A Vehicle Internet of Things Intrusion Detection Method and System

By constructing a detection model including an embedded layer, a transformer encoder layer, a linear layer and a Softmax layer, the problem of the inability to identify message injection attacks in the prior art is solved, precise intrusion detection of the Internet of Vehicles network is realized, and the security of vehicle communication is improved.

CN119052796BActive Publication Date: 2025-05-27BEIJING WANGANXIN TECHNOLOGY CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411084205.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-08
Publication Date
2025-05-27
Estimated Expiration
2044-08-08

AI Technical Summary

Technical Problem

The existing Internet of Vehicle detection model cannot recognize message injection attacks, resulting in unsafe vehicle communications, and an urgent need for a method that can accurately detect intrusions.

Method used

Using a method of intrusion detection of vehicle network intrusion, a detection model including an embedding layer, a transformer encoder layer, a linear layer and a Softmax layer is constructed by obtaining a sequence of network traffic data of multiple consecutive historical moments. The model processes data through a multi-head attention mechanism and residual network and trains the model with cross-entropy loss to identify intrusions.

Benefits of technology

Accurate identification of known and unknown network attacks in the vehicle's external network is realized, and the security of vehicle communication is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119052796B_ABST
    Figure CN119052796B_ABST
Patent Text Reader

Abstract

The present invention discloses a vehicle networking intrusion detection method and system. The vehicle networking intrusion detection method includes: obtaining a plurality of sequences composed of vehicle networking network traffic data at multiple consecutive historical moments to form a training data set; constructing a detection model; training the detection model based on the training data set to obtain a trained detection model; obtaining the vehicle networking network traffic data of the current sequence of a target vehicle; and inputting the vehicle networking network traffic data of the current sequence into the trained detection model to obtain a detection result of whether there is an intrusion. The present invention learns the left and right contexts, detects known and unknown network attacks in the vehicle external network, and can accurately identify message injection attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of vehicle networking information security. Specifically, it relates to a vehicle networking intrusion detection method and system. Background Art

[0002] Due to more and more complex requirements, electronic control units are increasingly integrated into modern vehicle systems. However, the high connectivity between in-vehicle networks and external networks reduces the information security performance. Currently, the vehicle external network lacks encryption and authentication mechanisms, making vehicle-based communication insecure and vulnerable to various types of attacks. Since message injection attacks can change the order of vehicle networking network traffic data, and existing detection models cannot identify this type of attack, there is an urgent need for a detection model to achieve accurate intrusion detection and improve the security of vehicle communication. Summary of the Invention

[0003] The present invention is precisely proposed based on the above-mentioned needs of the prior art. The technical problem to be solved by the present invention is to provide a vehicle networking intrusion detection method and system to improve the intrusion detection ability.

[0004] To solve the above problems, the present invention is implemented by adopting the following technical solutions:

[0005] A method for intrusion detection in the Internet of Vehicles, the method comprising: obtaining a plurality of sequences composed of Internet of Vehicles network traffic data at a plurality of consecutive historical moments to form a training data set; constructing a detection model, the detection model including an embedding layer, a Transformer encoder layer, a linear layer, and a Softmax layer that sequentially perform data transmission, the Transformer encoder layer including a first sub-layer and a second sub-layer, the first sub-layer including a multi-head attention mechanism and a first residual network, the second sub-layer including a position feed-forward network and a second residual network; training the detection model based on the training data set to obtain a trained detection model, including: the input data passes through the embedding layer to output a total embedding, projecting each Internet of Vehicles network traffic data in the input data into a multi-dimensional space to obtain an identifier embedding; performing position encoding on the Internet of Vehicles network traffic data using a sine function to obtain a position embedding; based on the identifier embedding and the corresponding position embedding, obtaining a total embedding; inputting the total embedding into a plurality of Transformer encoder layers to obtain first data; inputting the first data into the linear layer to output second data; randomly replacing a proportion of the Internet of Vehicles network traffic data in the historical sequence and randomly masking the Internet of Vehicles network traffic data; inputting the second data corresponding to the masked Internet of Vehicles network traffic data into the Softmax layer to obtain the probability that each Internet of Vehicles network traffic data in the sequence belongs to the masked Internet of Vehicles network traffic data; training the detection model using cross-entropy loss to determine the trained detection model; obtaining the Internet of Vehicles network traffic data of the current sequence of the target vehicle; inputting the Internet of Vehicles network traffic data of the current sequence into the trained detection model to obtain a detection result of whether it is invaded.

