Vehicle Network Intrusion Detection Method Based on Parallel Analysis of Spatiotemporal Features
By adopting a spatial and temporal feature extraction method with parallel analysis in vehicle intrusion detection and using self-attention mechanism for feature fusion, the problems of high false alarm rate and unreasonable spatial and temporal feature extraction methods in the existing technology are solved, and more efficient vehicle intrusion detection performance is achieved.
Patent Information
- Application Number
- CN202310489303.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-28
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2043-04-28
AI Technical Summary
The existing Internet of Vehicle Intrusion Detection methods have high problems in terms of false alarm rates, and the spatial and temporal feature extraction methods are usually connected in series, ignoring the differences and advantages between temporal and spatial features.
The method based on spatial and temporal features is adopted to extract the spatial and temporal features of the Internet of Vehicles in parallel through the spatial feature extraction module and the time domain feature extraction module, and the self-attention mechanism is used to fusion of features to improve the characterization ability of Internet of Vehicles in traffic data.
It improves the performance of Internet of Vehicles intrusion detection, reduces the false alarm rate, and improves the characterization ability of Internet of Vehicles traffic data, and enhances the accuracy and reliability of detection.
Smart Images

Figure CN116506858B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of vehicle networking, and more specifically, relates to a vehicle networking intrusion detection method based on parallel analysis of spatio-temporal characteristics. Background Art
[0002] In recent years, with the development of Internet of Things and artificial intelligence technologies, the level of vehicle intelligence and networking has been gradually increasing. Vehicle networking is becoming the focus of attention in academia and industry. By making all-round network connections with the outside world, vehicles can further improve their intelligence level, thus providing users with diversified services. How to protect the security of vehicle networking from being invaded by network attackers has always been a key issue that urgently needs to be solved. Once a vehicle is invaded, catastrophic consequences will occur. At the same time, the number of vehicles accessing vehicle networking has increased sharply, and the network environment has become increasingly complex, posing a great challenge to the security of vehicle networking. As a network security technology, intrusion detection collects key information in the network system, processes and analyzes this information, and thus detects attack behaviors in the network system. Therefore, vehicle networking intrusion detection methods have very important research and application values.
[0003] Currently, deep learning is the main implementation method for vehicle networking intrusion detection. By mining intrusion sample data through deep learning, implicit features in the data can be obtained, thereby detecting network intrusion data. However, a high false alarm rate has always been the main problem faced by vehicle networking intrusion detection schemes based on deep learning, because these schemes do not extract data features in vehicle networking sufficiently. Although some researchers have proposed to improve intrusion detection performance and reduce the false alarm rate by extracting spatio-temporal features in vehicle networking data, these schemes usually only connect two models in series, ignoring the differences and respective advantages between time features and space features. At the same time, the features extracted by the previous model will affect the latter model. When there are limitations in the previous model, the intrusion detection performance of the entire model will be affected. Summary of the Invention
[0004] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a vehicle networking intrusion detection method based on parallel analysis of spatio-temporal characteristics, which parallelly extracts spatial features and time domain features from vehicle networking traffic data and fuses them based on the self-attention mechanism to obtain spatio-temporal features, improves the representation ability of vehicle networking traffic data, and further improves the vehicle networking intrusion detection performance.
