Vehicle CAN bus intrusion detection method, device, electronic device and medium
By converting the real-time CAN bus data of the vehicle into images and using the CNN-SwinT hybrid model for detection, the problem that existing systems cannot effectively capture context information and are prone to misjudgment is solved, and efficient and accurate intrusion detection is achieved.
Patent Information
- Application Number
- CN202410212829.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-27
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-02-27
AI Technical Summary
The existing vehicle CAN bus intrusion detection system cannot effectively capture the data sequence context information, and it is prone to misjudgment caused by abnormal data false alarms.
Using the vehicle CAN bus intrusion detection method based on the CNN-SwinT hybrid model, the real-time CAN bus data is converted into a red, green and blue three-channel image, and the model is input to extract image features and classify it, and the probability value of the attack type is output to determine the intrusion.
It significantly improves the accuracy and efficiency of vehicle CAN bus intrusion detection, and can quickly train the model in the case of insufficient data, capture the spatio-temporal characteristics of the data, and reduce false alarms and misjudgments.
Smart Images

Figure CN118552757B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of vehicle network security and artificial intelligence technology, and in particular to a vehicle CAN bus intrusion detection method, a vehicle CAN bus intrusion detection device, an electronic device and a computer-readable medium. Background Art
[0002] The vehicle CAN bus is a network system for internal communication in the vehicle, which records the data exchange between various electronic control units in the vehicle. CAN bus data provides an important and available data resource for vehicle intrusion detection, but the current vehicle CAN bus intrusion detection system using a single neural network has some difficult problems to solve. For example, the intrusion detection system using only CNN cannot capture information in the context of the data sequence. In addition, the intrusion detection system using traditional deep learning usually relies on normal CAN bus data, but once an abnormal data is mistakenly recorded in the CAN bus data, it will cause a false alarm in the intrusion detection system.
[0003] Transfer learning is a deep learning method that allows a model trained on a certain task to be used for another related but different task. The key advantage of this method is that it can use the existing knowledge obtained from pre-training to reduce the training data required for new tasks. Fine-tuning the pre-trained model using transfer learning methods can speed up the entire training process.
[0004] The SwinT model is a window-based self-attention transformer model proposed by the Microsoft team in a paper. In the field of computer vision, the SwinT model has become the current industry benchmark with its excellent performance. It can not only pay attention to the context information of the data, but also the spatial information of the data. However, the network structure of the SwinT model is complex, the number of parameters is large, and the training consumes a lot of computing resources. Therefore, how to use transfer learning to fine-tune the SwinT model is particularly important. Summary of the invention
[0005] In view of the above problems, the present invention is proposed to provide a vehicle CAN bus intrusion detection method and a corresponding vehicle CAN bus intrusion detection device, an electronic device and a computer-readable medium that overcome the above problems or at least partially solve the above problems.
[0006] The present invention discloses a vehicle CAN bus intrusion detection method, the method comprising:
[0007] Collect real-time CAN bus data of vehicles;
[0008] Convert the real-time CAN bus data of the vehicle into a red, green and blue three-channel image to obtain the real-time CAN bus image data of the vehicle;
[0009] The real-time CAN bus image data of the vehicle is input into a vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model outputs probability values of various vehicle CAN bus attack types; the vehicle CAN bus attack types include denial of service attack, fuzzy attack, impersonation attack, and no attack state;
[0010] If the probability value of the non-attack state is less than a preset safety threshold, it is determined that the vehicle has been invaded.
[0011] Optionally, the real-time vehicle CAN bus image data is input into a vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model outputs probability values of various vehicle CAN bus attack types, including:
[0012] The vehicle real-time CAN bus image data is input into the vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model extracts the features of the vehicle real-time CAN bus data from the vehicle real-time CAN bus image data to generate an image feature map of the vehicle real-time CAN bus data;
[0013] The image feature graph of the real-time CAN bus data of the vehicle is classified and processed, and probability values of various vehicle CAN bus attack types are output.
[0014] Optionally, the vehicle real-time CAN bus image data is input into the vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model extracts features of the vehicle real-time CAN bus data from the vehicle real-time CAN bus image data to generate an image feature map of the vehicle real-time CAN bus data, including:
[0015] The real-time CAN bus image data of the vehicle is input into the vehicle CAN bus intrusion detection model, and the first convolution layer of the vehicle CAN bus intrusion detection model performs a convolution operation on the real-time CAN bus image data of the vehicle, extracts features of the real-time CAN bus data of the vehicle and adjusts the number of channels of the image feature map;
[0016] The first batch normalization layer of the vehicle CAN bus intrusion detection model normalizes the features of the vehicle real-time CAN bus data, and the first maximum pooling layer of the vehicle CAN bus intrusion detection model compresses the normalized features to obtain an initial image feature map of the vehicle real-time CAN bus data;
[0017] The second convolution layer of the vehicle CAN bus intrusion detection model performs a convolution operation on the initial image feature map to extract low-dimensional features of the vehicle real-time CAN bus data and adjust the number of image feature map channels;
[0018] The second batch normalization layer of the vehicle CAN bus intrusion detection model normalizes the low-dimensional features of the vehicle's real-time CAN bus data, and the second maximum pooling layer of the vehicle CAN bus intrusion detection model compresses the normalized low-dimensional features to obtain an image feature map of the vehicle's real-time CAN bus data.
[0019] Optionally, the image feature graph of the real-time CAN bus data of the vehicle is classified and processed to output probability values of various types of vehicle CAN bus attacks, including:
[0020] The vehicle CAN bus intrusion detection model performs block partitioning on the image feature map to obtain a plurality of feature regions of the same size and without overlapping each other;
[0021] Flattening the feature region and inputting it into the linear embedding layer of the vehicle CAN bus intrusion detection model for conversion to obtain a feature region code;
[0022] Inputting the characteristic region code into a plurality of SwinT encoding blocks of the vehicle CAN bus intrusion detection model;
[0023] The SwinT encoding block calculates the self-attention weight of the feature region code and performs weighted processing on the feature region code according to the self-attention weight to obtain a self-attention feature map; a block merging layer is set in the middle of the SwinT encoding block to merge the output of the SwinT encoding block;
[0024] The self-attention feature map output by the last SwinT encoding block is input into a multi-layer perceptron layer consisting of a fully connected layer and a softmax activation function, which outputs probability values of various vehicle CAN bus attack types.
[0025] Optionally, the generation of the vehicle CAN bus intrusion detection model includes:
[0026] Acquire historical CAN bus data of the vehicle; the historical CAN bus data of the vehicle includes messages of multiple attack types and probability value labels of each attack type; the messages of the multiple attack types include denial of service attack messages, fuzzy attack messages, impersonation attack messages, and no attack status messages;
[0027] Convert the vehicle historical CAN bus data into a red, green and blue three-channel image to obtain the vehicle historical CAN bus image data;
[0028] The vehicle historical CAN bus image data is used to train the pre-trained CNN-SwinT hybrid model to obtain the vehicle CAN bus intrusion detection model.
