A system and method for identifying and isolating attack channels in vehicle control

By combining switching and adaptive strategies, and utilizing RBF neural networks and adaptive backstepping methods to identify and isolate attack channels, the problem of attack identification and isolation in vehicle control systems is solved, thereby improving vehicle safety and control stability.

CN116318780BActive Publication Date: 2025-11-14ZHEJIANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211534000.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-01
Publication Date
2025-11-14
Estimated Expiration
2042-12-01

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively identify and isolate attack channels in vehicle control systems, especially when attack patterns change frequently. Switching and adaptive methods are ineffective in preventing attacks from impacting the system.

Method used

Combining switch-based and adaptive attack tolerance control strategies, a radial basis function (RBF) neural network is used for attack estimation and detection. An adaptive backstepping method is used to design a controller to monitor weight changes in real time, identify and isolate attack channels.

Benefits of technology

It enables timely adaptive adjustments when a vehicle is attacked, cutting off attack channels, preventing further attacks, and improving vehicle safety and control stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116318780B_ABST
    Figure CN116318780B_ABST
Patent Text Reader

Abstract

This invention discloses a system and method for identifying and isolating attack channels in vehicle control. Vehicles under remote control may be susceptible to attacks, potentially leading to accidents. This invention uses an adaptive method and a switching control strategy in tandem to mitigate the impact of attacks. First, for the attacked vehicle system, an adaptive method is used to adapt to the injected attack. Second, after adaptation, an identification algorithm is used to identify the attacked channel. Finally, the attacked channel is cut off, and the control algorithm is switched. This invention can make timely adaptive adjustments when the vehicle is attacked and can promptly cut off the attack injection channel after adaptation, preventing attackers from injecting more severe attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to an attack identification system and method in vehicle control, and more particularly to a method for identifying and isolating attack channels in vehicle control. Background Technology

[0002] Connected electric vehicles are a new generation of automobiles equipped with advanced onboard sensors, controllers, actuators, and other devices, integrating modern communication and network technologies to possess complex environmental perception, intelligent decision-making, collaborative control, and execution functions. However, while technologies such as vehicle networking have improved the intelligence and convenience of automobiles, they have also brought serious security challenges. Due to the increase in onboard sensors, controllers, and actuators, and the existence of issues such as insufficient security of communication protocols and incomplete encryption coverage at the network level, security risks such as remote attacks, malicious control, and the theft of user privacy data can endanger the safety of vehicles, roads, the environment, and even the lives and property of people and national security.

[0003] For vehicle safety control, methods to address common attacks can be broadly categorized into two types: switching-based methods and adaptive methods. Switching-based methods aim to cut off the attacked channel or delete all attacked data received by the estimator, thereby eliminating the attack's impact. However, they are ineffective until the attack is correctly detected. Adaptive methods, on the other hand, aim to reduce rather than eliminate the attack's impact. However, when attack patterns change frequently, they can still significantly affect the system because the controller needs to constantly re-estimate the attack in such cases. Summary of the Invention

[0004] To address the problems in the background art, this invention provides a system and method for identifying and isolating attack channels in vehicle control. This invention combines switch-based and adaptive attack tolerance control strategies, proposing an attack channel identification and isolation mechanism based on an adaptive backstepping method. This mechanism can make timely adaptive adjustments when the vehicle is attacked, and can promptly cut off the attack injection channel after the adaptation is completed, preventing attackers from injecting more severe attacks and improving the security of remote vehicle control.

[0005] The technical solution adopted in this invention is as follows:

[0006] I. A system for identifying and isolating attack channels in vehicle control

[0007] The system includes a vehicle actuator, a vehicle sensor, an attack estimator, an attack detector, an attack identifier, a first communication network, a controller, and a second communication network. The attack estimator, attack detector, attack identifier, vehicle actuator, and vehicle sensor are all deployed in the controlled vehicle. The controller transmits signals to the vehicle actuator through the second communication network. The vehicle sensor is connected to the attack estimator, and the attack estimator is connected to the attack detector. The vehicle sensor and the attack estimator also transmit signals to the controller through the first communication network. The attack detector is connected to the vehicle actuator through the attack identifier.