[0005] To achieve the above invention purpose, the vehicle networking intrusion detection method based on parallel analysis of spatio-temporal characteristics of the present invention includes the following steps:
[0006] S1: For the vehicle networking that needs to be intrusion - detected, collect a number of vehicle networking traffic data sequences respectively when it is in the normal operation state and when an intrusion occurs. Each vehicle networking traffic data sequence contains N consecutive vehicle networking traffic data, and each vehicle networking traffic data contains M data features, where the value of M is determined according to actual needs. For each vehicle networking traffic data, perform pre - processing to obtain the initial feature vector of the vehicle networking traffic data. The pre - processing method is: encode the character data features into numerical features and standardize the numerical data features;
[0007] S2: According to the vehicle networking state when each vehicle networking traffic data sequence is collected, label the vehicle networking traffic data sequence with a class label. If the vehicle networking is in the normal operation state during collection, let the class label be 1. If an intrusion occurs in the vehicle networking during collection, let the class label be 0;
[0008] S3: Screen the data features based on the collected vehicle networking traffic data to obtain K effective data features, and then reduce the dimension of each initial feature vector of the vehicle networking traffic data according to the effective data features to obtain the feature vector of the vehicle networking traffic data. Then, for each vehicle networking traffic data sequence, use its N vehicle networking traffic data feature vectors as row vectors to form a vehicle networking traffic data feature matrix of size N×K;
[0009] S4: Build a vehicle networking intrusion detection model, including a spatial feature extraction module, a time - domain feature extraction module, a feature splicing module, a self - attention module, a feature fusion module, and a multi - layer perceptron. Among them:
[0010] The spatial feature extraction module is used to extract spatial feature vectors with dimension B for each vehicle networking traffic data feature vector in the input vehicle networking traffic data feature matrix. The value of B is determined according to actual needs, and then form a spatial feature F of size N×B with N spatial feature vectors spatial and send it to the feature splicing module and the feature fusion module;
[0011] The time - domain feature extraction module is used to extract a time - domain feature F of size N×B from the input vehicle networking traffic data feature matrix temporal and send it to the feature splicing module and the feature fusion module;
[0012] The feature splicing module is used to splice the spatial feature F spatial and the time - domain feature F temporal to obtain a spatio - temporal feature F of size N×2B and send it to the self - attention module;
[0013] The self - attention module is used to generate a self - attention score matrix H of size N×2B corresponding to the spatio - temporal feature F according to the self - attention mechanism and send it to the feature fusion module;
[0014] The feature fusion module is used to fuse the spatial feature F according to the self-attention score matrix H spatial and the temporal feature F temporal to obtain the fused feature F fusion and send it to the multi-layer perceptron. The specific method is as follows:
[0015] Divide the self-attention score matrix H according to the splicing method of the feature splicing module, and take the first B columns as the weight matrix λ spatial of the spatial feature F spatial , and take the last B columns as the weight matrix λ temporal of the temporal feature F temporal , and then calculate the fused feature F using the following formula fusion :
[0016] F fusion =λ spatial *F spatial +λ temporal *F temporal
[0017] where * represents the Hadamard product;
[0018] The multi-layer perceptron is used to predict whether an intrusion occurs in the vehicle network when collecting the input vehicle network traffic data feature matrix according to the fused feature F fusion to obtain the intrusion detection result;
[0019] S5: Use the vehicle network traffic data feature matrix corresponding to each vehicle network traffic data sequence as the input, and the corresponding class label as the expected output to train the vehicle network intrusion detection model constructed in step S4 to obtain a trained vehicle network intrusion detection model;
[0020] S6: When it is necessary to perform intrusion detection on the vehicle network, collect a vehicle network traffic data sequence containing N consecutive vehicle network traffic data. Each vehicle network traffic data contains K valid data features. Process each vehicle network traffic data according to the preprocessing method in step S1 to obtain the corresponding vehicle network traffic data feature vector. Then, use the N vehicle network traffic data feature vectors as row vectors to form a vehicle network traffic data feature matrix of size N×K. Input this vehicle network traffic data feature matrix into the trained vehicle network intrusion detection model in step S5 to obtain the vehicle network intrusion detection result.
[0021] The vehicle network intrusion detection method based on parallel analysis of spatio-temporal features in the present invention collects a number of vehicle network traffic data sequences respectively when the vehicle network is operating normally and when an intrusion occurs. Each vehicle network traffic data sequence contains continuous vehicle network traffic data. The vehicle network traffic data feature matrix is obtained through data feature screening, and the vehicle network traffic data samples are obtained through label annotation. A vehicle network intrusion detection model including a spatial feature extraction module, a time-domain feature extraction module, a feature splicing module, a self-attention module, a feature fusion module and a multi-layer perceptron is constructed. The vehicle network intrusion detection model is trained with the vehicle network traffic data samples. When it is necessary to perform intrusion detection on the vehicle network, data is collected and the vehicle network traffic data feature matrix is obtained, which is input into the trained vehicle network intrusion detection model to obtain the vehicle network intrusion detection result.
