System and method for autonomous driving system to detect abnormal behavior based on fused data
By generating fused data through a mobile edge computing system and combining it with weighted sensing data to identify malicious V2V messages, the problem of malicious message attacks in autonomous driving systems has been solved, improving the accuracy of navigation and guidance and reducing the risk of accidents.
Patent Information
- Application Number
- CN202210110169.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-29
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2042-01-29
AI Technical Summary
Autonomous vehicles are vulnerable to malicious V2V message attacks, which can reduce navigation and guidance capabilities and potentially cause traffic accidents.
The system uses a mobile edge computing system to generate fused data, which is combined with weighted RSU sensing data and vehicle sensing data. Malicious V2V messages are identified through an abnormal behavior detection module, and the processor is used to manage vehicle performance and report the data to the security credential management system.
Effectively identify and filter malicious V2V messages to improve the navigation and guidance accuracy of autonomous driving systems and reduce accident risks.
Smart Images

Figure CN116552559B_ABST
Abstract
Description
Technical Field
[0001] This technical field generally relates to autonomous vehicles, and more specifically to systems and methods for detecting malicious vehicle-to-vehicle (V2V) messages in an autonomous driving system. Background Technology
[0002] Automated vehicles are typically configured to receive vehicle-to-vehicle (V2V) messages from other automated vehicles. V2V messages include vehicle identifiers and vehicle data associated with the sending vehicle. The automated driving system (ADS) of an automated vehicle typically relies on the vehicle data contained in the V2V messages received from other automated vehicles to correctly guide and navigate the vehicle.
[0003] Malicious entities can send seemingly legitimate V2V messages to autonomous vehicles via wireless communication channels. The malicious entity may attempt to impersonate another, non-existent, autonomous vehicle. This non-existent autonomous vehicle can be referred to as a ghost vehicle. The malicious V2V message may include malicious vehicle data associated with the ghost vehicle.
[0004] An Adaptive Controller (ADS) within an autonomous vehicle might perform one or more actions based on malicious vehicle data received in malicious V2V messages. These actions could reduce traffic-related guidance efficiency or enable maneuvers to avoid non-existent ghost vehicles that could potentially cause accidents. It would be beneficial if the ADS could identify malicious V2V messages to avoid using malicious vehicle data that could impair its ability to properly guide and navigate the autonomous vehicle. Summary of the Invention
[0005] In one embodiment, an autonomous driving system (ADS) for an autonomous vehicle includes a communication module, an abnormal behavior detection module, and a processor. The communication module is configured to receive vehicle-to-vehicle (V2V) messages including source vehicle data and to receive fused data messages including fused data from a mobile edge computing (MEC) system including roadside units (RSUs). The source vehicle data includes the source vehicle location. The fused data is based on RSU sensing data and vehicle sensing data received at the RSU from at least one vehicle. The abnormal behavior detection module is configured to determine whether the source vehicle is located at the source vehicle location based on the fused data. The processor is configured to manage the performance of the autonomous vehicle based at least in part on the determination result and the source vehicle data.
[0006] In one embodiment, the fused data is based on weighted RSU sensing data and weighted vehicle sensing data, with a first weight associated with the RSU sensing data being greater than a second weight associated with the weighted vehicle sensing data.
[0007] In one embodiment, the abnormal behavior detection module is configured to determine whether the source vehicle data has passed the vehicle trustworthiness check, and the processor is configured to manage the performance of the autonomous vehicle based in part on the determination result and the source vehicle data.
[0008] In one embodiment, the vehicle credibility check of the source vehicle data includes at least one of the following: source vehicle speed credibility check, source vehicle location credibility check, vehicle acceleration credibility check, vehicle sudden appearance credibility check, vehicle message frequency credibility check, vehicle heading credibility check, and vehicle continuous message consistency credibility check.
[0009] In one embodiment, the abnormal behavior detection module is configured to classify V2V messages as malicious V2V messages when it is determined that the source vehicle is not located at the source vehicle's location.
[0010] In one embodiment, the system includes an anomaly behavior reporting module configured to report source vehicle identifiers associated with malicious V2V messages to a Security Credential Management System (SCMS).
[0011] In one embodiment, the fused data message is a message broadcast by the MEC system.
[0012] In one embodiment, a computer-readable medium includes instructions stored thereon for detecting anomalous behavior at an automated driving system (ADS), which, when executed by a processor, cause the processor to: receive a vehicle-to-vehicle (V2V) message including source vehicle data, the source vehicle data including the location of a source vehicle; receive a fused data message from a mobile edge computing (MEC) system including roadside units (RSUs), the fused data being based on RSU sensing data and vehicle sensing data received at the RSU from at least one vehicle; determine, based on the fused data, whether a source vehicle is located at the source vehicle location; and manage the performance of the automated driving vehicle based at least in part on the determination result and the source vehicle data.
[0013] In one embodiment, the computer-readable medium further includes instructions to cause a processor to receive a fused data message comprising fused data based on weighted RSU sensing data and weighted vehicle sensing data, wherein a first weight associated with the RSU sensing data is greater than a second weight associated with the weighted vehicle sensing data.
