic management data, such as lane restrictions, toll collection, etc., from applications or devices outside the vehicle. Internal sources could be internal vehicle systems, such as cameras, microphones, other sensors on the vehicle, navigation systems, user input, etc. The data received in real time is applied to the AI ​​model for continuous learning. The AI ​​model 402 is continuously monitored 408 to learn and create updates for upgrading the model over time 410.

[0034] There are multiple points in this process where the AI ​​model may be vulnerable to cyberattacks during training / testing and again after deployment. This invention aims to protect the AI ​​model used in lane / traffic management systems within ADAS / autonomous vehicle systems during training and testing, and also after deployment. This invention blocks paths from attackers at multiple attack points.

[0035] To achieve this, the subject matter of this invention considers training data 404. Training data is data used to train and test an AI model before its deployment. In this example, the training data is lane / traffic management data received from a verifiable source (such as a government agency responsible for lane and traffic management), which is used during the training and testing of the AI ​​model to develop the AI ​​model before its deployment. This data source makes it possible to implement security features that detect verifiable data and block data from attackers during the development phase of the AI ​​model. Because the source of the training data from the government agency is verifiable, only data identified as originating from a verifiable source of lane and traffic management will be used during the training of the AI ​​model. All other data is blocked.

[0036] After the AI ​​model is deployed, continuous learning operations are performed. During continuous learning, the model continuously receives data for retraining. Any data received by the in-vehicle computing system for model retraining or improvement must also be secure. Verification can be determined using a certified data pattern similar to that used by government agencies. For example, when the AI ​​model is receiving data, only data that is traffic or lane management-related is verified and allowed for retraining. Other data is not permitted. If an attacker attempts to feed malicious data during the model's continuous training, it will be considered irrelevant because it does not originate from a verifiable source and will be blocked.

[0037] Figure 5 This is flowchart 500, which describes in detail a method for protecting an AI model (hereinafter referred to as the model) before deployment. Figure 6 This is a flowchart 600 describing a detailed method for protecting a model after its deployment. The method may be, for example, derived from a reference... Figure 3 The processor in the vehicle described is used to execute the commands.

[0038] Method 500 for securing the model before deploying a traffic and lane management model includes receiving training data at step 502. The training data used for the AI ​​model before deployment is static, originates from a known source, and is of a predefined type. The data used for lane management and traffic management ADAS functions has predefined lane patterns and traffic signs defined by legal authorities. Therefore, any attempt to inject any other data is considered malicious and will be blocked. At step 504, the training data is signed using a private key associated with the data source. In this case, the source is the government agency supplying the data, and the private key is the private key supplied by the source. Only signed data at step 506 is passed and used to develop the ADAS lane / traffic management AI model at step 508. Any data other than data that cannot be identified as originating from a known source cannot be signed at step 510 and will be blocked at step 512. Signature verification ensures that the training data used to develop the model is secure.

[0039] At step 508, controllable parameters are developed during the training and testing of the AI ​​model. At step 514, the controllable parameters are encrypted using a public key, thereby protecting the AI ​​model before deployment. At step 516, a secure AI model is deployed.

[0040] Figure 6 This is a flowchart 600 describing a detailed method for protecting the model after deployment. Once deployed, the AI ​​model learns continuously, and controllable parameters such as weights and biases are updated. These updated controllable parameters are used to continuously retrain the model. The continuous monitoring and updating process includes sending data to / from... Figure 3The data supplied by the vehicle's internal and external sensors, cameras, radar, lidar, telematics, and other onboard computing systems again makes the model vulnerable to attacks that could inject errors or disruptively replace model weights and biases. Therefore, it is also essential to protect the dynamic learning data used to update controllable parameters from cyberattacks.