[0022] The present invention has the following beneficial effects:
[0023] 1) The present invention proposes a new parallel extraction architecture for spatio-temporal features, which uses a spatial feature extraction module and a time-domain feature extraction module to parallelly extract the spatio-temporal features of vehicle network traffic. The proposed architecture has higher reliability compared with the serial architecture;
[0024] 2) The present invention proposes a spatio-temporal feature fusion method based on the self-attention mechanism, which assigns weights to spatio-temporal features according to the self-attention scores, so as to realize the efficient fusion of different features, improve the representation ability of vehicle network traffic data, and thus effectively improve the performance of vehicle network intrusion detection. Description of the Drawings
[0025] Figure 1 is the flowchart of the specific implementation of the vehicle network intrusion detection method based on parallel analysis of spatio-temporal features in the present invention;
[0026] Figure 2 is the structural diagram of the vehicle network intrusion detection model in the present invention. Specific Embodiments
[0027] The following describes the specific embodiments of the present invention with reference to the drawings, so that those skilled in the art can better understand the present invention. It should be particularly noted that in the following description, when the detailed description of known functions and designs may dilute the main content of the present invention, these descriptions will be omitted here.
[0028] Embodiment
[0029] Figure 1 is the flowchart of the specific implementation of the vehicle network intrusion detection method based on parallel analysis of spatio-temporal features in the present invention. As Figure 1 shown, the specific steps of the vehicle network intrusion detection method based on parallel analysis of spatio-temporal features in the present invention include:
[0030] S101: Collect vehicle networking traffic data:
[0031] For the vehicle networking for which intrusion detection is required, several vehicle networking traffic data sequences are collected respectively when it is in normal operation and when an intrusion occurs. Each vehicle networking traffic data contains N consecutive vehicle networking traffic data, and each vehicle networking traffic data contains M data features, where the value of M is determined according to actual needs. For each vehicle networking traffic data, the character data features are encoded into numerical features, and the numerical data features are standardized, so as to obtain the corresponding initial feature vector of the vehicle networking traffic data.
[0032] In this embodiment, the data features include three types of data features. The first type is the basic safety data feature (BSM), that is, the safety status data exchanged between vehicles, including position, speed, heading, etc.; the second type is the network data feature, which is the key network information generated by vehicle communication, including network protocol type, source address, destination address, timestamp, etc.; the third type is the traffic statistics data feature, that is, the statistical data feature of the data sent by the roadside unit to the vehicle, including the data packet sending rate per unit time, data packet discard rate, etc. In practical applications, the information features included in each type of data can be set according to actual needs.
[0033] In this embodiment, the character data feature encoding adopts label encoding (LabelEncoder) in the sklearn library. The numerical data feature standardization adopts the Min - Max method to remove the influence of dimension.
[0034] S102: Label annotation:
[0035] According to the vehicle networking status when each vehicle networking traffic data sequence is collected, class labels are assigned to the vehicle networking traffic data sequences. If the vehicle networking is in normal operation during collection, the class label is set to 1; if an intrusion occurs in the vehicle networking during collection, the class label is set to 0.
[0036] S103: Data feature screening:
[0037] When performing vehicle networking intrusion detection, it is necessary to extract communication behavior information from the data features of the vehicle networking traffic to train the intrusion detection model. However, due to the complex multi - dimensional characteristics of the data in the vehicle networking, directly using these data for model training consumes excessive computing resources, and redundant features are also likely to cause model overfitting.
[0038] Therefore, according to the collected vehicle networking traffic data, the present invention screens data features to obtain K effective data features, and then reduces the dimension of each initial feature vector of the vehicle networking traffic data according to the effective data features to obtain a vehicle networking traffic data feature vector. Then, for each vehicle networking traffic data sequence, its N vehicle networking traffic data feature vectors are used as row vectors to form a vehicle networking traffic data feature matrix of size N×K.
[0039] In this embodiment, data feature screening is performed based on correlation to select data features applicable to vehicle networking intrusion detection, and a recursive elimination method is used to obtain an optimal data feature set. In this way, the selected data features can be made more reasonable to ensure the performance of vehicle networking intrusion detection. The specific method is as follows:
[0040] 1) Denote the number of vehicle networking traffic data sequences collected in step S101 as D, then the number G of initial feature vectors of the vehicle networking traffic data is G = D×N. Denote the g-th initial feature vector of the vehicle networking traffic data as with the corresponding class label y g , and calculate the correlation cor between each data feature and the class label using the following formula m :
[0041]
[0042] where σ m represents the standard deviation of the corresponding values of the m-th data feature in G initial feature vectors of the vehicle networking traffic data, σ y represents the standard deviation of G class labels, and cov m represents the Pearson correlation coefficient between the m-th data feature and the class label. The calculation formula is as follows:
[0043]
[0044] where μ m represents the average value of the corresponding values of the m-th data feature in G initial feature vectors of the vehicle networking traffic data, and μ y represents the average value of G class labels.