[0014] In one embodiment, the computer-readable medium further includes instructions to cause a processor to determine whether source vehicle data has passed a vehicle trustworthiness check and, in part based on the determination result, manage the performance of the autonomous vehicle according to the source vehicle data.
[0015] In one embodiment, the computer-readable medium further includes instructions to cause the processor to perform a vehicle trustworthiness check on the source vehicle data, the vehicle trustworthiness check including at least one of a source vehicle speed trustworthiness check, a source vehicle position trustworthiness check, a vehicle acceleration trustworthiness check, a vehicle sudden appearance trustworthiness check, a vehicle message frequency trustworthiness check, a vehicle heading trustworthiness check, and a vehicle continuous message consistency trustworthiness check.
[0016] In one embodiment, the computer-readable medium further includes instructions to cause the processor to classify a V2V message as a malicious V2V message when it determines that the source vehicle is not located at the source vehicle's location.
[0017] In one embodiment, the computer-readable medium further includes instructions to cause the processor to report the source vehicle identifier associated with the malicious V2V message to a security credential management system (SCMS).
[0018] In one embodiment, the computer-readable medium further includes instructions to cause a processor to receive a fused data message, the fused data message including a message broadcast by the MEC system.
[0019] In one embodiment, a method for detecting anomalous behavior at an autonomous driving system (ADS) of an autonomous vehicle includes: receiving, at the autonomous vehicle, a vehicle-to-vehicle (V2V) message including source vehicle data, the source vehicle data including the source vehicle location; receiving, at the autonomous vehicle, a fused data message including fused data based on RSU sensing data and vehicle sensing data received at the RSU from at least one vehicle; determining, at the anomalous behavior detection system, whether the source vehicle is located at the source vehicle location based on the fused data; and managing the performance of the autonomous vehicle based at least in part on the determination result and the source vehicle data.
[0020] In one embodiment, the system further includes: receiving a fused data message comprising fused data based on weighted RSU sensing data and weighted vehicle sensing data, wherein a first weight associated with the RSU sensing data is greater than a second weight associated with the weighted vehicle sensing data.
[0021] In one embodiment, the method further includes: determining whether source vehicle data has passed a vehicle credibility check at an abnormal behavior detection system, and managing the performance of the autonomous vehicle based in part on the source vehicle data based on the determination result.
[0022] In one embodiment, the method further includes: performing a vehicle credibility check on the source vehicle data, the vehicle credibility check including at least one of the following: source vehicle speed credibility check, source vehicle position credibility check, vehicle acceleration credibility check, vehicle sudden appearance credibility check, vehicle message frequency credibility check, vehicle heading credibility check, and vehicle continuous message consistency credibility check.
[0023] In one embodiment, the method further includes classifying the V2V message as a malicious V2V message when the abnormal behavior detection system determines that the source vehicle is not located at the source vehicle's location.
[0024] In one embodiment, the method further includes reporting the source vehicle identifier associated with the malicious V2V message to a security credential management system (SCMS). Attached Figure Description
[0025] Exemplary embodiments will be described below with reference to the accompanying drawings, in which the same reference numerals denote the same elements.
[0026] Figure 1 This is a functional block diagram of an autonomous vehicle including an abnormal behavior detection system, according to one embodiment.
[0027] Figure 2 This is a functional block diagram of an exemplary mobile edge computing (MEC) system including roadside units (RSUs);
[0028] Figure 3 This is a functional block diagram of the controller of an autonomous vehicle, including an embodiment of an abnormal behavior detection system.
[0029] Figure 4 This is a flowchart of an embodiment of a method for generating fused data messages at the MEC system and detecting anomalous behavior based on the fused data in the fused data messages at the Autopilot System (ADS) of an autonomous vehicle; and
[0030] Figure 5 This is a flowchart of an embodiment of a method for detecting abnormal behavior based on fused data at the ADS of an autonomous vehicle. Detailed Implementation
[0031] The following detailed description is exemplary in nature and is not intended to limit the scope of this application and its uses. Furthermore, it is not intended to be limited by any express or implied theory set forth in the foregoing technical field, the summary of the invention, or the following detailed description. As used herein, the term "module" refers to one or any combination of any hardware, software, firmware, electronic control components, processing logic, and / or processor device, including but not limited to: application-specific integrated circuits (ASICs), electronic circuits, processors (shared processors, dedicated processors, or processor groups) and memories executing one or more software or firmware programs, combinational logic circuits, and / or other suitable components providing the said functionality.
[0032] This document describes embodiments of the present disclosure based on functional and / or logical block components and various processing steps. It should be understood that these block components can be implemented by any number of hardware, software, and / or firmware components configured to perform specified functions. For example, embodiments of the present disclosure may employ various integrated circuit components (e.g., memory elements, digital signal processing elements, logic elements, or lookup tables, etc.) that can perform various functions under the control of one or more microprocessors or other control devices. Furthermore, those skilled in the art will understand that embodiments of the present disclosure can be practiced in conjunction with any number of systems, and the systems described herein are merely exemplary embodiments of the present disclosure.