[0029] Optionally, the vehicle historical CAN bus image data is used to train a pre-trained CNN-SwinT hybrid model to obtain the vehicle CAN bus intrusion detection model, including:
[0030] Initialize the parameter weights of the CNN part and the parameter weights of the linear embedding layer of the SwinT part in the pre-trained CNN-SwinT hybrid model, as well as the parameter weights of the multi-layer perceptron layer composed of a fully connected layer and a softmax activation function, and freeze the parameter weights of the SwinT coding block and the block merging layer of the SwinT part;
[0031] Input the vehicle historical CAN bus image data into the CNN-SwinT hybrid model, and output probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model;
[0032] According to the probability value label of each attack type and the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model, the parameter weights of the CNN part and the parameter weights of the linear embedding layer of the SwinT part in the CNN-SwinT hybrid model, as well as the parameter weights of the multi-layer perceptron layer composed of a fully connected layer and a softmax activation function are iteratively optimized to obtain the vehicle CAN bus intrusion detection model.
[0033] Optionally, the vehicle historical CAN bus image data is input into the CNN-SwinT hybrid model, and the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model are output, including:
[0034] Inputting the vehicle historical CAN bus image data into the CNN-SwinT hybrid model, the CNN-SwinT hybrid model extracting features of the vehicle historical CAN bus data from the vehicle historical CAN bus image data to obtain an image feature map of the vehicle historical CAN bus data;
[0035] The image feature graph of the vehicle historical CAN bus data is classified and processed, and the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model are output.
[0036] The present invention also discloses a vehicle CAN bus intrusion detection device, the device comprising:
[0037] Real-time CAN bus data acquisition module, used to collect real-time CAN bus data of vehicles;
[0038] A first image conversion module is used to convert the real-time CAN bus data of the vehicle into a red, green and blue three-channel image to obtain the real-time CAN bus image data of the vehicle;
[0039] A real-time attack probability prediction module is used to input the real-time CAN bus image data of the vehicle into a vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model outputs probability values of various vehicle CAN bus attack types; the vehicle CAN bus attack types include denial of service attack, fuzzy attack, impersonation attack, and no attack state;
[0040] The attack determination module is used to determine that the vehicle is invaded if the probability value of the non-attack state is less than a preset safety threshold.
[0041] Optionally, the real-time attack probability prediction module includes:
[0042] A real-time image feature map generating submodule, used for inputting the real-time CAN bus image data of the vehicle into the vehicle CAN bus intrusion detection model, wherein the vehicle CAN bus intrusion detection model extracts features of the real-time CAN bus data of the vehicle from the real-time CAN bus image data of the vehicle, and generates an image feature map of the real-time CAN bus data of the vehicle;
[0043] The real-time attack probability prediction submodule is used to classify the image feature map of the real-time CAN bus data of the vehicle and output the probability values of various vehicle CAN bus attack types.
[0044] Optionally, the real-time image feature map generating submodule includes:
[0045] A first convolution unit is used to input the real-time CAN bus image data of the vehicle into the vehicle CAN bus intrusion detection model, and the first convolution layer of the vehicle CAN bus intrusion detection model performs a convolution operation on the real-time CAN bus image data of the vehicle, extracts features of the real-time CAN bus data of the vehicle, and adjusts the number of channels of the image feature map;
[0046] A first normalization and compression unit, used for the first batch normalization layer of the vehicle CAN bus intrusion detection model to normalize the features of the vehicle real-time CAN bus data, and the first maximum pooling layer of the vehicle CAN bus intrusion detection model to compress the normalized features to obtain an initial image feature map of the vehicle real-time CAN bus data;
[0047] A second convolution unit, used for the second convolution layer of the vehicle CAN bus intrusion detection model to perform a convolution operation on the initial image feature map, extract low-dimensional features of the vehicle real-time CAN bus data and adjust the number of image feature map channels;
[0048] The second normalization and compression unit is used for the second batch normalization layer of the vehicle CAN bus intrusion detection model to normalize the low-dimensional features of the vehicle real-time CAN bus data, and the second maximum pooling layer of the vehicle CAN bus intrusion detection model to compress the normalized low-dimensional features to obtain an image feature map of the vehicle real-time CAN bus data.
[0049] Optionally, the real-time attack probability prediction submodule includes:
[0050] A partitioning unit, used for the vehicle CAN bus intrusion detection model to perform block partitioning on the image feature map to obtain a plurality of feature regions of the same size and non-overlapping;
[0051] A feature region code generating unit, used for flattening the feature region and inputting the flattened feature region into the linear embedding layer of the vehicle CAN bus intrusion detection model for conversion to obtain a feature region code;
[0052] An input unit, used for inputting the characteristic area code into a plurality of SwinT encoding blocks of the vehicle CAN bus intrusion detection model;
[0053] A self-attention feature map generating unit, which is used for the SwinT encoding block to calculate the self-attention weight of the feature region code and perform weighted processing on the feature region code according to the self-attention weight to obtain a self-attention feature map; a block merging layer is provided in the middle of the SwinT encoding block, which is used to merge the output of the SwinT encoding block;
[0054] The real-time attack probability prediction unit is used to input the self-attention feature map output by the last SwinT encoding block into a multi-layer perceptron layer composed of a fully connected layer and a softmax activation function, and the multi-layer perceptron layer outputs probability values of various vehicle CAN bus attack types.
[0055] Optionally, the device comprises:
[0056] A historical CAN bus data acquisition module is used to acquire historical CAN bus data of the vehicle; the historical CAN bus data of the vehicle includes messages of multiple attack types and probability value labels of each attack type; the messages of multiple attack types include denial of service attack messages, fuzzy attack messages, impersonation attack messages, and no attack status messages;
[0057] A second image conversion module is used to convert the vehicle historical CAN bus data into a red, green and blue three-channel image to obtain the vehicle historical CAN bus image data;
[0058] The model training module is used to train the pre-trained CNN-SwinT hybrid model using the historical CAN bus image data of the vehicle to obtain the vehicle CAN bus intrusion detection model.
[0059] Optionally, the model training module includes:
[0060] A weight freezing and initialization submodule, used to initialize the parameter weights of the CNN part and the parameter weights of the linear embedding layer of the SwinT part in the pre-trained CNN-SwinT hybrid model, and the parameter weights of the multi-layer perceptron layer composed of a fully connected layer and a softmax activation function, and freeze the parameter weights of the SwinT coding block and the block merging layer of the SwinT part;
[0061] A historical attack probability prediction submodule, used for inputting the vehicle historical CAN bus image data into the CNN-SwinT hybrid model, and outputting probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model;
[0062] The weight iterative optimization submodule is used to iteratively optimize the parameter weights of the CNN part and the parameter weights of the linear embedding layer of the SwinT part in the CNN-SwinT hybrid model, and the parameter weights of the multi-layer perceptron layer composed of a fully connected layer and a softmax activation function according to the probability value label of each attack type and the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model, so as to obtain the vehicle CAN bus intrusion detection model.