[0045] 2) Initialize r = 1 and initialize the data feature set as the set of all data features.
[0046] 3) Let the input be the feature vectors extracted from the initial feature vectors of the vehicle networking traffic data that contain the data features in the current data feature set, and the expected output be the corresponding class labels. Train a preset classifier and count the classification accuracy of the trained classifier. The classifier here can select a classifier with a relatively simple structure. For example, a multi-layer perceptron is used in this embodiment.
[0047] 4) Determine whether r < R, where R represents a preset threshold. If yes, go to step 5); otherwise, go to step 6).
[0048] 5) Screen out and delete the data feature with the lowest relevance to the class label from the current data feature set, then set r = r + 1, and return to step 3).
[0049] 6) Screen out the classifier with the highest classification accuracy from the R trained classifiers, and use the data features in its corresponding data feature set as valid data features.
[0050] S104: Construct a vehicle networking intrusion detection model:
[0051] To achieve vehicle networking intrusion detection, the present invention proposes a vehicle networking intrusion detection model based on parallel analysis of spatio-temporal features. Figure 2 It is the structural diagram of the vehicle networking intrusion detection model in the present invention. As Figure 2 shown, the vehicle networking intrusion detection model in the present invention includes a spatial feature extraction module, a time-domain feature extraction module, a feature splicing module, a self-attention module, a feature fusion module, and a multi-layer perceptron (MLP). Next, the multiple modules will be described in detail.
[0052] The spatial feature extraction module is used to extract spatial feature vectors with a dimension of B from each vehicle networking traffic data feature vector in the input vehicle networking traffic data feature matrix. The value of B is determined according to actual needs, and then N spatial feature vectors are used to form a spatial feature F of size N×B spatial and send it to the feature splicing module and the feature fusion module.
[0053] The spatial feature extraction module usually adopts a CNN (Convolutional Neural Network) model. As an improved structure of the CNN model, the TCN (Temporal Convolutional Network) network can process sequential data by adding causal convolutions. The proposed dilated convolution and residual module endow it with the ability to remember historical information. Compared with the traditional CNN that needs to process network traffic data into two-dimensional images for spatial feature extraction, the TCN can directly extract spatial features from one-dimensional data, with advantages such as less required computing resources and stable gradients. Therefore, in this embodiment, the spatial feature extraction module adopts a TCN network, which includes a causal convolution layer, a dilated convolution layer, and a residual connection layer, to extract the spatial feature vector of the vehicle network traffic data feature matrix. Since the TCN has a flexible receptive field and stable gradients compared with the traditional CNN, it can enhance the feature extraction ability, so that the extracted features can train an intrusion detection model with higher performance.
[0054] The temporal feature extraction module is used to extract the temporal feature F of size N×B from the input vehicle network traffic data feature matrix temporal and send it to the feature concatenation module and the feature fusion module.
[0055] Recurrent Neural Networks (RNNs) are usually used for temporal feature extraction. As an improved type of RNN, LSTM can solve the problem of long-term dependence in long sequence training. Therefore, in this embodiment, the temporal feature extraction module adopts an LSTM (Long Short Term Memory) network. The LSTM network consists of individual units, and each unit mainly includes three parts: a forget gate, an input gate, and an output gate, which control the state of the LSTM unit through these three gates. When the vehicle network traffic data feature matrix is input into the LSTM model, it can control the transmission state of the data according to the internal gates, realize long-term memory, and forget unimportant information. Through the LSTM model, the temporal features of sequential data can be effectively extracted, thus constructing an intrusion detection model with higher detection performance.
[0056] The feature concatenation module is used to concatenate the spatial feature F spatial and the temporal feature F temporal to obtain the spatio-temporal feature F of size N×2B and send it to the self-attention module.