[0008] The attack estimator includes a radial basis function neural network. The vehicle sensor sends a vehicle state signal to the attack estimator. After the vehicle state signal is input into the radial basis function neural network, it predicts and outputs an attack estimate. The attack estimate is sent to the controller through a first communication network. The weights of the radial basis function neural network are sent to the attack detector in real time.

[0009] The attack detector determines whether an attack has occurred and whether the attack has been estimated based on the weights of the radial basis neural network sent by the attack estimator.

[0010] In the attack detector, if the change in the weights of the radial basis function network exceeds a preset weight threshold, it is determined that an attack has occurred in the second communication network; otherwise, no attack has occurred. After determining that an attack has occurred, if the change in the weights of the radial basis function network is less than the preset weight threshold, it is determined that the attack estimation is complete, and then an attack completion instruction and the weights of the radial basis function network at the time of estimation completion are sent to the attack identifier.

[0011] The attack identifier calculates the value of each channel if it is not under attack based on the weights of the radial basis neural network when the estimation is completed and the data received by the vehicle actuator. It then subtracts the value if it is not under attack from the actual received value. If the difference of a certain channel is greater than a preset attack threshold, it is determined that the channel is under attack, and the corresponding channel of the vehicle actuator is shut down; otherwise, it is not under attack.

[0012] II. A method for identifying and isolating attack channels in vehicle control

[0013] Step 1: The controller transmits signals to the vehicle actuators through the second communication network. After the vehicle sensors collect the vehicle status, they send the vehicle status signals to the controller and the attack estimator.

[0014] Step 2: The attack estimator inputs the vehicle state signal into the radial basis neural network and then predicts and outputs the attack estimate. The attack estimate is then sent to the controller through the first communication network, and the weights of the radial basis neural network are sent to the attack detector in real time.

[0015] Step 3: Based on the weights of the radial basis neural network sent by the attack estimator, the attack detector determines whether an attack has occurred and whether the attack has been completed.

[0016] Step 4: Based on the weights of the radial basis function neural network at the time of estimation completion and the data received by the vehicle actuator, the attack detector determines the attacked channel in the vehicle actuator. If an attacked channel exists, the channel is closed.

[0017] Step 5: Based on the vehicle status signal and the attack estimate, the controller uses an adaptive control algorithm to estimate the attack and adjust the control strategy to achieve attack isolation.

[0018] In step 3, if the weight change of the radial basis function network exceeds the preset weight threshold, it is determined that an attack has occurred in the second communication network; otherwise, no attack has occurred. After determining that an attack has occurred, if the weight change of the radial basis function network is less than the preset weight threshold, it is determined that the attack estimation is complete, and then the attack completion instruction and the weight of the radial basis function network at the time of estimation completion are sent to the attack identifier.

[0019] In step 4, the values ​​of each channel if it is not attacked are calculated based on the weights of the radial basis neural network when the estimation is completed and the data received by the vehicle actuator. The difference between the value if it is not attacked and the actual received value is calculated. If the difference of a certain channel is greater than the preset attack threshold, it is determined that the channel is attacked, and the corresponding channel of the vehicle actuator is closed; otherwise, if it is not attacked, no action is taken.

[0020] The beneficial effects of this invention are:

[0021] This invention can make timely adaptive adjustments when a vehicle is attacked, and can cut off the attack injection channel in time after the adaptation is completed, preventing attackers from injecting more violent attacks and ensuring the safety of the vehicle before and after the attack channel is identified.

[0022] This invention is applicable to a variety of attacks, rather than being limited to a specific type of attack. Attached Figure Description

[0023] Figure 1 This is a system overall block diagram of the present invention.

[0024] Figure 2 This is a simulation diagram of the attack the vehicle suffered and the output of the estimator.

[0025] Figure 3 This is a simulation diagram of the attack detector's detection effect.

[0026] Figure 4 This is a simulation diagram of the channel switch status.

[0027] Figure 5 This is a simulation diagram of the lateral position tracking results.

[0028] Figure 6 This is a simulation diagram of the yaw angle.