[0063] Optionally, the historical attack probability prediction submodule includes:
[0064] A historical image feature map generating unit, used for inputting the vehicle historical CAN bus image data into the CNN-SwinT hybrid model, wherein the CNN-SwinT hybrid model extracts features of the vehicle historical CAN bus data from the vehicle historical CAN bus image data to obtain an image feature map of the vehicle historical CAN bus data;
[0065] The historical attack probability prediction unit is used to classify the image feature map of the vehicle's historical CAN bus data and output the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model.
[0066] The present invention also discloses an electronic device, comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus;
[0067] The memory is used to store computer programs;
[0068] The processor is used to implement the vehicle CAN bus intrusion detection method as described in the present invention when executing the program stored in the memory.
[0069] The present invention also discloses one or more computer-readable media on which instructions are stored. When executed by one or more processors, the processors execute the vehicle CAN bus intrusion detection method as described in the present invention.
[0070] The present invention includes the following advantages:
[0071] The vehicle CAN bus intrusion detection method of the present invention collects the real-time CAN bus data of the vehicle, converts the real-time CAN bus data of the vehicle into a red, green and blue three-channel image, obtains the real-time CAN bus image data of the vehicle, inputs the real-time CAN bus image data of the vehicle into the vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model outputs the probability values of various vehicle CAN bus attack types, and the vehicle CAN bus attack types include denial of service attack, fuzzy attack, impersonation attack, and no attack state. If the probability value of the no attack state is less than a preset safety threshold, the vehicle is determined to be invaded. The vehicle CAN bus intrusion detection model of the present invention is based on the CNN-SwinT hybrid model, and is trained using a transfer learning method. In the case of insufficient vehicle CAN bus intrusion data, the speed of model training and the accuracy of detection can be significantly improved, so that after obtaining the real-time CAN bus data of the vehicle, the temporal and spatial characteristics of the vehicle CAN bus data can be learned by combining transfer learning, CNN model and SwinT model, thereby realizing intrusion detection of the vehicle, and significantly improving the accuracy and efficiency of detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0072] Figure 1 It is a flow chart of the steps of a vehicle CAN bus intrusion detection method provided by an embodiment of the present invention;
[0073] Figure 2 It is a data processing flow chart of training a vehicle CAN bus intrusion detection model and applying a vehicle CAN bus intrusion detection model provided by an embodiment of the present invention;
[0074] Figure 3 It is a structural block diagram of a vehicle CAN bus intrusion detection method and device provided by an embodiment of the present invention;
[0075] Figure 4 is a block diagram of an electronic device provided by an embodiment of the present invention;
[0076] Figure 5 It is a schematic diagram of a computer-readable medium provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0077] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.
[0078] Reference Figure 1 , shows a flowchart of a method for generating user behavior tags based on a mini-program provided in an embodiment of the present invention, which may specifically include the following steps:
[0079] Step 101, collecting real-time CAN bus data of the vehicle;
[0080] The vehicle CAN bus intrusion detection model provided by the present invention can process the vehicle CAN bus data collected in real time and capture the data sequence context information. When the vehicle CAN bus data is pre-processed and input into the model, it can be determined whether the vehicle is invaded according to the output result of the model, thereby realizing intrusion detection of the vehicle status and significantly improving the accuracy and efficiency of detection.
[0081] For the collection of real-time CAN bus data of vehicles, a CAN bus adapter can be used to connect to the host computer software through the serial port. The host computer software can receive and display the data on the CAN bus in real time, and can also provide data storage, analysis, processing and other functions. In this way, real-time monitoring of the vehicle CAN bus can be achieved, and the real-time CAN bus data of the vehicle can be collected.
[0082] After obtaining the real-time CAN bus data of the vehicle, the obtained vehicle CAN bus data can be divided into 30 sequences. If the data is divided into several groups and the remaining data is less than 30, the remaining data is repeated until it reaches 30. Then, each group of data is subjected to robust normalization and maximum-minimum normalization to obtain the normalized real-time CAN bus data of the vehicle.
[0083] Specifically, each set of data is first subjected to robust normalization and then maximum and minimum normalization is applied. Robust normalization uses the median and interquartile range in the data to scale the data to reduce the impact of outliers in the data on the scaling results. Maximum and minimum normalization scales the robustly normalized data to the interval [0,1].
[0084] The formula for robust normalization is as follows:
[0085]
[0086] Among them, M is the input raw data; Median(M) is the median of the data; IQR is the four-digit range of the data, usually the difference between the 75th percentile and the 25th percentile of the data. The maximum and minimum normalization formulas are as follows:
[0087]
[0088] Among them, Mrobust is the data after robust normalization; min means taking the minimum value of the data in the data set; max means taking the maximum value of the data in the data set; Mscaled means the output result after maximum and minimum normalization.
[0089] Step 102, converting the real-time CAN bus data of the vehicle into a red, green and blue three-channel image to obtain the real-time CAN bus image data of the vehicle;
[0090] After completing the normalization of the real-time CAN bus data of the vehicle, the normalized sequence data can be converted into an image according to the number of features in the data set. The specific conversion method is: multiply each group of normalized data by 255, scale it to the interval [0,255], and then convert each group of sequence data into a red, green and blue three-channel image to obtain the real-time CAN bus image data of the vehicle.
[0091] Since each sequence data in the normalized dataset has M features, 3M continuous sequence data are taken, and the ToPILImage function in the torchvision library of PyTorch is used to convert the 3M continuous sequence data into an image of size M*M*3 with three channels of red, green and blue to obtain the real-time CAN bus image data of the vehicle. After converting the real-time CAN bus data of the vehicle into an image, the vehicle CAN bus intrusion detection model can quickly process a large amount of data, and intuitively observe the changes and anomalies of the data, which is convenient for discovering abnormal messages and identifying attacks, improving detection efficiency, and helping to better discover vehicle network intrusions and attacks.
[0092] Step 103, inputting the real-time CAN bus image data of the vehicle into a vehicle CAN bus intrusion detection model, wherein the vehicle CAN bus intrusion detection model outputs probability values of various vehicle CAN bus attack types; the vehicle CAN bus attack types include denial of service attack, fuzzy attack, impersonation attack, and no attack state;
[0093] After obtaining the vehicle's real-time CAN bus image data, the vehicle's real-time CAN bus image data can be input into the vehicle's CAN bus intrusion detection model. The vehicle's CAN bus intrusion detection model can process the vehicle's real-time CAN bus image data and directly output probability values of various vehicle CAN bus attack types. These probability values represent the probability of each attack type existing in the vehicle's real-time CAN bus data, thereby realizing intrusion detection of the vehicle's status and significantly improving the accuracy and efficiency of detection.