[0006] Optionally, projecting each Internet of Vehicles network traffic data in the input data into a multi-dimensional space to obtain an identifier embedding, and its expression is: Where represents the identifier embedding of the Internet of Vehicles network traffic data ; represents the t-th Internet of Vehicles network traffic data in the j-th sequence, W e represents the first embedding weight matrix, and b e represents the first bias.

[0007] Optionally, based on the identifier embedding and the corresponding position embedding, obtaining a total embedding, and its expression is: Where represents the total embedding of the Internet of Vehicles network traffic data ; represents the position embedding of the Internet of Vehicles network traffic data .

[0008] Optionally, the processing of each transformer encoder layer includes: processing the data input to the transformer encoder layer using the multi-head self-attention mechanism to obtain attention values; processing the attention values using the first residual network to obtain first intermediate data; processing the first intermediate data using the position feed-forward network to obtain second intermediate data; processing the second intermediate data using the second residual network to obtain the output data of the current layer as the input to the next layer; and the output of the last transformer encoder layer is used as the first data.

[0009] Optionally, processing the data input to the transformer encoder layer using the multi-head self-attention mechanism to obtain attention values, and its expression is: Q (j,n,l) = X (j,l) W (Q,n) , K (j,n,l) = X (j,l) W (K,n) , V (j,n,l) = X (j,l) W (V,n) , where Q (j,n,l) is the query vector of the nth attention head corresponding to the vehicle networking network traffic data of the jth sequence of the lth transformer encoder layer, X (j,l) represents the input data corresponding to the vehicle networking network traffic data of the jth sequence of the lth transformer encoder layer, K (j,n,l) is the key vector of the nth attention head corresponding to the vehicle networking network traffic data of the jth sequence of the lth transformer encoder layer, V (j,n,l) is the value vector of the nth attention head corresponding to the vehicle networking network traffic data of the jth sequence of the lth transformer encoder layer, W (Q,n) represents the weight matrix of the query vector Q of the nth attention head, W (K,n) represents the weight matrix of the key vector K of the nth attention head, W (V ,n) represents the weight matrix of the value vector V of the nth attention head, represents the weighted sum of values of the nth attention head corresponding to the vehicle networking network traffic data of the jth sequence of the lth transformer encoder layer, σ represents the Softmax function, and d represents the dimension of the Q (j,l) , K (j,l) or V (j,l) vector.

[0010] Optionally, processing the first intermediate data using the position feed-forward network to obtain second intermediate data includes: z(E (j,l) ) = [W 1 E (j,l) + ⊙ W 2 , where z(E​(j,l) ) represents the second intermediate data corresponding to the vehicle network traffic data of the j-th sequence in the l-th transformer encoder layer, E (j,l) represents the first intermediate data corresponding to the vehicle network traffic data of the j-th sequence in the l-th transformer encoder layer, W 1 represents the first projection matrix, W 2 represents the second projection matrix, ⊙ represents the hadarmard product, + represents obtaining the maximum value of the elements.

[0011] Optionally, inputting the first data into a linear layer to output second data, including:

[0012] Wherein, represents the second data corresponding to the t-th vehicle network traffic data of the j-th sequence, W m represents the second embedding weight matrix, represents the first data corresponding to the t-th vehicle network traffic data of the j-th sequence, b m represents the second bias.

[0013] Optionally, inputting the second data corresponding to the masked vehicle network traffic data into a Softmax layer to obtain the probability distribution of the masked vehicle network traffic data at each position in the sequence, including: Wherein, represents the probability distribution of the u-th masked vehicle network traffic data of the j-th sequence at each position in the sequence, σ is the Softmax function, represents the second data corresponding to the u-th masked vehicle network traffic data of the j-th sequence, W c represents the third embedding weight matrix, b c represents the third bias.

[0014] Optionally, training a detection model using cross-entropy loss to determine the trained detection model, including: Wherein, represents the predicted value, represents the u-th masked vehicle network traffic data of the j-th sequence, I represents the number of sequences, R is the total number of masked masks in the j-th sequence, and N is the number of training samples.