[0029] In the diagram: Vehicle actuator 1, controlled vehicle 2, attack estimator 3, attack detector 4, attack identifier 5, first communication network 6, controller 7, second communication network 8. Detailed Implementation

[0030] The following is a further explanation with reference to the accompanying drawings.

[0031] like Figure 1 As shown, the system includes a vehicle actuator 1, a vehicle sensor, an attack estimator 3, an attack detector 4, an attack identifier 5, a first communication network 6, a controller 7, and a second communication network 8. The attack estimator 3, attack detector 4, attack identifier 5, vehicle actuator 1, and vehicle sensor are all deployed in the controlled vehicle 2. The controller is a physical entity deployed remotely. The controller 7 transmits signals to the vehicle actuator 1 through the second communication network 8. The vehicle attack occurs in the second communication network 8. The vehicle sensor is connected to the attack estimator 3, and the attack estimator 3 is connected to the attack detector 4. The vehicle sensor and the attack estimator 3 also transmit signals to the controller 7 through the first communication network 6. The attack detector 4 is connected to the vehicle actuator 1 through the attack identifier 5.

[0032] The attack estimator 3 includes a radial basis function neural network. The vehicle sensor sends a vehicle state signal to the attack estimator 3. After the vehicle state signal is input into the radial basis function neural network, it predicts and outputs an attack estimate. The attack estimate is sent to the controller 7 through the first communication network 6. The weights of the radial basis function neural network are sent to the attack detector 4 in real time.

[0033] The attack detector 4 determines whether an attack has occurred and estimates whether the attack has been completed based on the weights of the radial basis neural network sent by the attack estimator 3.

[0034] Specifically, if the weight change of the radial basis function network exceeds the preset weight threshold, it is determined that an attack has occurred in the second communication network 8; otherwise, no attack has occurred. After determining that an attack has occurred, if the weight change of the radial basis function network is less than the preset weight threshold, it is determined that the attack estimation is complete, and then the attack completion instruction and the weight of the radial basis function network at the time of estimation completion are sent to the attack identifier 5.

[0035] There are multiple transmission channels between the controller and the actuator, and the actuator can be set to open or close a single transmission channel. Based on the weights of the radial basis function neural network at the time of estimation completion and the data received by the vehicle actuator 1, the attack detector 5 identifies the attacked channels in the vehicle actuator 1. If an attacked channel exists, it closes that channel.

[0036] Specifically, based on the weights of the radial basis function neural network at the time of estimation completion and the data received by the vehicle actuator 1, the values ​​of each channel if it is not under attack are calculated. The difference between the value if it is not under attack and the actual received value is calculated. If the difference of a certain channel is greater than the preset attack threshold, it is determined that the channel is under attack, and the corresponding channel of the vehicle actuator 1 is shut down. Subsequently, the controller will adjust the control strategy according to the channel shutdown status, so that the controller only outputs control commands to the unshutted channels; otherwise, it is not under attack.

[0037] The controller 7 includes an adaptive control algorithm for adaptively estimating the attacks injected into the second communication network 8 and compensating for the estimated attack values ​​to ensure control performance.

[0038] The method includes the following steps:

[0039] Step 1: The controller 7 transmits signals to the vehicle actuator 1 through the second communication network 8. After the vehicle sensor collects the vehicle status, it sends the vehicle status signal to the controller 7 and the attack estimator 3.

[0040] Step 2: After inputting the vehicle state signal into the radial basis neural network, the attack estimator 3 predicts and outputs the attack estimate, and sends the attack estimate to the controller 7 through the first communication network 6. The weights of the radial basis neural network are sent to the attack detector 4 in real time.

[0041] Step 3: Based on the weights of the radial basis neural network sent by the attack estimator 3, the attack detector 4 determines whether an attack has occurred and whether the attack has been completed.

[0042] Specifically, if the weight change of the radial basis function network exceeds the preset weight threshold, it is determined that an attack has occurred in the second communication network 8; otherwise, no attack has occurred. After determining that an attack has occurred, if the weight change of the radial basis function network is less than the preset weight threshold, it is determined that the attack estimation is complete, and then the attack completion instruction and the weight of the radial basis function network at the time of estimation completion are sent to the attack identifier 5.