[0033] For the sake of brevity, conventional techniques related to signal processing, data transmission, signaling, control, and other functional aspects of the system (and its various operating components) are not described in detail herein. Furthermore, the connections shown in the various figures included herein are intended to illustrate exemplary functional relationships and / or physical couplings between various elements. It should be noted that many alternative or additional functional relationships or physical connections may exist in one embodiment of this disclosure.
[0034] See Figure 1 The diagram shows a functional block diagram of an autonomous vehicle 100 including an abnormal behavior detection system 110, according to one embodiment. The autonomous vehicle 100 typically includes a chassis 112, a body 114, front wheels 116, and rear wheels 118. The body 114 is mounted on the chassis 112 and substantially encloses the components of the autonomous vehicle 100. The body 114 and the chassis 112 may together form a frame. The front wheels 116 and the rear wheels 118 are each rotatably connected to the chassis 112 near a corresponding corner of the body 114.
[0035] The autonomous vehicle 100 is, for example, a vehicle that is automatically controlled to transport passengers from one location to another. Although the autonomous vehicle 100 is depicted as a passenger car in the illustrated embodiment, other examples of autonomous vehicles include, but are not limited to, motorcycles, trucks, sport utility vehicles (SUVs), recreational vehicles (RVs), ships, and aircraft. In one embodiment, the autonomous vehicle 100 is a so-called Level 4 or Level 5 automation system. A Level 4 system means “high automation,” referring to the driving mode-specific performance of the Automated Driving System (ADS) for all aspects of a dynamic driving task, even when a human driver does not respond appropriately to an intervention request. A Level 5 system means “full automation,” referring to the all-time performance of the ADS for all aspects of a dynamic driving task under all road and environmental conditions that a human driver can handle.
[0036] As shown in the figure, an autonomous vehicle 100 typically includes a propulsion system 120, a transmission system 122, a steering system 124, a braking system 126, a vehicle sensor system 128, an actuator system 130, at least one data storage device 132, at least one controller 134, and a vehicle communication system 136. In various embodiments, the propulsion system 120 may include an internal combustion engine, an electric motor (such as a traction motor), and / or a fuel cell propulsion system. The transmission system 122 is configured to transmit power from the propulsion system 120 to the front wheels 116 and the rear wheels 118 according to a selectable speed ratio. According to various embodiments, the transmission system 122 may include a stepped automatic transmission, a continuously variable transmission (CVT), or other suitable transmission. The braking system 126 is configured to provide braking torque to the front wheels 116 and the rear wheels 118. In various embodiments, the braking system 126 may include friction brakes, brake-by-wire brakes, regenerative braking systems such as those powered by an electric motor, and / or other suitable braking systems. The steering system 124 influences the position of the front wheels 116 and the rear wheels 118. Although the steering system 124 is depicted as including a steering wheel for illustrative purposes, in some embodiments contemplated within the scope of this disclosure, the steering system 124 may not include a steering wheel.
[0037] The vehicle sensor system 128 includes one or more vehicle sensing devices 140a-140n that sense observable conditions of the external and / or internal environment of the autonomous vehicle 100. Examples of vehicle sensing devices 140a-140n include, but are not limited to, radar, lidar, GPS, optical cameras, thermal imaging cameras, ultrasonic sensors, and / or other sensors. The actuator system 130 includes one or more actuator devices 142a-142n that control one or more vehicle features, such as, but not limited to, propulsion system 120, transmission system 122, steering system 124, and braking system 126. In various embodiments, vehicle features may also include internal and / or external vehicle features, such as, but not limited to, doors, trunks, and cabin features (such as, for example, air, music, and lighting).
[0038] Vehicle communication system 136 is configured to wirelessly transmit information to each other with other entities (“Vehicle-to-Everything (V2X) communication”). For example, vehicle communication system 136 is configured to wirelessly transmit information to each other with other vehicles 148 (“V2V” communication), driving system infrastructure (“Vehicle-to-Infrastructure (V2I)” communication), remote systems, and / or personal devices. Examples of driving system infrastructure include, but are not limited to, mobile edge computing (MEC) systems 150 including roadside units (RSUs) 152. In one embodiment, vehicle communication system 136 is a wireless communication system configured to communicate via a wireless local area network (WLAN) employing the IEEE 802.11 standard or via cellular data communication. However, additional or alternative communication methods (such as dedicated short-range communication (DSRC) channels) are also considered within the scope of this disclosure. DSRC channels refer to one-way or two-way short-to-medium-range wireless communication channels designed for automobiles and a corresponding set of protocols and standards.
[0039] Data storage device 132 stores data used for automatically controlling the autonomous vehicle 100. Data storage device 132 may be part of controller 134, but separate from controller 134, or part of controller 134 and a separate system.