[0015] A vehicle networking intrusion detection system, the system comprising: a first acquisition module, which acquires a plurality of sequences composed of vehicle networking network traffic data at a plurality of consecutive historical moments to form a training data set; a detection model module, which constructs a detection model, the detection model including an embedding layer, a transformer encoder layer, a linear layer, and a Softmax layer that sequentially perform data transmission, the transformer encoder layer including a first sub-layer and a second sub-layer, the first sub-layer including a multi-head attention mechanism and a first residual network, and the second sub-layer including a position feed-forward network and a second residual network; a training module, which trains the detection model based on the training data set to obtain a trained detection model, including: the input data passes through the embedding layer to output a total embedding, projects each vehicle networking network traffic data in the input data into a multi-dimensional space to obtain an identifier embedding; performs position encoding on the vehicle networking network traffic data using a sine function to obtain a position embedding; based on the identifier embedding and the corresponding position embedding, obtains a total embedding; inputs the total embedding into a plurality of transformer encoder layers to obtain first data; inputs the first data into the linear layer to output second data; randomly replaces the proportion of vehicle networking network traffic data in the historical sequence and randomly masks the vehicle networking network traffic data; inputs the second data corresponding to the masked vehicle networking network traffic data into the Softmax layer to obtain the probability that each vehicle networking network traffic data in the sequence belongs to the masked vehicle networking network traffic data; trains the detection model using cross-entropy loss to determine the trained detection model; a second acquisition module, which acquires the vehicle networking network traffic data of the current sequence of the target vehicle; a detection module, which inputs the vehicle networking network traffic data of the current sequence into the trained detection model to obtain a detection result of whether an intrusion has occurred.

[0016] Compared with the prior art, the present invention proposes a vehicle networking intrusion detection method and system for detecting known and unknown network attacks in a vehicle external network. The detection model of the present invention is a self-supervised model, which can successfully describe the deep bidirectional representation of the Flow ID sequence through the left and right contexts in its respective layers and can accurately identify message injection attacks. When training the detection model, some Flow IDs in the input are randomly masked, aiming to predict the traditional IDs of the masked words based on their left and right contexts and optimize the trainable parameters in the model. Description of the Drawings

[0017] In order to more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings described below are only some embodiments recorded in the embodiments of this specification, and those of ordinary skill in the art can also obtain other drawings based on these drawings.

[0018] Figure 1It is a flowchart of a vehicle networking intrusion detection method provided by this embodiment;

[0019] Figure 2 It is a schematic diagram of the data transmission process of a vehicle networking intrusion detection method provided by this embodiment. Detailed implementation manners

[0020] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0021] For ease of understanding of the embodiments of the present invention, the following will further explain with specific examples with reference to the accompanying drawings. The examples do not constitute a limitation to the protection scope of the present invention.

[0022] Embodiment 1

[0023] This embodiment provides a vehicle networking intrusion detection method, including:

[0024] S1 Obtain a plurality of sequences composed of vehicle networking network traffic data at a plurality of consecutive historical moments to form a training data set.

[0025] Each sequence includes vehicle networking network traffic data at T consecutive historical moments, forming a Flow ID sequence S = [id 1 ,..., id t ,..., id T , where represents the vehicle networking network traffic data of the M-dimensional vector transmitted at the t-th moment of the vehicle external network, represents the set of Flow IDs extracted from the Flow message, and M is the size of the set, and the vehicle networking network traffic data is the vehicle external network traffic data.

[0026] This embodiment uses unsupervised learning for anomaly detection and only uses normal data for training. Therefore, only the set of N Flow ID sequences is used as the training data set, and this set is represented as where S j represents the Flow ID sequence corresponding to the j-th sequence, and N represents the total number of sequences.

[0027] S2 Construct a detection model.

[0028] The detection model includes an embedding layer, a Transformer encoder layer, a linear layer, and a Softmax layer that perform data transmission in sequence. The Transformer encoder layer includes a first sub-layer and a second sub-layer. The first sub-layer includes a multi-head attention mechanism and a first residual network, and the second sub-layer includes a positional feed-forward network and a second residual network.