[0043] Step 4: Based on the weights of the radial basis function neural network at the time of estimation completion and the data received by the vehicle actuator 1, the attack detector 5 determines the attacked channel in the vehicle actuator 1. If an attacked channel exists, the channel is closed.

[0044] Specifically, based on the weights of the radial basis function neural network at the time of estimation completion and the data received by the vehicle actuator 1, the values ​​of each channel if it is not under attack are calculated. The difference between the value if it is not under attack and the actual received value is calculated. If the difference of a certain channel is greater than the preset attack threshold, it is determined that the channel is under attack, and the corresponding channel of the vehicle actuator 1 is closed; otherwise, if it is not under attack, no action is taken.

[0045] Step 5: Based on the vehicle status signal and the attack estimate, the controller 7 uses an adaptive control algorithm to estimate the attack and adjust the control strategy. Specifically, the control strategy is adjusted according to the channel closure status, so that the controller only outputs control commands to the unclosed channels, thereby isolating the attack.

[0046] The adaptive control algorithm for the vehicle is designed as follows.

[0047] Considering the lateral dynamics model of the vehicle,

[0048]

[0049] Where y represents the lateral position of the vehicle. The first derivative representing the lateral position. The second derivative represents the horizontal position. The first derivative represents the yaw angle. Let ψ represent the second derivative of the yaw angle, where ψ is the vehicle's yaw angle. For lateral control of the vehicle, the longitudinal velocity remains constant, denoted as V. x M is the mass of the car, I z Let C be the moment of inertia about the z-axis. f and C r These are the tire cornering stiffnesses for the front and rear wheels of the vehicle, respectively. L f and L r These represent the distances from the front and rear wheels to the vehicle's center of gravity, respectively. δ represents the steering wheel angle, which is the control input.

[0050] The value of δ can be designed to be input from m channels, thus the control input part can be modeled as follows:

[0051]

[0052] Among them, b j This represents the state of channel j, where j = 1, 2, ..., m, and is used to indicate whether channel j is open or closed. (b j =1 indicates the channel is open, b j =0 indicates the channel is closed. η j Given the channel coefficients, it can be derived from... It was allocated. Control signals that may be attacked.

[0053]

[0054] Among them, u j It is a pure control signal generated by the controller, d j A value of 1 or 0 indicates whether channel j is attackable (d j =1 indicates that it can be attacked). f j It is fake data injected by an unknown entity.

[0055] This invention uses an RBF neural network to estimate attacks. Specifically, the RBF neural network used in this invention has three layers: an input layer, a hidden layer, and an output layer. The activation functions of the input and output layers are linear functions. The activation function of the hidden layer is a radial basis function. The formulas for the neurons in the network are as follows:

[0056]

[0057] Where, φ i The output of the i-th neuron is the system state x (i.e., the vehicle state signal), which is the input feature vector satisfying x = [x1, x2, ..., x]. m ], c i σ is the center vector of the width between two neurons. i It is a constant that can adjust the amplitude of neurons, where n is the number of neurons.

[0058] The weights between the input layer and the hidden layer are both fixed at 1, while the weights between the hidden layer and the output layer are... This represents the weights of the second neuron in the hidden layer and the output layer, with T denoteing the transpose operation. The output h(x) of the neural network can be used as an approximation, i.e.

[0059]

[0060] in, It is an ideal weight vector, Φ(x)=[φ1,φ2,...,φ n ] T ε is the output vector of RBF, and ε is the approximation error.

[0061] In practice, Unknown. Therefore, the weights obtained during training are used. Actual output of RBF It becomes:

[0062]

[0063] To estimate the attack, the RBF neural network is deployed in each input channel.

[0064] The control objective is to make the output of the attacked system track the time-varying target y. r To achieve the control objective, the yaw angle and yaw rate are variables related to the input, and it is assumed that they are both known. A backstepping method and adaptive control algorithm using Lyapunov functions are employed. Design a controller for each channel, where This is the difference between the actual weight vector and the estimated weight vector. To estimate the weight vector, Let z1 be the actual weight vector, assumed to be constant, and z2 be the first error and z1 be the second error. This vector can be obtained from the following formula:

[0065] z1=yy r

[0066]

[0067] The designed controller process is as follows: Taking the derivative of the Lyapunov function, we can obtain:

[0068]

[0069] In order to make For semi-negative constant, the controller is designed as follows:

[0070]

[0071] Among them, u j (t) represents the pure control signal generated by the controller at time t. This represents the neural network weights on channel j.