[0041] At step 602, after deployment, the encrypted model parameters are decrypted using the private key. The private key is managed by the ADAS OEM. The private key should be stored in a separate storage device, such as a Secure File System (SFS) Replay Protected Memory Block (RPMB). After deployment and decryption, the decrypted model runs continuously at step 604, performing the lane / traffic management tasks developed for it. (See above reference...) Figure 3 Specifically, in step 606, the AI ​​model is continuously monitored using dynamic learning data 608 received from sources inside and outside the vehicle. At this stage, the dynamic learning data 608 must be protected and verified before being applied to continuous learning.

[0042] During continuous learning operations, model parameters are evaluated against desired objectives, and the parameters are continuously monitored and managed using periodic updates of the deployed model. Communication to and from the onboard computing system generates vulnerabilities that require protection; therefore, the dynamic learning data 608 is signed and verified using a public key 610. Only signed and verified data 612 is used in continuous learning operations 614 to protect the AI ​​model. Through continuous learning 614, controllable parameters are continuously updated 616. Any data not signed and verified 618 is blocked 620. ADAS performs the tasks and operations expected by the safety AI model 604 used for lane and traffic management without fear of the model being compromised by attackers. The subject matter of this invention contributes to the safety of upcoming autonomous vehicles whose operation relies on AI models.

[0043] In the foregoing description, this disclosure has been described with reference to specific exemplary embodiments. However, various modifications and changes may be made without departing from the scope of this disclosure as set forth in the claims. The description and drawings are illustrative and not restrictive, and the modifications are intended to be included within the scope of this disclosure. Therefore, the scope of this disclosure should be determined by the claims and their legal equivalents, and not merely by the described examples.

[0044] For example, the steps recited in any method or process claim can be performed in any order, and are not limited to the specific order presented in the claim. Similarly, the components and / or elements recited in any device claim can be assembled in various arrangements or otherwise operably configured, and are therefore not limited to the specific configuration recited in the claim.

[0045] The benefits, other advantages, and solutions to problems have been described above with respect to specific embodiments; however, no benefit, advantage, solution to a problem, or any element that may cause any particular benefit, advantage, or solution to appear or become more significant should be construed as a critical, essential, or necessary feature or component of any or all claims.

[0046] The terms “comprising,” “having,” “including,” or any variation thereof are used to mean a non-exclusive inclusion, such that a process, method, article, composition, or apparatus that includes the list of elements includes not only the elements described, but may also include other elements not expressly listed or inherent to such process, method, article, composition, or apparatus. Other combinations and / or modifications of the above-described structures, arrangements, applications, proportions, elements, materials, or components used in the practice of this disclosure, except those specifically stated, may be altered or specifically adapted to particular environments, manufacturing specifications, design parameters, or other operational needs without departing from the general principles of this disclosure.

Claims

1. A computer-implemented method for detecting and preventing malicious attacks on an artificial intelligence (AI) model in an advanced driver assistance system (ADAS) of a vehicle, the method comprising the steps of: receiving training data to prepare a lane and traffic management AI model for deployment in the ADAS; identifying from the received training data data supplied by a verifiable source; performing a signature verification on the data supplied by the verifiable source using a private key associated with the verifiable source; preventing data other than the signature verified data; applying the signature verified data to the AI model for training and testing prior to deployment of the AI model; encrypting the AI model and its controllable parameters prior to deployment of the AI model to protect the AI model; deploying the encrypted AI model; performing a continuous learning operation on the encrypted AI model using a dynamic data pattern continuously transmitted between the encrypted AI model and the ADAS after deployment of the AI model; decrypting the AI model and its controllable parameters during the continuous learning operation using a private key stored in a replay protection memory block for decryption; accessing dynamic learning data using the private key for decryption and validating the dynamic learning data by determining an authentication data pattern, the validated dynamic learning data continuously applied to the controllable parameters of the AI model; and continuously monitoring the AI model to ensure the dynamic data pattern is protected and validated prior to application to the continuous learning operation.

2. The method of claim 1 further comprising signature verifying dynamic learning data to be used by the secure AI model during the continuous learning operation.

3. The method of claim 2 further comprising the step of protecting the private key in a secure file system block of memory.