[0029] S3 trains the detection model based on the training dataset to obtain the trained detection model.

[0030] In this step, it includes:

[0031] The input data passes through the embedding layer and outputs the total embedding.

[0032] Step 1: Project each vehicle networking network traffic data in the input data into a multi-dimensional space to obtain the identifier embedding.

[0033] Use a single linear layer to project each identifier j of size (M,1) in the Flow sequence S into a d-dimensional space, that is:

[0034]

[0035] where represents the t-th vehicle networking network traffic data in the j-th sequence, represents the identifier embedding of the vehicle networking network traffic data with a size of (d,1); represents the first embedding weight matrix, represents the first bias, W e and b e are trainable parameters.

[0036] Step 2: Use the sine function to perform positional encoding on the vehicle networking network traffic data to obtain the positional embedding.

[0037] Use the sine function to encode the position of the identifier into a d-dimensional positional embedding

[0038] Step 3: Based on the identifier embedding and the corresponding positional embedding, obtain the total embedding.

[0039] Each vehicle networking network traffic data corresponds to an identifier embedding and a positional embedding. Add the corresponding identifier embedding and positional embedding to obtain the total embedding. The expression is where is the total embedding of the vehicle networking network traffic data id t j and represents the vehicle networking network traffic data For the positional embedding, the input sequence S j The corresponding total embedding is where X j represents the total embedding of T consecutive historical moments, a matrix of size T×d.

[0040] S310 inputs the total embedding into multiple transformer encoder layers to obtain the first data.

[0041] In this embodiment, there are L transformer encoder layers. The total embedding X j is input into a stack of L transformer encoder layers to obtain the first data, and its expression is:

[0042] E (j,l) = g(X (j,l) ) + f(X (j,l) + g(X (j,l) ))

[0043] H (j,l) = z(E (j,l) ) + f(E (j,l) + z(E (j,l) ))

[0044] X (j,l+1) = H (j,l)

[0045] where E (j,l) represents the output data corresponding to the vehicle networking network traffic data of the j-th sequence in the first sub-layer of the l-th transformer encoder layer. g represents the multi-head attention function, f represents the layer normalization function, X (j,l) represents the input data corresponding to the vehicle networking network traffic data of the j-th sequence in the l-th transformer encoder layer, H (j,l) represents the output data corresponding to the vehicle networking network traffic data of the j-th sequence in the second sub-layer of the l-th transformer encoder layer, z is the position feed-forward function, and X (j,l+1) represents the input data corresponding to the vehicle networking network traffic data of the j-th sequence in the (l + 1)-th transformer encoder layer.

[0046] The processing steps of each transformer encoder layer specifically include:

[0047] Step 1: Use the multi-head self-attention mechanism to process the data input to the transformer encoder layer to obtain the attention value.

[0048] Multiple attention heads allow the model to capture different aspects of data simultaneously on different Flow IDs. In this embodiment, the input data of the l-th transformer encoder layer is multiplied by the weight matrices of different attention heads to obtain the query vectors, key vectors, and value vectors corresponding to the respective attention heads, realizing the projection of the d-dimensional Flow identifier into subspaces calculated by different attention heads n ∈ {1,.., H}, and its expression is:

[0049]

[0050]

[0051]

[0052] Among them, X (j,l) represents the input data corresponding to the vehicle networking network traffic data of the j-th sequence of the l-th transformer encoder layer. The input data of the first transformer encoder layer is the total embedding; the input data of the remaining transformer encoder layers is the output data of the previous transformer encoder layer. Q (j,n,l) is the query vector of the n-th attention head corresponding to the vehicle networking network traffic data of the j-th sequence of the l-th transformer encoder layer, K (j,n,l) is the key vector of the n-th attention head corresponding to the vehicle networking network traffic data of the j-th sequence of the l-th transformer encoder layer, V (j,n,l) is the value vector of the n-th attention head corresponding to the vehicle networking network traffic data of the j-th sequence of the l-th transformer encoder layer. represents the weight matrix of the query vector Q of the n-th attention head, with a size of d × F, represents the weight matrix of the key vector K of the n-th attention head, with a size of d × F, represents the weight matrix of the value vector V of the n-th attention head, with a size of d × F, W (Q,n) , W (K,n) and W (V,n) are all trainable parameters.