[0094] Among them, the vehicle CAN bus attack type may include denial of service attack, fuzzy attack, impersonation attack, and no attack state. There may also be other attack types according to actual conditions, and the present invention does not limit this.
[0095] In one embodiment of the present invention, the real-time CAN bus image data of the vehicle is input into a vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model outputs probability values of various vehicle CAN bus attack types, including:
[0096] The vehicle real-time CAN bus image data is input into the vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model extracts the features of the vehicle real-time CAN bus data from the vehicle real-time CAN bus image data to generate an image feature map of the vehicle real-time CAN bus data;
[0097] The image feature graph of the real-time CAN bus data of the vehicle is classified and processed, and probability values of various vehicle CAN bus attack types are output.
[0098] The vehicle CAN bus intrusion detection model of the present invention may include a CNN part, a SwinT part, and a multi-layer perceptron layer composed of a fully connected layer and a softmax activation function. The CNN part is used to extract the features of the image and output an image feature map, the SwinT part is used to classify the image feature map, and the multi-layer perceptron layer is used to output the classification result of the SwinT part. After the vehicle real-time CAN bus image data is input into the vehicle CAN bus intrusion detection model, the CNN part of the vehicle CAN bus intrusion detection model extracts the features of the vehicle real-time CAN bus data from the vehicle real-time CAN bus image data, generates an image feature map of the vehicle real-time CAN bus data, and then the SwinT part of the vehicle CAN bus intrusion detection model classifies the image feature map of the vehicle real-time CAN bus data, and then finely adjusts the classification result through the multi-layer perceptron layer, and outputs the probability values of various vehicle CAN bus attack types. In general, by combining the multi-level feature extraction and classification processing of CNN and SwinT, and the fine adjustment of the multi-layer perceptron layer, the vehicle CAN bus intrusion detection model can detect the intrusion behavior in the vehicle network more accurately and efficiently, and provide strong support for ensuring vehicle safety.
[0099] In one embodiment of the present invention, the vehicle real-time CAN bus image data is input into the vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model extracts features of the vehicle real-time CAN bus data from the vehicle real-time CAN bus image data to generate an image feature map of the vehicle real-time CAN bus data, including:
[0100] The real-time CAN bus image data of the vehicle is input into the vehicle CAN bus intrusion detection model, and the first convolution layer of the vehicle CAN bus intrusion detection model performs a convolution operation on the real-time CAN bus image data of the vehicle, extracts features of the real-time CAN bus data of the vehicle and adjusts the number of channels of the image feature map;
[0101] The first batch normalization layer of the vehicle CAN bus intrusion detection model normalizes the features of the vehicle real-time CAN bus data, and the first maximum pooling layer of the vehicle CAN bus intrusion detection model compresses the normalized features to obtain an initial image feature map of the vehicle real-time CAN bus data;
[0102] The second convolution layer of the vehicle CAN bus intrusion detection model performs a convolution operation on the initial image feature map to extract low-dimensional features of the vehicle real-time CAN bus data and adjust the number of image feature map channels;
[0103] The second batch normalization layer of the vehicle CAN bus intrusion detection model normalizes the low-dimensional features of the vehicle's real-time CAN bus data, and the second maximum pooling layer of the vehicle CAN bus intrusion detection model compresses the normalized low-dimensional features to obtain an image feature map of the vehicle's real-time CAN bus data.
[0104] The CNN part in the present invention is only used to extract image features and does not need to output results, so its structure is: 3*3 convolution layer, batch normalization layer, maximum pooling layer, 1*1 convolution layer, batch normalization layer, maximum pooling layer, and its final output is a three-channel image feature map. The convolution layer is used to extract the features of the input image and change the number of channels of the feature map to achieve the purpose of finally outputting a three-channel feature map; the batch normalization layer can increase the speed of model training and reduce the risk of model overfitting; the maximum pooling layer compresses the extracted image features and reduces the amount of calculation in model training.
[0105] Specifically, the real-time CAN bus image data of the vehicle is input into the vehicle CAN bus intrusion detection model, the first convolution layer of the vehicle CAN bus intrusion detection model performs convolution operation on the real-time CAN bus image data of the vehicle, extracts the features of the real-time CAN bus data of the vehicle and adjusts the number of channels of the image feature map, the first batch normalization layer of the vehicle CAN bus intrusion detection model normalizes the features of the real-time CAN bus data of the vehicle, and the first maximum pooling layer of the vehicle CAN bus intrusion detection model compresses the normalized features to obtain the initial image feature map of the real-time CAN bus data of the vehicle. Then, the second convolution layer of the vehicle CAN bus intrusion detection model performs convolution operation on the initial image feature map, extracts the low-dimensional features of the real-time CAN bus data of the vehicle and adjusts the number of channels of the image feature map, the second batch normalization layer of the vehicle CAN bus intrusion detection model normalizes the low-dimensional features of the real-time CAN bus data of the vehicle, and the second maximum pooling layer of the vehicle CAN bus intrusion detection model compresses the normalized low-dimensional features to obtain the image feature map of the real-time CAN bus data of the vehicle.
[0106] In one embodiment of the present invention, the image feature graph of the real-time CAN bus data of the vehicle is classified and processed, and the probability values of various vehicle CAN bus attack types are output, including:
[0107] The vehicle CAN bus intrusion detection model performs block partitioning on the image feature map to obtain a plurality of feature regions of the same size and without overlapping each other;
[0108] Flattening the feature region and inputting it into the linear embedding layer of the vehicle CAN bus intrusion detection model for conversion to obtain a feature region code;
[0109] Inputting the characteristic region code into a plurality of SwinT encoding blocks of the vehicle CAN bus intrusion detection model;
[0110] The SwinT encoding block calculates the self-attention weight of the feature region code and performs weighted processing on the feature region code according to the self-attention weight to obtain a self-attention feature map; a block merging layer is set in the middle of the SwinT encoding block to merge the output of the SwinT encoding block;
[0111] The self-attention feature map output by the last SwinT encoding block is input into a multi-layer perceptron layer consisting of a fully connected layer and a softmax activation function, which outputs probability values of various vehicle CAN bus attack types.
[0112] In the present invention, the SwinT part of the vehicle CAN bus intrusion detection model classifies and processes the image feature map of the vehicle real-time CAN bus data. First, the image feature map can be partitioned into blocks to obtain multiple feature regions of the same size and non-overlapping. The obtained feature regions are flattened and input into the linear embedding layer for transformation. The linear embedding will project each flattened feature region onto an arbitrary dimension C to obtain a feature region code token. The feature region code token is then input into four SwinT encoding blocks. The SwinT encoding block calculates the self-attention weight of the feature region code and performs weighted processing on the feature region code according to the self-attention weight to obtain a self-attention feature map. The block merging layer after each encoding block merges the output of the SwinT block to achieve communication between different windows. The output of the last SwinT encoding block is connected to a multi-layer perceptron layer composed of a fully connected layer and a softmax activation function. The multi-layer perceptron layer processes the self-attention feature map and outputs the probability values of various vehicle CAN bus attack types.