[0040] The controller 134 includes at least one processor 144 and a computer-readable storage device 146. The computer-readable storage device 146 may also refer to a computer-readable medium 146. In one embodiment, the computer-readable storage device 146 includes an embodiment of an abnormal behavior detection system 110. The processor 144 may be any custom or commercially available processor, central processing unit (CPU), graphics processing unit (GPU), auxiliary processor among several processors associated with the controller 134, semiconductor-based microprocessor (in the form of a microchip or chipset), macroprocessor, any combination thereof, or any device generally used for executing instructions. For example, the computer-readable storage device 146 may include volatile and non-volatile storage in read-only memory (ROM), random access memory (RAM), and persistent powered-on memory (KAM). KAM is persistent or non-volatile memory that can be used to store various operational variables when the processor 144 is powered off. The computer-readable storage device 146 may be implemented using any of a variety of known storage devices, such as PROM (programmable read-only memory), EPROM (electrically programmable read-only memory), EEPROM (electrically erasable programmable read-only memory), flash memory, or any other electrical, magnetic, optical, or combined storage device capable of storing data (some of which represent executable instructions used by the controller 134 in controlling the autonomous vehicle 100).
[0041] The instructions may include one or more separate programs, each comprising a sequence of executable instructions for implementing logical functions. When executed by processor 144, the instructions receive and process signals from vehicle sensor system 128, perform logic, calculations, methods, and / or algorithms to automatically control components of autonomous vehicle 100, and generate control signals to actuator system 130 to automatically control one or more components of autonomous vehicle 100 based on logic, calculations, methods, and / or algorithms. Although in Figure 1 Only one controller 134 is shown, but alternative embodiments of the autonomous vehicle 100 may include any number of controllers 134 that communicate via any suitable communication medium or combination of communication media and collaboratively process sensor signals, execute logic, calculations, methods and / or algorithms, and generate control signals to automatically control the features of the autonomous vehicle 100.
[0042] In various embodiments, one or more instructions of controller 134 are implemented to provide the ADS functionality as described with reference to one or more embodiments herein. Controller 134 or one of its functional modules is configured to implement the functionality described in one or more embodiments of the reference anomalous behavior detection system 110.
[0043] See Figure 2 A functional block diagram of an exemplary MEC system 150 including an RSU 152 is shown. The MEC system 150 includes an RSU 152 and a computing system 200. In one embodiment, the MEC system 150 includes an RSU 152 integrated with the computing system 200. In another embodiment, the computing system 200 and the RSU 152 are separate entities, wherein the computing system 200 is positioned within the communication range of the RSU 152.
[0044] In one embodiment, RSU 152 includes an RSU controller 202, an RSU sensor system 204, and an RSU communication system 206. The RSU sensor system 204 includes one or more RSU sensing devices 208a-208n that sense observable conditions associated with a vehicle passing through RSU 152. Examples of RSU sensing devices 208a-208n include, but are not limited to, radar, lidar, optical cameras, thermal imaging cameras, ultrasonic sensors, and / or other sensors. The RSU sensor system 204 is configured to generate RSU sensing data, including sensor data associated with the vehicle's location within the range of the RSU sensor system 204. The RSU sensor system 204 may be configured to generate RSU sensing data associated with other attributes of the vehicle within the range of the RSU sensor system 204.
[0045] In one embodiment, the RSU communication system 206 is a wireless communication system configured to receive V2I messages, including vehicle sensing data, from a vehicle within the range of the RSU 152. The RSU communication system 206 is configured to communicate via a wireless local area network (WLAN) employing the IEEE 802.11 standard or via cellular data communication. However, additional or alternative communication methods, such as Dedicated Short Range Communication (DSRC) channels, are also considered within the scope of this disclosure. DSRC channels refer to one-way or two-way short-to-medium range wireless communication channels specifically designed for automobiles, along with a corresponding set of protocols and standards.
[0046] Each vehicle receiving a V2I message at RSU 152 includes a vehicle controller, a vehicle sensor system, and a vehicle communication system. The vehicle sensor system is configured to sense other vehicles and objects within its range and generate vehicle sensing data. The vehicle controller is configured to generate a V2I message including the vehicle sensing data. The vehicle communication system is configured to send the V2I message including the vehicle sensing data to RSU 152. The V2I message is received by RSU communication system 206 at RSU 152.
[0047] In one embodiment, the computing system 200 includes a controller 210. In another embodiment, the controller 210 includes one or more processors 212 and a cooperative sensing module 214. The cooperative sensing module 214 is configured to generate fused data based on RSU sensing data generated by the RSU sensor system 204 and vehicle sensing data received from V2I messages within the range of the RSU 152. The RSU sensing data is independent of specific vehicle coordinates. The cooperative sensing module 214 is configured to fuse the RSU sensing data and vehicle sensing data using global coordinates (such as, for example, Global Positioning System (GPS) coordinates) to generate the fused data. The cooperative sensing module 214 is configured to periodically generate updated fused data based on updated RSU sensing data received from the RSU sensor system 204 and updated vehicle sensing data received in V2I messages.
[0048] In one embodiment, the collaborative sensing module 214 is configured to apply a first weight to RSU sensing data and a second weight to vehicle sensing data to generate fused data, wherein the first weight is greater than the second weight. V2I messages received at RSU 152 may be malicious. Applying a lower weight to the vehicle sensing data received in the V2I messages reduces the impact of potentially malicious V2I messages on the integrity of the fused data.