[0053] Based on the query vector, key vector, and value vector, calculate the value weighted sum of each attention head, and its expression is: Among them, represents the value weighted sum of the n-th attention head corresponding to the vehicle networking network traffic data of the j-th sequence of the l-th transformer encoder layer, σ represents the Softmax function, and d represents Q (j ,l) , K (j,l) or V (j,l)The dimension of the vector. In this embodiment, the dot product similarity is used to compare the query vector of the Flow identifier with all other key vectors. If the query and key vectors are comparable and have a high attention weight, the matching value is considered relevant.

[0054] Use the weight matrix W O Concatenate the results of multiple attention heads and project them back into a space of size T×d, and its expression is Among them, represents the multi-head attention value corresponding to the vehicle networking network traffic data of the j-th sequence in the l-th transformer encoder layer.

[0055] Step 2: Process the attention value using the first residual network to obtain the first intermediate data.

[0056] Step 3: Process the first intermediate data using the position feed-forward network to obtain the second intermediate data.

[0057] Apply the position feed-forward network with the ReLU activation function to each layer of the encoder, and its expression is:

[0058] z(E (j,l) ) = [W 1 E (j,l) + ⊙W 2

[0059] Among them, z(E (j,l) ) represents the second intermediate data corresponding to the vehicle networking network traffic data of the j-th sequence in the l-th transformer encoder layer, E (j,l) represents the first intermediate data corresponding to the vehicle networking network traffic data of the j-th sequence in the l-th transformer encoder layer, W 1 represents the first projection matrix, W 2 represents the second projection matrix, and W 1 and W 2 are trainable parameters, ⊙ represents the hadarmard product, and []+ represents obtaining the maximum value of the elements.

[0060] Through the processing of the position feed-forward network, the model is more sensitive to the position of the data in the sequence, improving the intrusion detection accuracy.

[0061] Step 4: Process the second intermediate data using the second residual network to obtain the output data of the current layer.

[0062] In this embodiment, the output data of the last transformer encoder layer is the first data, and the output data of the remaining layers is the input data of the next layer. Among them, the set of the first data corresponding to the j-th sequence is The matrix size is d×1, ​Represents the first data corresponding to the t-th vehicle networking network traffic data in the j-th sequence.

[0063] S320 inputs the first data into a linear layer and outputs second data.

[0064] After passing through different transformer layers, the L-th context embedding vector (first data) of the Flow ID is fed into a single linear layer, projecting each first data into an M-dimensional layer to obtain second data, and its expression is:

[0065]

[0066] Where, Represents the second data corresponding to the t-th vehicle networking network traffic data in the j-th sequence, with a size of M×1, Represents the second embedding weight matrix, Represents the second bias, W m and b m Are trainable parameters.

[0067] S330 randomly replaces the proportion of vehicle networking network traffic data in the historical sequence and randomly masks the vehicle networking network traffic data.

[0068] S340 inputs the second data corresponding to the masked vehicle networking network traffic data into the Softmax function to obtain the probability that each vehicle networking network traffic data in the sequence belongs to the masked vehicle networking network traffic data.

[0069] Through the formula Obtain the probability distribution of the entire Flow ID set, where, Represents the probability distribution of the u-th masked vehicle networking network traffic data in the j-th sequence at each position in the sequence, which is an m-dimensional vector, σ is the Softmax function, Represents the second data corresponding to the u-th masked vehicle networking network traffic data in the j-th sequence, W c Represents the third embedding weight matrix, b c Represents the third bias, W c and b c Are trainable parameters.

[0070] Use the masked language model to train the detection model to capture the patterns of normal Flow-ID sequences, enabling the masked data to pay attention to the data on both sides. This embodiment adopts a training method without data labels to reduce labor costs.

[0071] S350 trains the detection model using cross-entropy loss to determine the trained detection model.

[0072] Aiming to minimize a batch of I (I ≤ N) sequences, a detection model is trained using the cross - entropy loss function to reliably predict the Flow ID that has been randomly masked, and its expression is: Among them, represents the predicted value, represents the vehicle - to - everything (V2X) network traffic data of the u - th mask of the j - th sequence, I represents the number of sequences, R is the total number of masking masks in the j - th sequence, and N is the number of training samples.