[0113] Step 104: If the probability value of the non-attack state is less than a preset safety threshold, it is determined that the vehicle has been invaded.
[0114] After obtaining the probability value of each attack type in the real-time CAN bus data of the vehicle, it is possible to determine whether the probability value of the non-attack state meets the safety conditions. If it meets the safety conditions, the vehicle is in a safe state; if it does not meet the safety conditions, the vehicle may be invaded and is in an unsafe state. Specifically, it is possible to determine whether the probability value of the non-attack state is less than a preset safety threshold. If it is determined that the probability value of the non-attack state is less than the preset safety threshold, it can be determined that the vehicle has been invaded, and then an alarm can be issued to the driver or relevant personnel to take safety control measures to ensure the safe operation of the vehicle. Among them, the preset safety threshold can be set according to actual safety requirements, such as 0.6, 0.5, 0.7, etc.
[0115] In one embodiment of the present invention, the generation of the vehicle CAN bus intrusion detection model includes:
[0116] Acquire historical CAN bus data of the vehicle; the historical CAN bus data of the vehicle includes messages of multiple attack types and probability value labels of each attack type; the messages of the multiple attack types include denial of service attack messages, fuzzy attack messages, impersonation attack messages, and no attack status messages;
[0117] Convert the vehicle historical CAN bus data into a red, green and blue three-channel image to obtain the vehicle historical CAN bus image data;
[0118] The vehicle historical CAN bus image data is used to train the pre-trained CNN-SwinT hybrid model to obtain the vehicle CAN bus intrusion detection model.
[0119] In one embodiment of the present invention, the pre-trained CNN-SwinT hybrid model is trained using the historical CAN bus image data of the vehicle to obtain the vehicle CAN bus intrusion detection model, including:
[0120] Initialize the parameter weights of the CNN part and the parameter weights of the linear embedding layer of the SwinT part in the pre-trained CNN-SwinT hybrid model, as well as the parameter weights of the multi-layer perceptron layer composed of a fully connected layer and a softmax activation function, and freeze the parameter weights of the SwinT coding block and the block merging layer of the SwinT part;
[0121] Input the vehicle historical CAN bus image data into the CNN-SwinT hybrid model, and output probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model;
[0122] According to the probability value label of each attack type and the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model, the parameter weights of the CNN part and the parameter weights of the linear embedding layer of the SwinT part in the CNN-SwinT hybrid model, as well as the parameter weights of the multi-layer perceptron layer composed of a fully connected layer and a softmax activation function are iteratively optimized to obtain the vehicle CAN bus intrusion detection model.
[0123] In one embodiment of the present invention, the vehicle historical CAN bus image data is input into the CNN-SwinT hybrid model, and the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model are output, including:
[0124] Inputting the vehicle historical CAN bus image data into the CNN-SwinT hybrid model, the CNN-SwinT hybrid model extracting features of the vehicle historical CAN bus data from the vehicle historical CAN bus image data to obtain an image feature map of the vehicle historical CAN bus data;
[0125] The image feature graph of the vehicle historical CAN bus data is classified and processed, and the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model are output.
[0126] For the training of the CNN-SwinT hybrid model, the present invention uses CNN to first extract the low-dimensional features of the image, then divides the extracted low-dimensional features into blocks, and uses the transfer learning method to input the divided low-dimensional features into the improved SwinT model for model fine-tuning to obtain a vehicle CAN bus intrusion detection model.
[0127] Specifically, the historical CAN bus data of the vehicle is first obtained. The present invention uses the CAN-intrusion-dataset dataset released by HCR Laboratory as the historical CAN bus data of the vehicle. The dataset includes denial of service attack messages, fuzzy attack messages, impersonation attack messages, and no attack status messages. The specific number of messages in the dataset is shown in Table 1:
[0128] Table 1 Attack types and message counts in the CAN-intrusion-dataset dataset
[0129]
[0130] The vehicle historical CAN bus data can also include a probability value label for each attack type. The probability value label for each attack type is calculated and marked by the number of messages of each attack type in the vehicle historical CAN bus data. Then, the obtained vehicle historical CAN bus data can be preprocessed. The vehicle historical CAN bus data is first robustly normalized and then maximum and minimum normalization is applied. Robust normalization uses the median and quartile range in the data to scale the data to reduce the impact of outliers in the data on the scaling results. Maximum and minimum normalization scales the robustly normalized data to the [0,1] interval.
[0131] The formula for robust normalization is as follows:
[0132]
[0133] Among them, M is the input raw data; Median(M) is the median of the data; IQR is the four-digit range of the data, usually the difference between the 75th percentile and the 25th percentile of the data. The maximum and minimum normalization formulas are as follows:
[0134]
[0135] Among them, Mrobust is the data after robust normalization; min means taking the minimum value of the data in the data set; max means taking the maximum value of the data in the data set; Mscaled means the output result after maximum and minimum normalization.
[0136] The normalized sequence data is converted into an image according to the number of features in the data set. The specific conversion method is as follows: first multiply the normalized data by 255. Since each sequence data in the data set has M features, 3M continuous sequence data are taken, and the ToPILImage function in the torchvision library of PyTorch is used to convert the 3M continuous sequence data into a red, green and blue three-channel image of size M*M*3 to obtain the vehicle historical CAN bus image data.
[0137] The historical CAN bus image data of the vehicle can be used to train the CNN-SwinT hybrid model. The CNN part of the model is used to extract the features of the image and output the image feature map, and the SwinT part is used to classify the image feature map.
[0138] When training the CNN-SwinT hybrid model, the parameter weights of the CNN part and the linear embedding layer of the SwinT part in the pre-trained CNN-SwinT hybrid model, as well as the parameter weights of the multi-layer perceptron layer composed of a fully connected layer and a softmax activation function can be initialized first, and the parameter weights of the SwinT encoding block and the block merging layer of the SwinT part can be frozen.
[0139] In the present invention, CNN is only used to extract image features and does not need to output results, so its structure is: 3*3 convolution layer, batch normalization layer, maximum pooling layer, 1*1 convolution layer, batch normalization layer, maximum pooling layer, and its final output is a three-channel image feature map. The convolution layer is used to extract the features of the input image and change the number of channels of the feature map to achieve the purpose of finally outputting the three-channel feature map; the batch normalization layer can increase the speed of model training and reduce the risk of model overfitting; the maximum pooling layer compresses the extracted image features and reduces the amount of calculation in model training. The parameters of the convolution layer, batch normalization layer and maximum pooling layer are all learnable.
[0140] The convolutional layer formula is as follows:
[0141]
[0142] Among them, P represents the output image matrix after the convolution operation; F represents the input image matrix; K represents the convolution kernel; ∑m,n means that the feature map P can be obtained by traversing and summing F using the convolution kernel.
[0143] The batch normalization layer formula is as follows:
[0144]
[0145] Among them, m represents the number of image matrices input in a batch; x represents the input image matrix, and u represents the mean of all image matrices in a batch.