[0049] RSU communication system 206 is configured to broadcast converged data messages that include converged data generated by cooperative sensing module 214. The converged data is periodically updated, and converged messages including the updated converged data are periodically broadcast. Vehicles within range of RSU 152 receive the broadcast converged data messages. The converged data messages may be referred to as Custom Basic Safety Messages (BSMs). MEC system 150 may include additional components that facilitate the operation of MEC system 150. Although one configuration of the MEC system is shown, alternative embodiments may include other configurations of the MEC system.
[0050] See Figure 3 This diagram illustrates a functional block diagram of a controller 134 of an autonomous vehicle 100, including an abnormal behavior detection system 110, according to one embodiment. The controller 134 is configured to be communicatively coupled to a vehicle communication system 136. In one embodiment, the controller 134 is configured to be communicatively coupled to a Security Credential Management System (SCMS) 302. In one embodiment, the SCMS 302 is located in a back-end office. In another embodiment, the SCMS 302 is located in an edge computing cluster. The SCMS 302 includes a Certificate Authority (CA) 304 and an abnormal behavior management authority 306.
[0051] Vehicle communication system 136 is configured to receive converged data messages and V2V messages broadcast by MEC system 150 via a wireless communication channel. Each received V2V message includes a source vehicle identifier and source vehicle data. The source vehicle identifier identifies the source vehicle from which the V2V message is allegedly sent to autonomous vehicle 100. In one embodiment, the source vehicle data includes the source vehicle location. In one embodiment, a V2V message receiving source vehicle data from a source vehicle is called a Basic Safety Message (BSM).
[0052] In one embodiment, the vehicle communication system 136 is a wireless communication system configured to communicate via a wireless local area network (WLAN) employing the IEEE 802.11 standard or via cellular data communication. However, additional or alternative communication methods, such as Dedicated Short Range Communication (DSRC) channels, are also considered within the scope of this disclosure. A DSRC channel refers to a one-way or two-way short-to-medium range wireless communication channel specifically designed for automobiles, along with a corresponding set of protocols and standards.
[0053] In one embodiment, controller 134 implements the ADS within the autonomous vehicle 100. That is, suitable software and / or hardware components of controller 134 (e.g., processor 144 and computer-readable storage device 146) are used to provide the ADS for use in conjunction with other components of the autonomous vehicle 100. In one embodiment, the instructions of the ADS are organized by function or system. In one embodiment, the abnormal behavior detection system 110 described herein and its functions are part of the ADS and implement at least a portion of the functions of the ADS. The ADS includes additional components (not shown) that facilitate the operation of the autonomous vehicle 100. Controller 134 is configured to communicatively couple to other components (not shown) of the autonomous vehicle 100 to facilitate the operation of the ADS.
[0054] The controller 134 includes at least one processor 144 and a memory 146. The memory 146 is also referred to as a computer-readable storage device, a computer-readable medium, or a computer-readable medium. In one embodiment, the memory 146 includes an embodiment of an abnormal behavior detection system 110 and a communication module 308.
[0055] Communication module 308 is configured to process received V2V messages and received converged data messages. Communication module 308 is configured to process received V2V messages and received converged data messages according to the physical layer (PHY), media access control (MAC), and short wavelet message protocol (WSMP) associated with the V2V messages and converged data messages.
[0056] In one embodiment, the communication module 308 includes a security service layer. In one embodiment, the communication module 308 includes an IEEE 1609.2 security service layer. The security service layer is configured to determine whether the certificate associated with a received V2V message and / or a received converged data message is an authorized certificate or a legitimate certificate.
[0057] Communication module 308 includes a V2X application. In one embodiment, the V2X application is configured to generate source vehicle data based on V2V messages received at communication module 308 via vehicle communication system 136. The source vehicle data includes source vehicle attributes. Examples of source vehicle attributes include, but are not limited to, source vehicle speed, source vehicle position, source vehicle acceleration, and source vehicle heading. The V2V message includes a timestamp associated with the source vehicle and a source vehicle identifier. In one embodiment, the V2X application is configured to generate fused data received in a fused data message.
[0058] In one embodiment, the V2X application is configured to analyze source vehicle data to determine whether the autonomous vehicle 100 poses a potential risk. The ADS uses the potential risks identified by the V2X application to implement one or more risk avoidance actions. For example, source vehicle data associated with the source vehicle may indicate that the source vehicle is located at an intersection. The V2X application may determine that the source vehicle poses a potential collision risk to the autonomous vehicle 100. By issuing a command to the braking system 126, the ADS may implement one or more actions to slow down or stop the autonomous vehicle 100 to avoid a potential collision with the source vehicle.
[0059] In one embodiment, the abnormal behavior detection system 110 includes an abnormal behavior detection module 310. In another embodiment, the abnormal behavior detection system 110 includes an abnormal behavior detection module 310 and an abnormal behavior reporting module 312. The abnormal behavior detection module 310 is configured to determine, based on fused data, whether the source vehicle is physically located at the source vehicle location included in the V2V message, to determine whether the received V2V message is a legitimate V2V message or a malicious V2V message. The abnormal behavior detection module 310 is configured to convert the fused data based on global coordinates into coordinates associated with a specific vehicle. The abnormal behavior detection module 310 is configured to compare the coordinates associated with the specific vehicle with the coordinates associated with the source vehicle location to determine whether the source vehicle is physically located at the source vehicle location.