[0057] The self-attention module is used to generate a self-attention score matrix H of size N×2B corresponding to the spatio-temporal feature F according to the self-attention mechanism and send it to the feature fusion module. The self-attention mechanism is a commonly used machine learning method, and its principle and specific process will not be elaborated here.
[0058] The feature fusion module is used to fuse the spatial feature F spatial and the temporal feature F temporal to obtain a fused feature F fusion and send it to the multi-layer perceptron. The specific method is as follows:
[0059] Divide the self-attention score matrix H according to the splicing method of the feature splicing module, and take the first B columns as the weight matrix λ spatial of the spatial feature F spatial , and take the last B columns as the weight matrix λ temporal of the temporal feature F temporal , and then use the following formula to calculate the fused feature F fusion :
[0060] F fusion =λ spatial *F spatial +λ temporal *F temporal
[0061] where * represents the Hadamard product.
[0062] After extracting the spatio-temporal features, if the extracted spatio-temporal features are directly used without processing, many important information will be ignored. Through research, it is found that the spatial features and temporal features have their own focuses, and for different types of network attacks in the vehicle network, the spatio-temporal features need to have different weights. Therefore, the differences between the spatio-temporal features cannot be ignored. In the present invention, the self-attention module assigns differentiated weights to the spatio-temporal features, so as to obtain the fused features, which can more reasonably and effectively represent the vehicle network traffic data, thereby realizing the efficient detection of different types of attacks in the vehicle network.
[0063] The multi-layer perceptron is used to predict the probability of whether there is an intrusion in the vehicle network when collecting the feature matrix of the input vehicle network traffic data according to the fused feature F fusion to obtain the intrusion detection result.
[0064] S105: Train the vehicle network intrusion detection model:
[0065] Take the feature matrix of the vehicle network traffic data corresponding to each vehicle network traffic data sequence as the input, and the corresponding class label as the expected output, and train the vehicle network intrusion detection model constructed in step S104 to obtain the trained vehicle network intrusion detection model.
[0066] In this embodiment, the cross-entropy loss function is adopted as the loss function during the training of the vehicle network intrusion detection model. However, with the fusion of spatio-temporal features, the model will become complex and prone to overfitting. Therefore, in this embodiment, an L2 regularization term is added to the loss function to reduce the degree of overfitting and lower the model complexity. The calculation formula of the loss function L in this embodiment is as follows:
[0067]
[0068] where n represents the number of samples in the current training sample batch (patch), and y ic is the sign function, which takes 1 when the true category of sample i in the current training sample batch is the c-th category, and 0 otherwise. Obviously, in the present invention, the number of categories is 2, namely normal operation and intrusion occurrence. p ic is the predicted probability that sample i belongs to the c-th category output by the multi-layer perceptron, ω is the model parameter, η is the penalty term, and || || represents taking the norm. Through continuous training iteration, the loss function of the model converges, and thus a trained intrusion detection classification model is obtained.
[0069] S106: Vehicle network intrusion detection:
[0070] When it is necessary to perform intrusion detection on the vehicle network, a vehicle network traffic data sequence containing N consecutive vehicle network traffic data is collected. Each vehicle network traffic data contains K valid data features. Each vehicle network traffic data is processed according to the preprocessing method in step S101 to obtain the corresponding vehicle network traffic data feature vector. Then, the N vehicle network traffic data feature vectors are used as row vectors to form a vehicle network traffic data feature matrix with a size of N×K. The vehicle network traffic data feature matrix is input into the vehicle network intrusion detection model trained in step S105 to obtain the vehicle network intrusion detection result.
[0071] To further illustrate the technical effects of the present invention, this embodiment conducts experimental verification on the present invention using a specific example. In this experiment, the UNSW-NB15 dataset is used, which is one of the most commonly used datasets in the field of network intrusion detection. This embodiment selects 4 typical models in the field of intrusion detection, namely the SVM model, the CNN model, the LSTM model, and the FedAGRU model. The intrusion detection methods based on the above models are used as comparison methods, and are compared with the present invention in terms of three evaluation indicators: accuracy (Accuracy), false positive rate (FPR), and F1 value, so as to illustrate the advantages of the present invention. Table 1 is the comparison table of intrusion detection evaluation indicators of the present invention and 4 comparison methods on the UNSW-NB15 dataset.