[0146]
[0147] in, Represents the variance of all image matrices in a batch.
[0148]
[0149] in, Represents the normalized image matrix. q is a very small parameter used to ensure that the denominator is greater than 0.
[0150]
[0151] Among them, y i represents the output of xi after batch normalization; g i represents the scaling weight, and b represents the bias weight, both of which are trained weights.
[0152] The formula for the maximum pooling layer is as follows:
[0153]
[0154] Among them, H represents the input image matrix, O represents the output image matrix after maximum pooling; w represents the pooling size area, such as 2*2 or 4*4; s represents the number of steps the pooling window moves on the image matrix; a and b are the indices traversed in the window.
[0155] The image feature map output by the CNN part is partitioned into blocks, which will cut the image feature map into four feature regions of equal size but non-overlapping. The obtained feature regions are then flattened and input into the linear embedding layer for transformation. The linear embedding will project each flattened feature region onto an arbitrary dimension C to obtain the feature region code token.
[0156] Freeze the learnable weights of all layers except the linear embedding layer in the pre-trained SwinT model, and delete the classification head of SwinT. The encoder part in SwinT is composed of four repeatedly stacked SwinT encoding blocks, and there is a block merging layer in the middle of each of the four SwinT encoding blocks. Each SwinT encoding block consists of two sublayers. The first sublayer includes layer normalization and window self-attention layer, and the second sublayer includes layer normalization and multi-layer perceptron layer. The window self-attention mechanism divides the input into multiple non-overlapping small windows and performs self-attention calculation in each small window; the block merging layer merges the output of the SwinT encoding block to achieve communication between different windows.
[0157] The formula for calculating self-attention within a small window is as follows:
[0158]
[0159] Among them, B represents the relative position encoding of each small window; Q represents query, K represents key, and V represents value. These four parameters are obtained through pre-training; the value of di is the dimension size of Q / K; Softmax is an activation function used to output probability.
[0160] The feature region code token is input into four SwinT encoding blocks. The SwinT encoding block calculates the self-attention weight of the feature region code and performs weighted processing on the feature region code according to the self-attention weight to obtain a self-attention feature map. The block merging layer after each encoding block merges the output of the SwinT block to achieve communication between different windows. A multi-layer perceptron layer consisting of a fully connected layer and a softmax activation function is constructed in the CNN-SwinT hybrid model, which is connected to the last SwinT encoding block, so that the category probability predicted by the CNN-SwinT hybrid model can be output.
[0161] According to the probability value label of each attack type and the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model, the parameter weights of the CNN part and the linear embedding layer of the SwinT part in the CNN-SwinT hybrid model, as well as the parameter weights of the multi-layer perceptron layer composed of the fully connected layer and the softmax activation function are iteratively optimized to train the vehicle CAN bus intrusion detection model. Figure 2 , which is a data processing flow chart for training a vehicle CAN bus intrusion detection model and applying a vehicle CAN bus intrusion detection model provided in an embodiment of the present invention.
[0162] By deploying the trained vehicle CAN bus intrusion detection model to the vehicle CAN bus, the vehicle CAN bus data can be obtained in real time for intrusion judgment. The vehicle CAN bus can be monitored through the vehicle CAN bus intrusion detection model, and an alarm can be issued when the CAN bus is invaded.
[0163] In an embodiment of the present invention, by collecting real-time CAN bus data of a vehicle, converting the real-time CAN bus data of the vehicle into a red, green and blue three-channel image, obtaining real-time CAN bus image data of the vehicle, inputting the real-time CAN bus image data of the vehicle into a vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model outputs probability values of various vehicle CAN bus attack types, and the vehicle CAN bus attack types include denial of service attack, fuzzy attack, impersonation attack, and no attack state. If the probability value of the no attack state is less than a preset safety threshold, the vehicle is determined to be invaded. The vehicle CAN bus intrusion detection model of the present invention is based on a CNN-SwinT hybrid model, and is trained using a transfer learning method. In the case of insufficient vehicle CAN bus intrusion data, the speed of model training and the accuracy of detection can be significantly improved, so that after obtaining the real-time CAN bus data of the vehicle, the temporal and spatial characteristics of the vehicle CAN bus data can be learned by combining transfer learning, CNN model and SwinT model, thereby realizing intrusion detection of the vehicle state, and significantly improving the accuracy and efficiency of detection.
[0164] It should be noted that, for the sake of simplicity, the method embodiments are described as a series of action combinations, but those skilled in the art should be aware that the embodiments of the present invention are not limited by the order of the actions described, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present invention.
[0165] Reference Figure 3 , shows a structural block diagram of a vehicle CAN bus intrusion detection device provided in an embodiment of the present invention, which may specifically include the following modules:
[0166] A real-time CAN bus data acquisition module 301 is used to collect real-time CAN bus data of the vehicle;
[0167] The first image conversion module 302 is used to convert the real-time CAN bus data of the vehicle into a red, green and blue three-channel image to obtain the real-time CAN bus image data of the vehicle;
[0168] A real-time attack probability prediction module 303 is used to input the real-time vehicle CAN bus image data into a vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model outputs probability values of various vehicle CAN bus attack types; the vehicle CAN bus attack types include denial of service attack, fuzzy attack, impersonation attack, and no attack state;
[0169] The attack determination module 304 is configured to determine that the vehicle has been invaded if the probability value of the non-attack state is less than a preset safety threshold.
[0170] Optionally, the real-time attack probability prediction module includes:
[0171] A real-time image feature map generating submodule, used for inputting the real-time CAN bus image data of the vehicle into the vehicle CAN bus intrusion detection model, wherein the vehicle CAN bus intrusion detection model extracts features of the real-time CAN bus data of the vehicle from the real-time CAN bus image data of the vehicle, and generates an image feature map of the real-time CAN bus data of the vehicle;
[0172] The real-time attack probability prediction submodule is used to classify the image feature map of the real-time CAN bus data of the vehicle and output the probability values of various vehicle CAN bus attack types.
[0173] Optionally, the real-time image feature map generating submodule includes:
[0174] A first convolution unit is used to input the real-time CAN bus image data of the vehicle into the vehicle CAN bus intrusion detection model, and the first convolution layer of the vehicle CAN bus intrusion detection model performs a convolution operation on the real-time CAN bus image data of the vehicle, extracts features of the real-time CAN bus data of the vehicle, and adjusts the number of channels of the image feature map;
[0175] A first normalization and compression unit, used for the first batch normalization layer of the vehicle CAN bus intrusion detection model to normalize the features of the vehicle real-time CAN bus data, and the first maximum pooling layer of the vehicle CAN bus intrusion detection model to compress the normalized features to obtain an initial image feature map of the vehicle real-time CAN bus data;
[0176] A second convolution unit, used for the second convolution layer of the vehicle CAN bus intrusion detection model to perform a convolution operation on the initial image feature map, extract low-dimensional features of the vehicle real-time CAN bus data and adjust the number of image feature map channels;
[0177] The second normalization and compression unit is used for the second batch normalization layer of the vehicle CAN bus intrusion detection model to normalize the low-dimensional features of the vehicle real-time CAN bus data, and the second maximum pooling layer of the vehicle CAN bus intrusion detection model to compress the normalized low-dimensional features to obtain an image feature map of the vehicle real-time CAN bus data.