[0072]

[0073] Wherein, α is the main body of the backstepping controller. For time-varying target y r The first derivative, For time-varying target y r The second derivative of , c1 is the first coefficient of the controller, which is a designable positive constant, and c2 is the second coefficient of the controller, which is also a designable positive constant.

[0074] The RBF weight update rate is:

[0075]

[0076] Where Υ is the adaptive rate, η is the channel coefficient vector, and I Φ(x) The basis matrices for the RBF neural network are defined as follows:

[0077]

[0078]

[0079] The attack detector is designed as follows.

[0080] The basic mechanism of attack detectors is to monitor changes in the weights of the RBF neural network. Intuitively, if the input channel is not under attack, or if the RBF network has already estimated the attack, the network weights will change very little. However, they will change significantly between the occurrence of the attack and the completion of the estimation. Therefore, these two crucial time points can be detected by monitoring the weights of the RBF neural network.

[0081] To quantify the changes in weights, the following mechanism is used. First, the historical weights are input into a queue of length N (single-input, single-output buffer), i.e.:

[0082]

[0083] Where Θ is the buffer vector, Let represent the norm of the weights at time k. k is the superscript of the latest weights. The mean of Θ, E(Θ), and the variance of Θ, σ(Θ), can be obtained as follows:

[0084]

[0085] The attack detector is designed as follows:

[0086] normal

[0087] abnormal

[0088] in, h represents the difference between the absolute norm of the mean and the new weights. J The threshold is "normal", which means there is no attack or the RBF neural network has estimated the attack, and "abnormal" means there is an attack, but the estimation has not been completed.

[0089] The identifier is designed as follows.

[0090] Upon detecting an attack, the exact attacked input channel should be identified. To do this, the attack identifier should wait for the attack detector to release a normal signal, indicating that the estimation process is complete.

[0091] For each channel, the system can only acquire the attacked control signal. The attack detector uses this information and the output of the RBF network to calculate the control signals that are not under attack.

[0092] Assume the system can measure each channel of its input, i.e. For j = 1, 2, ..., m, it is possible to obtain the output of the RBF network if the attack identifier performs the following calculation:

[0093]

[0094] So Where u j This is the unattacked output of the controller.

[0095] The design concept of this recognizer is as follows. From the RBF neural network estimator, we can obtain... at the same time

[0096] So

[0097]

[0098]

[0099] Once the attack assessment is complete, We can obtain:

[0100]

[0101] To calculate the control signals received by the channel when no attack is received.

[0102] Then, the recognizer can be designed as follows:

[0103] No attack received

[0104] Attacked

[0105] Where δ i It is a threshold.

[0106] If the input channel j is attacked, then the corresponding coefficient b j Setting it to 0 means that channel j rejects input signals. It's worth noting that not all channels will be rejected; in this case, control signals cannot be input to the system. In other words, at least one channel is reserved for transmitting control signals.

[0107] The controller control rate has been updated as follows.

[0108] The controller has been updated to:

[0109]

[0110] Once the attacked channel is denied access, the attack will also be denied. A collection of channels that have not been attacked. This represents the number of channels that have not been attacked.

[0111] Weights of an RBF neural network It should be reset. The updated attack estimator is as follows:

[0112]

[0113] in, and These are the adaptive coefficients and channel coefficients for the unattacked channel.

[0114] Simulation results:

[0115] Assuming the attack is

[0116] f = 3ε(t-10) + 2ε(t-22).