[0072]
[0073] Table 1
[0074] As can be seen from Table 1, the accuracy rate of the present invention is higher than that of the comparative methods, reaching 96.34%. The highest before was 94.22% of the CNN-BiSRU method. The present invention is 2.12% higher than the highest comparative method, indicating that the present invention has strong correct classification ability. In terms of the false alarm rate index, PA-STF also performs the best, only 1.38%. The false alarm rate of the present invention is reduced by 1.57% compared with the method with the lowest false alarm rate. For the F1 value, the F1 value of the present invention reaches 95.76%, which is increased by 1.52% compared with the method with the highest F1 value.
[0075] From the comparison data, it can be seen that the deep learning-based method can better model the spatio-temporal characteristics of the vehicle network and has stronger comprehensive detection performance. The feature modeling and analysis ability of the traditional machine learning method SVM is weaker than that of the deep learning method. This is because the deep learning method can extract deeper network behavior characteristics and effectively learn the internal laws and representation levels of sample data by constructing a non-linear network structure composed of multiple hidden layers, enabling accurate and efficient classification of normal data and attack data. The comparative method CNN-BiSRU first uses CNN for spatial feature extraction and then extracts temporal features based on CNN, without considering the correlation and difference between spatio-temporal features. The present invention uses two parallel modules for spatio-temporal feature extraction and fusion based on the self-attention mechanism, and has better feature representation ability than the CNN-BiSRU method, so the detection performance is higher.
[0076] In summary, the present invention has a high accuracy rate in vehicle network intrusion detection, can effectively reduce false alarms during the detection process, and has higher usability.
[0077] Although the above describes the illustrative specific embodiments of the present invention for the understanding of those skilled in the art of the present technology, it should be clear that the present invention is not limited to the scope of the specific embodiments. For those of ordinary skill in the art of the present technology, as long as various changes are within the spirit and scope of the present invention defined and determined by the appended claims, these changes are obvious, and all inventions and creations using the concept of the present invention are within the scope of protection.
Claims
1. A vehicle networking intrusion detection method based on parallel analysis of spatio-temporal features, characterized in that, it includes the following steps: S1: For the vehicle networking to be detected for intrusion, collect a number of vehicle networking traffic data sequences respectively when it is in normal operation state and when an intrusion occurs. Each vehicle networking traffic data sequence contains N consecutive vehicle networking traffic data, and each vehicle networking traffic data contains M data features, and the value of M is determined according to actual needs; perform preprocessing on each vehicle networking traffic data to obtain an initial feature vector of the vehicle networking traffic data. The preprocessing method is: encode the character data features into numerical features, and standardize the numerical data features; S2: Label the class label of the vehicle networking traffic data sequence according to the vehicle networking state when each vehicle networking traffic data sequence is collected. If the vehicle networking is in normal operation state during collection, let the class label be 1. If an intrusion occurs in the vehicle networking during collection, let the class label be 0; S3: Screen the data features according to the collected vehicle networking traffic data to obtain K effective data features, and then reduce the dimension of each initial feature vector of the vehicle networking traffic data according to the effective data features to obtain a feature vector of the vehicle networking traffic data; then for each vehicle networking traffic data sequence, use its N vehicle networking traffic data feature vectors as row vectors to form a vehicle networking traffic data feature matrix of size N×K; S4: Build a vehicle networking intrusion detection model, including a spatial feature extraction module, a time-domain feature extraction module, a feature splicing module, a self-attention module, a feature fusion module and a multi-layer perceptron, where: The spatial feature extraction module is used to extract spatial feature vectors with dimension B from each vehicle networking traffic data feature vector in the input vehicle networking traffic data feature matrix. The value of B is determined according to actual needs. Then, N spatial feature vectors are used to form a spatial feature F with size N×B spatial and send it to the feature splicing module and the feature fusion module; The time-domain feature extraction module is used to extract the time-domain feature F of size N×B from the input vehicle networking traffic data feature matrix temporal and send it to the feature splicing module and the feature fusion module; The feature splicing module is used to splice the spatial feature F spatial and the temporal feature F temporal to obtain the spatio-temporal feature F of size N×2B and send it to the self-attention module; The self-attention module is used to generate a self-attention score matrix H of size N×2B corresponding to the spatio-temporal feature F according to the self-attention