[0178] Optionally, the real-time attack probability prediction submodule includes:
[0179] A partitioning unit, used for the vehicle CAN bus intrusion detection model to perform block partitioning on the image feature map to obtain a plurality of feature regions of the same size and non-overlapping;
[0180] A feature region code generating unit, used for flattening the feature region and inputting the flattened feature region into the linear embedding layer of the vehicle CAN bus intrusion detection model for conversion to obtain a feature region code;
[0181] An input unit, used for inputting the characteristic area code into a plurality of SwinT encoding blocks of the vehicle CAN bus intrusion detection model;
[0182] A self-attention feature map generating unit, which is used for the SwinT encoding block to calculate the self-attention weight of the feature region code and perform weighted processing on the feature region code according to the self-attention weight to obtain a self-attention feature map; a block merging layer is provided in the middle of the SwinT encoding block, which is used to merge the output of the SwinT encoding block;
[0183] The real-time attack probability prediction unit is used to input the self-attention feature map output by the last SwinT encoding block into a multi-layer perceptron layer composed of a fully connected layer and a softmax activation function, and the multi-layer perceptron layer outputs probability values of various vehicle CAN bus attack types.
[0184] Optionally, the device comprises:
[0185] A historical CAN bus data acquisition module is used to acquire historical CAN bus data of the vehicle; the historical CAN bus data of the vehicle includes messages of multiple attack types and probability value labels of each attack type; the messages of multiple attack types include denial of service attack messages, fuzzy attack messages, impersonation attack messages, and no attack status messages;
[0186] A second image conversion module is used to convert the vehicle historical CAN bus data into a red, green and blue three-channel image to obtain the vehicle historical CAN bus image data;
[0187] The model training module is used to train the pre-trained CNN-SwinT hybrid model using the historical CAN bus image data of the vehicle to obtain the vehicle CAN bus intrusion detection model.
[0188] Optionally, the model training module includes:
[0189] A weight freezing and initialization submodule, used to initialize the parameter weights of the CNN part and the parameter weights of the linear embedding layer of the SwinT part in the pre-trained CNN-SwinT hybrid model, and the parameter weights of the multi-layer perceptron layer composed of a fully connected layer and a softmax activation function, and freeze the parameter weights of the SwinT coding block and the block merging layer of the SwinT part;
[0190] A historical attack probability prediction submodule, used for inputting the vehicle historical CAN bus image data into the CNN-SwinT hybrid model, and outputting probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model;
[0191] The weight iterative optimization submodule is used to iteratively optimize the parameter weights of the CNN part and the parameter weights of the linear embedding layer of the SwinT part in the CNN-SwinT hybrid model, and the parameter weights of the multi-layer perceptron layer composed of a fully connected layer and a softmax activation function according to the probability value label of each attack type and the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model, so as to obtain the vehicle CAN bus intrusion detection model.
[0192] Optionally, the historical attack probability prediction submodule includes:
[0193] A historical image feature map generating unit, used for inputting the vehicle historical CAN bus image data into the CNN-SwinT hybrid model, wherein the CNN-SwinT hybrid model extracts features of the vehicle historical CAN bus data from the vehicle historical CAN bus image data to obtain an image feature map of the vehicle historical CAN bus data;
[0194] The historical attack probability prediction unit is used to classify the image feature map of the vehicle's historical CAN bus data and output the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model.
[0195] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0196] In addition, an embodiment of the present invention further provides an electronic device, such as Figure 4 As shown, it includes a processor 401, a communication interface 402, a memory 403 and a communication bus 404, wherein the processor 401, the communication interface 402, and the memory 403 communicate with each other through the communication bus 404.
[0197] Memory 403, used for storing computer programs;
[0198] The processor 401 is used to implement the vehicle CAN bus intrusion detection method described in the above embodiment when executing the program stored in the memory 403.
[0199] The communication bus mentioned in the above terminal can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0200] The communication interface is used for communication between the above terminal and other devices.
[0201] The memory may include a random access memory (RAM) or a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.
[0202] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0203] like Figure 5As shown, in another embodiment provided by the present invention, a computer-readable storage medium 501 is also provided, in which instructions are stored. When the computer-readable storage medium 501 is run on a computer, the computer executes the vehicle CAN bus intrusion detection method described in the above embodiment.
[0204] In another embodiment provided by the present invention, a computer program product including instructions is also provided, which, when executed on a computer, enables the computer to execute the vehicle CAN bus intrusion detection method described in the above embodiment.
[0205] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented by software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present invention is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk Solid State Disk (SSD)), etc.
[0206] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
[0207] Each embodiment in this specification is described in a related manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0208] The above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention are included in the protection scope of the present invention.
Claims
1. A vehicle CAN bus intrusion detection method, characterized in that: The method comprises: Collect real-time CAN bus data of vehicles; Convert the real-time CAN bus data of the vehicle into a red, green and blue three-channel image to obtain the real-time CAN bus image data of the vehicle; The real-time CAN bus image data of the vehicle is input into a vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model outputs probability values of various vehicle CAN bus attack types; the vehicle CAN bus attack types include denial of service attack, fuzzy attack, impersonation attack, and no attack state; If the probability value of the non-attack state is less than a preset safety threshold, it is determined that the vehicle has been invaded; The generation of the vehicle CAN bus intrusion detection model includes: Acquire historical CAN bus data of the vehicle; the historical CAN bus data of the vehicle includes messages of multiple attack types and probability value labels of each attack type; the messages of the multiple attack types include denial of service attack messages, fuzzy attack messages, impersonation attack messages, and no attack status messages; Convert the vehicle historical CAN bus data into a red, green and blue three-channel image to obtain the vehicle historical CAN bus image data; The vehicle historical CAN bus image data is used to train the pre-trained CNN-SwinT hybrid model to obtain the vehicle CAN bus intrusion detection model; The pre-trained CNN-SwinT hybrid model is trained using the vehicle historical CAN bus image data to obtain the vehicle CAN bus intrusion detection model, including: Initialize the parameter weights of the CNN part and the parameter weights of the linear embedding layer of the SwinT part in the pre-trained CNN-SwinT hybrid model, as well as the parameter weights of the multi-layer perceptron layer composed of a fully connected layer and a softmax activation function, and freeze the parameter weights of the SwinT coding block and the block merging layer of the SwinT part; Input the vehicle historical CAN bus image data into the CNN-SwinT hybrid model, and output probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model; According to the probability value label of each attack type and the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model, iteratively optimize the parameter weights of the CNN part and the parameter weights of the linear embedding layer of the SwinT part in the CNN-SwinT hybrid model, and the parameter weights of the multi-layer perceptron layer composed of a fully connected layer and a softmax activation function, to obtain the vehicle CAN bus intrusion detection model; The vehicle historical CAN bus image data is input into the CNN-SwinT hybrid model, and the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model are output, including: Inputting the vehicle historical CAN bus image data into the CNN-SwinT hybrid model, the CNN-SwinT hybrid model extracting features of the vehicle historical CAN bus data from the vehicle historical CAN bus image data to obtain an image feature map of the vehicle historical CAN bus data; The image feature graph of the vehicle historical CAN bus data is classified and processed, and the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model are output.