4. The method of claim 1 wherein the data supplied by the verifiable source further comprises lane management and traffic management data and the verifiable source is a legal or government agency.

5. A non-transitory computer readable storage medium comprising instructions which, when executed by a processor, cause the processor to perform steps for detecting and preventing malicious attacks on a lane and traffic management AI model of an advanced driver assistance system (ADAS) of a vehicle, the steps comprising: receiving training data; identifying from the training data a predetermined data type supplied by a verifiable source; performing a signature verification on the predetermined data type supplied by the verifiable source using a private key associated with the verifiable source; preparing an artificial intelligence (AI) model by training the AI model using only the signature verified data; encrypting the AI model and its controllable parameters prior to deployment of the AI model to protect the AI model; deploying the encrypted AI model; performing a continuous learning operation on the encrypted AI model using a dynamic data pattern continuously transmitted between the encrypted AI model and the ADAS after deployment of the AI model; decrypting the AI model and its controllable parameters during the continuous learning operation using a private key stored in a replay protection memory block for decryption; ​ accessing dynamic learning data using a private key for decryption and validating the dynamic learning data by determining an authenticated data pattern, the validated dynamic learning data being continuously applied to controllable parameters of the AI model; and continuously monitoring the AI model to ensure that the dynamic data pattern is protected and validated before being applied to the continuous learning operation.

6. The computer readable storage medium of claim 5, wherein protecting the AI model includes encrypting controllable parameters using a public key maintained by the verifiable source.

7. The computer readable storage medium of claim 6, wherein deploying the AI model includes using only signed validated dynamic learning data during the continuous learning operation of the AI model.

8. The computer readable storage medium of claim 7, wherein the private key is maintained by an operator of the ADAS and the private key is stored in a secure file system block of memory.

9. The computer readable storage medium of claim 5, wherein the data types supplied by the verifiable source further include predefined lane patterns and traffic signs defined by the verifiable source.

10. The computer readable storage medium of claim 9, wherein the verifiable source is a known legal or government agency.

11. A system for detecting and preventing malicious attacks on an artificial intelligence (AI) model in an advanced driver assistance system (ADAS) of a vehicle, comprising: a memory storing a machine learning (ML) system for an advanced driver assistance system (ADAS) of a vehicle; a secure artificial intelligence (AI) model for lane management and traffic management, the AI being prepared by the ML system using signed validated data supplied by a verifiable source, the signed validated data being validated using a private key associated with the verifiable source; controllable parameters, the controllable parameters being encrypted prior to deployment of the AI model, the controllable parameters being encrypted using a public key maintained by an operator of the ML system; and data other than the data supplied by the verifiable source being blocked from entering the AI model prior to deployment of the AI model, wherein the AI model and its controllable parameters are encrypted prior to deployment of the AI model to protect the AI model; a continuous learning operation on the encrypted AI model using a dynamic data pattern continuously transmitted between the encrypted AI model and the ADAS after deployment of the AI model; decrypting the AI model and its controllable parameters during the continuous learning operation using a private key stored in a replay protection memory block for decryption; accessing dynamic learning data using a private key for decryption and validating the dynamic learning data by determining an authenticated data pattern, the validated dynamic learning data being continuously applied to controllable parameters of the AI model; and continuously monitoring the AI model to ensure that the dynamic data pattern is protected and validated before being applied to the continuous learning operation.

12. The system of claim 11, wherein the data supplied by the verifiable source is lane patterns and traffic data and the verifiable source is a legal or government agency.

13. The system of claim 11, wherein the private key is maintained by an operator of the ML system.

14. The system of claim 13, wherein, after decrypting the controllable parameters, signed validation dynamic learning data is applied to the deployed AI model for continuous learning operations of the ML system.

Citation Information

Patent Citations

  • Black Box Data Recorder with Artificial Intelligence Processor in Autonomous Driving Vehicle

    US20190302766A1

  • Methodologies, systems, and components for incremental and continual learning for scalable improvement of autonomous systems

    WO2019232335A1