mechanism and send it to the feature fusion module; The feature fusion module is used to fuse the spatial feature F according to the self-attention score matrix H spatial and the temporal feature F temporal to obtain the fused feature F fusion and send it to the multi-layer perceptron. The specific method is as follows: Divide the self-attention score matrix H according to the splicing method of the feature splicing module, and take the first B columns as the spatial feature F spatial 's weight matrix λ spatial , and take the last B columns as the temporal feature F temporal 's weight matrix λ temporal , and then calculate the fused feature F using the following formula fusion : F fusion = λ spatial * F spatial + λ temporal * F temporal where, * represents the Hadamard product; The multi-layer perceptron is used to predict whether an intrusion occurs in the vehicle network when collecting the feature matrix of the input vehicle network traffic data according to the fused feature F, and obtain the intrusion detection result; fusion S5: Use the vehicle networking traffic data feature matrix corresponding to each vehicle networking traffic data sequence as the input, and the corresponding class label as the expected output, and train the vehicle networking intrusion detection model constructed in step S4 to obtain a trained vehicle networking intrusion detection model; S6: When it is necessary to detect intrusion in the vehicle networking, collect a vehicle networking traffic data sequence containing N consecutive vehicle networking traffic data. Each vehicle networking traffic data contains K effective data features. Process each vehicle networking traffic data according to the preprocessing method in step S1 to obtain the corresponding feature vector of the vehicle networking traffic data, and then use the N vehicle networking traffic data feature vectors as row vectors to form a vehicle networking traffic data feature matrix of size N×K. Input this vehicle networking traffic data feature matrix into the trained vehicle networking intrusion detection model in step S5 to obtain the vehicle networking intrusion detection result.
2. The vehicle networking intrusion detection method according to claim 1, characterized in that, the data features in step S1 include three types of data features. The first type is basic security data features, that is, the security status data exchanged between vehicles; the second type is network data features, which are the key network information generated by vehicle communication; the third type is traffic statistical data features, that is, the statistical data features of the data sent by roadside units to vehicles.
3. The vehicle networking intrusion detection method according to claim 1, characterized in that, the following method is adopted for data feature screening in step S3: 1) Denote the number of the collected vehicle - to - everything (V2X) traffic data sequences in step S1 as D. Then the number of the initial feature vectors of the V2X traffic data G = D×N. Denote the g - th initial feature vector of the V2X traffic data as The corresponding class label is y g , and use the following formula to calculate the correlation cor between each data feature and the class label m : Among them, σ m represents the standard deviation of the corresponding value of the m-th data feature in the initial feature vectors of G vehicle network traffic data, and σ y represents the standard deviation of G class labels, and cov m represents the Pearson correlation coefficient between the m-th data feature and the class label. The calculation formula is as follows: Among them, μ m represents the average value of the corresponding values of the m-th data feature in the G initial feature vectors of the vehicle network traffic data, and μ y represents the average value of the G class labels; 2) Initialize r = 1, and initialize the data feature set as the set of all data features; 3) Let the input be the feature vector extracted from the initial feature vector of vehicle networking traffic data and containing the data features in the current data feature set, and the expected output be the corresponding class label. Train the preset classifier and count the classification accuracy of the trained classifier; 4) Determine whether r < R, where R represents the preset threshold. If so, go to step 5); otherwise, go to step 6); 5) Screen out and delete the data feature with the lowest correlation with the class label in the current data feature set, then let r = r + 1, and return to step 3); 6) Screen out the classifier with the highest classification accuracy from the R trained classifiers, and use the data features in its corresponding data feature set as the valid data features.
4. The vehicle networking intrusion detection method according to claim 1, characterized in that, the spatial feature extraction module in step S3 adopts a TCN network.
5. The vehicle networking intrusion detection method according to claim 1, characterized in that, the time domain feature extraction module in step S3 adopts an LSTM network.
6. The vehicle networking intrusion detection method according to claim 1, characterized in that, the calculation formula of the loss function L during the training of the vehicle networking intrusion detection model in step S5 is as follows: where n represents the number of samples in the current training sample batch, and y ic is the sign function, which takes 1 when the true class of sample i in the current training sample batch is the c-th class, and 0 otherwise; p ic is the predicted probability that sample i belongs to the c-th class output by the multi-layer perceptron, ω is the model parameter, η is the penalty term, and || || represents taking the norm.