[0060] In one embodiment, if the abnormal behavior detection module 310 determines that the source vehicle is physically located at the source vehicle location in the V2V message, then the abnormal behavior detection module 310 determines that the V2V message is a legitimate V2V message. In another embodiment, if the abnormal behavior detection module 310 determines that the source vehicle is not physically located at the source vehicle location in the V2V message, then the abnormal behavior detection module 310 determines that the V2V message is a malicious V2V message.
[0061] In one embodiment, if the abnormal behavior detection module 310 determines that the source vehicle is physically located at the source vehicle location in the V2V message, the abnormal behavior detection module 310 is configured to perform a vehicle trustworthiness check on the vehicle attributes included in the V2V message to determine whether the V2V message is a legitimate V2V message. If the vehicle attributes pass the vehicle trustworthiness check, the abnormal behavior detection module 310 determines that the V2V message is a legitimate V2V message. If one or more vehicle attributes fail the vehicle trustworthiness check, the abnormal behavior detection module 310 determines that the V2V message is a malicious V2V message.
[0062] Malicious V2V messages can appear to be generated by an actual vehicle but are actually generated by a malicious entity. A malicious entity might be attempting a Sybil attack, where the malicious V2V message is generated by a ghost vehicle or a non-existent vehicle. The anomaly detection module 310 is configured to notify the V2X application that a received V2V message is malicious and to ignore source vehicle data associated with the malicious V2V message, thereby ensuring that the ADS does not perform navigation and / or guidance actions based on source vehicle data contained in the malicious V2V message.
[0063] The V2V message includes a source vehicle identifier that identifies the source vehicle that allegedly sent the V2V message to the autonomous vehicle 100. If the abnormal behavior detection module 310 determines that the received V2V message is a malicious V2V message, the abnormal behavior detection module 310 classifies the source vehicle identifier associated with the malicious V2V message as a malicious source vehicle identifier. In one embodiment, the abnormal behavior detection module 310 is configured to notify the communication module 308 that the source vehicle identifier associated with the received malicious V2V message is a malicious source vehicle identifier, so that the communication module 308 will identify any future V2V messages that include the malicious source vehicle identifier as malicious V2V messages and ignore the source vehicle data associated with these malicious V2V messages.
[0064] In one embodiment, the abnormal behavior detection module 310 is configured to notify the abnormal behavior reporting module 312 that the source vehicle identifier associated with the received malicious V2V message is a malicious source vehicle identifier. The abnormal behavior reporting module 312 sends a classification report including the malicious source vehicle identifier to the SCMS 302.
[0065] In one embodiment, when the abnormal behavior detection module 310 classifies the source vehicle identifier as a malicious source vehicle identifier, the abnormal behavior reporting module 312 generates a classification report including a unique identifier based on the vehicle's license plate, vehicle characteristics, and the vehicle's V2V message or BSM identifier, and maps the unique identifier to the vehicles classified as legitimate or malicious vehicles. The abnormal behavior reporting module 312 is configured to send the classification report to the SCMS 302.
[0066] In one embodiment, the abnormal behavior management unit 306 at SCMS 302 receives a classification report including a malicious source vehicle identifier and broadcasts the malicious vehicle identifier to other vehicles near the autonomous vehicle 100 that identified the malicious source vehicle identifier, causing these other vehicles to identify V2V messages associated with the malicious source vehicle identifier as malicious V2V messages and ignore the source vehicle data associated with these malicious V2V messages.
[0067] although Figure 3 The diagram shows several different components of the autonomous vehicle 100 and controller 134, but the autonomous vehicle 100 and / or controller 134 may include additional components that facilitate the operation of the autonomous vehicle.
[0068] See Figure 4 This diagram illustrates a flowchart of an embodiment of a method 400 for generating a fused data message at an MEC system 150 and detecting anomalous behavior based on the fused data in the fused data message at the Autopilot System (ADS) of an autonomous vehicle 100. Method 400 is performed by an embodiment including an anomalous behavior detection system 110 and a controller 134 of the MEC system 150. Method 400 can be performed by the MEC system 150 and controller 134 in conjunction with other components of the autonomous vehicle 100. Method 400 can be performed by hardware circuitry, firmware, software, and / or combinations thereof. Reference Figure 2 and Figure 3 Description method 400.
[0069] In step 402, the cooperative sensing module 214 receives RSU sensing data generated by the RSU sensor system 204. The RSU sensing data is associated with vehicles located within the range of the RSU sensor system 204. The RSU sensing data does not include specific vehicle coordinates associated with different vehicles within the range of the RSU sensor system 204.
[0070] In step 404, the cooperative sensing module 214 receives vehicle sensing data. The RSU communication system 206 at the MEC system 150 receives V2I messages including vehicle sensing data from vehicles within the range of the RSU 152. The vehicle sensing data received from the vehicle is associated with other vehicles and objects within the range of that vehicle's vehicle sensing system.