2. The method according to claim 1, characterized in that The real-time vehicle CAN bus image data is input into a vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model outputs probability values of various vehicle CAN bus attack types, including: The vehicle real-time CAN bus image data is input into the vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model extracts the features of the vehicle real-time CAN bus data from the vehicle real-time CAN bus image data to generate an image feature map of the vehicle real-time CAN bus data; The image feature graph of the real-time CAN bus data of the vehicle is classified and processed, and probability values of various vehicle CAN bus attack types are output.
3. The method according to claim 2, characterized in that Inputting the vehicle real-time CAN bus image data into the vehicle CAN bus intrusion detection model, the vehicle CAN bus intrusion detection model extracting features of the vehicle real-time CAN bus data from the vehicle real-time CAN bus image data, and generating an image feature map of the vehicle real-time CAN bus data, including: The real-time CAN bus image data of the vehicle is input into the vehicle CAN bus intrusion detection model, and the first convolution layer of the vehicle CAN bus intrusion detection model performs a convolution operation on the real-time CAN bus image data of the vehicle, extracts features of the real-time CAN bus data of the vehicle and adjusts the number of channels of the image feature map; The first batch normalization layer of the vehicle CAN bus intrusion detection model normalizes the features of the vehicle real-time CAN bus data, and the first maximum pooling layer of the vehicle CAN bus intrusion detection model compresses the normalized features to obtain an initial image feature map of the vehicle real-time CAN bus data; The second convolution layer of the vehicle CAN bus intrusion detection model performs a convolution operation on the initial image feature map to extract low-dimensional features of the vehicle real-time CAN bus data and adjust the number of image feature map channels; The second batch normalization layer of the vehicle CAN bus intrusion detection model normalizes the low-dimensional features of the vehicle's real-time CAN bus data, and the second maximum pooling layer of the vehicle CAN bus intrusion detection model compresses the normalized low-dimensional features to obtain an image feature map of the vehicle's real-time CAN bus data.
4. The method according to claim 2, characterized in that: The image feature graph of the real-time CAN bus data of the vehicle is classified and processed, and probability values of various types of vehicle CAN bus attacks are output, including: The vehicle CAN bus intrusion detection model performs block partitioning on the image feature map to obtain a plurality of feature regions of the same size and without overlapping each other; Flattening the feature region and inputting it into the linear embedding layer of the vehicle CAN bus intrusion detection model for conversion to obtain a feature region code; Inputting the characteristic region code into a plurality of SwinT encoding blocks of the vehicle CAN bus intrusion detection model; The SwinT encoding block calculates the self-attention weight of the feature region code and performs weighted processing on the feature region code according to the self-attention weight to obtain a self-attention feature map; a block merging layer is set in the middle of the SwinT encoding block to merge the output of the SwinT encoding block; The self-attention feature map output by the last SwinT encoding block is input into a multi-layer perceptron layer consisting of a fully connected layer and a softmax activation function, which outputs probability values of various vehicle CAN bus attack types.
5. A vehicle CAN bus intrusion detection device, characterized in that: The device comprises: Real-time CAN bus data acquisition module, used to collect real-time CAN bus data of vehicles; A first image conversion module is used to convert the real-time CAN bus data of the vehicle into a red, green and blue three-channel image to obtain the real-time CAN bus image data of the vehicle; A real-time attack probability prediction module is used to input the real-time CAN bus image data of the vehicle into a vehicle CAN bus intrusion detection model, and the vehicle CAN bus intrusion detection model outputs probability values of various vehicle CAN bus attack types; the vehicle CAN bus attack types include denial of service attack, fuzzy attack, impersonation attack, and no attack state; An attack determination module, configured to determine that the vehicle is invaded if the probability value of the non-attack state is less than a preset safety threshold; The device also includes: A historical CAN bus data acquisition module is used to acquire historical CAN bus data of the vehicle; the historical CAN bus data of the vehicle includes messages of multiple attack types and probability value labels of each attack type; the messages of multiple attack types include denial of service attack messages, fuzzy attack messages, impersonation attack messages, and no attack status messages; A second image conversion module is used to convert the vehicle historical CAN bus data into a red, green and blue three-channel image to obtain the vehicle historical CAN bus image data; A model training module, used to train the pre-trained CNN-SwinT hybrid model using the historical CAN bus image data of the vehicle to obtain the vehicle CAN bus intrusion detection model; The model training module includes: A weight freezing and initialization submodule, used to initialize the parameter weights of the CNN part and the parameter weights of the linear embedding layer of the SwinT part in the pre-trained CNN-SwinT hybrid model, and the parameter weights of the multi-layer perceptron layer composed of a fully connected layer and a softmax activation function, and freeze the parameter weights of the SwinT coding block and the block merging layer of the SwinT part; A historical attack probability prediction submodule, used for inputting the vehicle historical CAN bus image data into the CNN-SwinT hybrid model, and outputting probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model; A weight iteration optimization submodule, for iteratively optimizing the parameter weights of the CNN part and the parameter weights of the linear embedding layer of the SwinT part in the CNN-SwinT hybrid model, and the parameter weights of the multi-layer perceptron layer composed of a fully connected layer and a softmax activation function according to the probability value label of each attack type and the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model, so as to obtain the vehicle CAN bus intrusion detection model; The historical attack probability prediction submodule includes: A historical image feature map generating unit, used for inputting the vehicle historical CAN bus image data into the CNN-SwinT hybrid model, wherein the CNN-SwinT hybrid model extracts features of the vehicle historical CAN bus data from the vehicle historical CAN bus image data to obtain an image feature map of the vehicle historical CAN bus data; The historical attack probability prediction unit is used to classify the image feature map of the vehicle's historical CAN bus data and output the probability values of various vehicle CAN bus attack types predicted by the CNN-SwinT hybrid model.
6. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; The memory is used to store computer programs; The processor is used to implement the vehicle CAN bus intrusion detection method as described in any one of claims 1-4 when executing the program stored in the memory.
7. One or more computer-readable media having instructions stored thereon, which, when executed by one or more processors, enable the processors to execute the vehicle CAN bus intrusion detection method as described in any one of claims 1-4.
Citation Information
Patent Citations
Vehicle bus attack detection method based on RGB image coding
CN113301020A