[0117] Where ε(·) is the step function. In the simulation, the first and third channels of the vehicle system are attacked. Figure 2 The output of the successfully injected attack and the estimator shows that the estimator estimates the attack promptly after it occurs, and the injected attack becomes 0 when the attack estimation is roughly completed, indicating that the estimation, removal, and identification of the attack are all achieved. Figure 3 For attack identification results, when the first attack occurs 10 seconds later, the change in weights exceeds its upper limit, meaning the attack detector correctly detected the attack. A short time later, when the attack is successfully estimated, the change in weights returns to its boundary. This means the attack detector detected the point in time when the estimation was completed. Figure 4 The switch status of the actuator channel shows that the attacked input channel was correctly and promptly rejected. Figure 5 This is the result of lateral tracking. The proposed algorithm can achieve lateral tracking both before and after the attack is cut off. Figure 6 It is the yaw angle, which means that the control commands can ensure that the yaw angle is bounded.

Claims

1. A system for identifying and isolating attack channels in vehicle control, characterized in that, The system includes a vehicle actuator (1), a vehicle sensor, an attack estimator (3), an attack detector (4), an attack identifier (5), a first communication network (6), a controller (7), and a second communication network (8). The attack estimator (3), the attack detector (4), the attack identifier (5), the vehicle actuator (1), and the vehicle sensor are all deployed in the controlled vehicle (2). The controller (7) transmits signals to the vehicle actuator (1) through the second communication network (8). The vehicle sensor is connected to the attack estimator (3), and the attack estimator (3) is connected to the attack detector (4). The vehicle sensor and the attack estimator (3) also transmit signals to the controller (7) through the first communication network (6). The attack detector (4) is connected to the vehicle actuator (1) through the attack identifier (5). The attack estimator (3) includes a radial basis neural network. The vehicle sensor sends a vehicle state signal to the attack estimator (3). After the vehicle state signal is input into the radial basis neural network, the attack estimate is predicted and output. The attack estimate is sent to the controller (7) through the first communication network (6). The weights of the radial basis neural network are sent to the attack detector (4) in real time. The attack detector (4) determines whether an attack has occurred and estimates whether the attack has been completed based on the weights of the radial basis neural network sent by the attack estimator (3). In the attack detector (4), if the change in weight of the radial basis neural network exceeds the preset weight threshold, it is determined that an attack has occurred in the second communication network (8); otherwise, no attack has occurred. After determining that an attack has occurred, if the change in weight of the radial basis neural network is less than the preset weight threshold, it is determined that the attack estimation is completed, and then the attack completion instruction and the weight of the radial basis neural network when the estimation is completed are sent to the attack identifier (5). The attack identifier (5) calculates the value of each channel if it is not attacked based on the weights of the radial basis neural network when the estimation is completed and the data received by the vehicle actuator (1). It then subtracts the value if it is not attacked from the actual received value. If the difference of a certain channel is greater than the preset attack threshold, it is determined that the channel is attacked and the corresponding channel of the vehicle actuator (1) is closed; otherwise, it is not attacked.

2. A method for identifying and isolating attack channels in vehicle control, used to implement the system for identifying and isolating attack channels in vehicle control as described in claim 1, characterized in that, Includes the following steps: Step 1: The controller (7) transmits signals to the vehicle actuator (1) through the second communication network (8). After the vehicle sensor collects the vehicle status, it sends the vehicle status signal to the controller (7) and the attack estimator (3). Step 2: The attack estimator (3) inputs the vehicle state signal into the radial basis neural network and predicts the output attack estimate. The attack estimate is sent to the controller (7) through the first communication network (6). The weights of the radial basis neural network are sent to the attack detector (4) in real time. Step 3: Based on the weights of the radial basis neural network sent by the attack estimator (3), the attack detector (4) determines whether an attack has occurred and whether the attack has been completed; Step 4: Based on the weights of the radial basis neural network at the time of estimation completion and the data received by the vehicle actuator (1), the attack detector (5) determines the attacked channel in the vehicle actuator (1). If there is an attacked channel, the channel is closed. Step 5: Based on the vehicle status signal and the attack estimate, the controller (7) uses an adaptive control algorithm to estimate the attack and adjust the control strategy to achieve attack isolation.

Citation Information

Patent Citations

  • Method for controlling reliability of active suspension when network between controller and actuator is under DoS (denial-of-service) attack

    CN109795277A

  • Online monitoring method and system for braking abnormity / attack of automatic driving automobile

    CN112622862A