[0071] In step 406, the cooperative sensing module 214 generates fused data based on RSU sensing data generated by the RSU sensor system 204 and vehicle sensing data from V2I messages received from the vehicle within the range of RSU 152. The cooperative sensing module 214 is configured to fuse the RSU sensing data and vehicle sensing data using global coordinates (such as, for example, GPS coordinates) to generate the fused data. In one embodiment, the cooperative sensing module 214 applies a first weight to the RSU sensing data and a second weight to the vehicle sensing data to generate the fused data, wherein the first weight is greater than the second weight. V2I messages received at RSU 152 may be malicious. Applying a lower weight to the vehicle sensing data received in the V2I messages reduces the impact of potentially malicious V2I messages on the integrity of the fused data.
[0072] In step 408, the MEC system 150 broadcasts a fused data message, which includes fused data generated by the cooperative sensing module 214. In step 410, the abnormal behavior detection system 110 of the autonomous vehicle 100 receives the fused data message, which includes the fused data, via the vehicle communication system 136.
[0073] In step 412, almost simultaneously with receiving the fused data message at the abnormal behavior detection system 110 in step 410, a V2V message including source vehicle data and a source vehicle identifier is received at the abnormal behavior detection system 110. The V2V message is received at the abnormal behavior detection system 110 via the vehicle communication system 136 and the communication module 308. The source vehicle data includes vehicle attributes of the source vehicle. Examples of vehicle attributes include, but are not limited to, the source vehicle's speed, source vehicle position, source vehicle acceleration, and source vehicle heading.
[0074] In step 414, the anomaly detection system 110 determines whether the source vehicle is actually located at the source vehicle location received in the V2V message. The anomaly detection system 110 converts the fused data based on global coordinates into coordinates associated with a specific vehicle. Based on the fused data, the anomaly detection system 110 compares the coordinates associated with the specific vehicle with the coordinates associated with the source vehicle location received in the V2V message to determine whether the source vehicle is physically located at the source vehicle location specified in the V2V message.
[0075] In one embodiment, if the abnormal behavior detection system 110 determines in step 414 that the source vehicle is not physically located at the source vehicle location in the V2V message, then in step 416, the abnormal behavior detection system 110 determines that the V2V message is a malicious V2V message. A malicious V2V message may appear to be generated by an actual vehicle, but is actually generated by a malicious entity. The malicious entity may be attempting a Sybil attack, where the malicious V2V message is generated by a ghost vehicle or a non-existent vehicle.
[0076] The abnormal behavior detection system 110 notifies the V2X application that a received V2V message is a malicious V2V message and ignores the source vehicle data associated with the malicious V2V message, thereby ensuring that the ADS does not perform navigation and / or guidance actions based on malicious source vehicle data. In one embodiment, the abnormal behavior detection system 110 generates a classification report including a malicious source vehicle identifier and sends the classification report including the malicious source vehicle identifier to SCMS 302. The abnormal behavior management authority 306 at SCMS 302 stores the malicious source vehicle identifier at SCMS 302. The abnormal behavior management authority 306 broadcasts the malicious source vehicle identifier to autonomous vehicles located near the autonomous vehicle 100.
[0077] If, in step 414, the abnormal behavior detection system 110 determines that the source vehicle is physically located at the source vehicle location received in the V2V message, then in step 418, the abnormal behavior detection system 110 performs a vehicle credibility check on the vehicle attributes contained in the V2V message to determine whether the V2V message is a legitimate V2V message. The vehicle credibility check is used to determine whether the V2V vehicle data is credible. In one embodiment, the vehicle credibility check includes one or more of the following: source vehicle speed credibility check, source vehicle location credibility check, vehicle acceleration credibility check, vehicle sudden appearance credibility check, vehicle message frequency credibility check, vehicle heading credibility check, and vehicle continuous message consistency credibility check.
[0078] If the abnormal behavior detection system 110 determines in step 418 that the vehicle attributes have passed the vehicle trustworthiness check, then in step 420, the abnormal behavior detection system 110 determines that the V2V message is a legitimate V2V message. The controller 134 is configured to implement ADS in the autonomous vehicle 100 based on the source vehicle data associated with the legitimate V2V message when the V2V message is identified as a legitimate V2V message.
[0079] See Figure 5 The diagram illustrates a flowchart of one embodiment of a method 500 for detecting anomalous behavior based on fused data at the ADS of an autonomous vehicle 100. Method 500 is performed by a controller 134, including an anomalous behavior detection system 110, as in one embodiment. Method 500 can be performed by the controller 134 in conjunction with other components of the autonomous vehicle 100. Method 500 can be performed by hardware circuitry, firmware, software, and / or combinations thereof.
[0080] In step 502, a V2V message including source vehicle data, including the source vehicle's location, is received at the autonomous vehicle 100. In step 504, a fused data message including fused data, based on RSU sensing data and vehicle sensing data received at the RSU 152 from the MEC system 150 including RSU 152, is received at the autonomous vehicle 100. In step 506, the abnormal behavior detection system 110 determines whether the source vehicle is located at the source vehicle's location based on the fused data. In step 508, the ADS manages the performance of the autonomous vehicle 100 based at least in part on the determination result using the source vehicle data.
[0081] Employing an anomaly detection system 110 at the autonomous vehicle 100 can help identify Sybil attacks targeting malicious or ghost vehicles based on fused data generated by the cooperative sensing module 214, determining whether the actual vehicle is located at the source vehicle position in the received V2V message. Identifying Sybil attacks targeting malicious entities can reduce the infiltration of malicious source vehicle data received via malicious V2V messages into the intelligent transportation system (ITS) of the autonomous vehicle 100. Employing an anomaly detection system 110 at the autonomous vehicle 100 can help remove anomalous or malicious entities from the V2X ecosystem, thereby protecting the autonomous vehicle 100 and the entire autonomous vehicle system. Employing the cooperative sensing module 214 can also allow the identification of malicious V2V messages generated by malicious entities masquerading as ghost vehicles, which appear to be located in a position where the vehicle sensor system 128 of the autonomous vehicle 100 cannot sense the presence of the actual vehicle.
[0082] While at least one exemplary embodiment has been presented in the foregoing detailed descriptions, it should be understood that numerous variations exist. It should also be understood that one or more exemplary embodiments are merely examples and are not intended to limit the scope, applicability, or configuration of this disclosure in any way. Rather, the foregoing detailed descriptions will provide those skilled in the art with a convenient roadmap for implementing one or more exemplary embodiments. It should be understood that various changes can be made to the function and arrangement of the elements without departing from the scope of this disclosure as set forth in the appended claims and their legal equivalents.
Claims
1. An autonomous driving system (ADS) for an autonomous vehicle, comprising an abnormal behavior detection system, wherein the ADS includes: The communication module is configured as follows: Receive vehicle-to-vehicle (V2V) messages from the source vehicle, including source vehicle data such as its location; and Receives a fused data message containing fused data from a mobile edge computing (MEC) system including a roadside unit (RSU), the fused data being based on RSU sensing data and vehicle sensing data received at the RSU from the source vehicle. The abnormal behavior detection module is configured as follows: Based on the fused data, determine whether the source vehicle is located at the source vehicle's location; When it is determined that the source vehicle is not located at the source vehicle's location, the V2V message is classified as a malicious V2V message generated by a malicious entity. Ignore the source vehicle data associated with the malicious V2V information, thereby ensuring that the ADS does not perform navigation actions based on the source vehicle data included in the malicious V2V message; as well as The processor is configured to manage the performance of the autonomous vehicle based at least in part on the source vehicle data, according to a determined result.
2. The system of claim 1, wherein the fused data is based on weighted RSU sensing data and weighted vehicle sensing data, and a first weight associated with the RSU sensing data is greater than a second weight associated with the weighted vehicle sensing data.
3. The system of claim 1, wherein the abnormal behavior detection module is configured to determine whether the source vehicle data has passed the vehicle trustworthiness check, and the processor is configured to manage the performance of the autonomous vehicle based in part on the determination result and the source vehicle data.
4. The system according to claim 3, wherein the vehicle reliability check of the source vehicle data includes at least one of the following: source vehicle speed reliability check, source vehicle position reliability check, vehicle acceleration reliability check, vehicle sudden appearance reliability check, vehicle message frequency reliability check, vehicle heading reliability check, and vehicle continuous message consistency reliability check.
5. The system according to claim 4 further includes an abnormal behavior reporting module, configured to report the source vehicle identifier associated with the malicious V2V message to the Security Credential Management System (SCMS).
6. The system of claim 1, wherein the fusion data message includes a message broadcast by the MEC system.
7. A computer-readable medium including instructions stored thereon for detecting anomalous behavior at an automated driving system (ADS), the instructions, when executed by a processor, causing the processor to perform the following operations: Receive vehicle-to-vehicle V2V messages from the source vehicle, including source vehicle data such as the source vehicle's location. Receives a fused data message containing fused data from a mobile edge computing (MEC) system including a roadside unit (RSU), the fused data being based on RSU sensing data and vehicle sensing data received at the RSU from the source vehicle. Based on the fused data, determine whether the source vehicle is located at the source vehicle's location; When it is determined that the source vehicle is not located at the source vehicle's location, the V2V message is classified as a malicious V2V message generated by a malicious entity. Ignore the source vehicle data associated with the malicious V2V information, thereby ensuring that the ADS does not perform navigation actions based on the source vehicle data included in the malicious V2V message; and The performance of autonomous vehicles is managed, at least in part, based on the determined results and the source vehicle data.
8. The computer-readable medium of claim 7, further comprising instructions to cause the processor to receive a fused data message including the fused data, the fused data being based on weighted RSU sensing data and weighted vehicle sensing data, wherein a first weight associated with the RSU sensing data is greater than a second weight associated with the weighted vehicle sensing data.
9. The computer-readable medium of claim 7, further comprising instructions to cause the processor to determine whether the source vehicle data has passed a vehicle trustworthiness check and to manage the performance of the autonomous vehicle based on the source vehicle data in part based on the determination result.
Citation Information
Patent Citations
Misbehavior detection in autonomous driving communications
US20200137580A1