[0073] S4 Obtain the V2X network traffic data of the current sequence of the target vehicle.

[0074] S5 Input the V2X network traffic data of the current sequence into the trained detection model to obtain the detection result.

[0075] Input the V2X network traffic data of the current sequence into the trained detection model for a randomly masked test sequence, and obtain the probability distribution of each masked V2X network traffic data in the current sequence, that is, the probability that each V2X network traffic data in the sequence belongs to the V2X network traffic data of this mask. The out - of - vehicle network traffic corresponding to the highest probability is the expected candidate. If the actual V2X network traffic data is among the expected candidates, the V2X network traffic data of the current sequence is normal; otherwise, the V2X network traffic data is abnormal.

[0076] Compared with the prior art, this embodiment proposes a V2X intrusion detection method and system to detect known and unknown network attacks in the vehicle's external network. The detection model in this embodiment is a self - supervised model, which can successfully describe the deep bidirectional representation of the Flow ID sequence through the left - and - right context in its various layers and can accurately identify message injection attacks. When training the detection model, some Flow IDs in the input are randomly masked, aiming to predict the traditional ID of the masked word according to its left - and - right context and optimize the trainable parameters in the model.

[0077] Embodiment 2

[0078] This embodiment provides a V2X intrusion detection system that implements a V2X intrusion detection method in Embodiment 1. The system includes:

[0079] The first acquisition module acquires a plurality of sequences composed of V2X network traffic data at multiple consecutive historical moments to form a training data set.

[0080] Detection model module, which constructs a detection model. The detection model includes an embedding layer, a Transformer encoder layer, a linear layer, and a Softmax layer that sequentially perform data transmission. The Transformer encoder layer includes a first sub-layer and a second sub-layer. The first sub-layer includes a multi-head attention mechanism and a first residual network. The second sub-layer includes a position feed-forward network and a second residual network.

[0081] Training module, which trains the detection model based on a training data set to obtain a trained detection model, including: the input data passes through the embedding layer to output a total embedding, projects each vehicle networking network traffic data in the input data into a multi-dimensional space to obtain an identifier embedding; uses a sine function to perform position encoding on the vehicle networking network traffic data to obtain a position embedding; based on the identifier embedding and the corresponding position embedding, obtains a total embedding; inputs the total embedding into multiple Transformer encoder layers to obtain first data; inputs the first data into the linear layer to output second data; randomly replaces a proportion of the vehicle networking network traffic data in the historical sequence and randomly masks the vehicle networking network traffic data; inputs the second data corresponding to the masked vehicle networking network traffic data into the Softmax layer to obtain the probability that each vehicle networking network traffic data in the sequence belongs to the masked vehicle networking network traffic data; uses cross-entropy loss to train the detection model to determine the trained detection model.

[0082] Second acquisition module, which acquires the vehicle networking network traffic data of the current sequence of the target vehicle.

[0083] Detection module, which inputs the vehicle networking network traffic data of the current sequence into the trained detection model to obtain a detection result of whether it has been invaded.

[0084] The above specific implementation manners further elaborate on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above is only the specific implementation manners of the present invention and is not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A vehicle network intrusion detection method, characterized in that: include: Acquire multiple sequences consisting of vehicle network traffic data at multiple consecutive historical moments to form a training data set; Constructing a detection model, the detection model comprising an embedding layer, a transformer encoder layer, a linear layer, and a Softmax layer for sequentially transmitting data, the transformer encoder layer comprising a first sublayer and a second sublayer, the first sublayer comprising a multi-head attention mechanism and a first residual network, and the second sublayer comprising a position feedforward network and a second residual network; The detection model is trained based on the training data set to obtain the trained detection model, including: the input data is output through the embedding layer to output the total embedding, and each vehicle network traffic data in the input data is projected into the multi-dimensional space to obtain the identifier embedding, which is expressed as: in, Indicates the network traffic data of the Internet of Vehicles Identifier embedding, represents the t-th IoV network traffic data in the j-th sequence, W e represents the first embedding weight matrix, b e Represents the first deviation; the sine function is used to position encode the network traffic data of the Internet of Vehicles to obtain position embedding; based on the identifier embedding and the corresponding position embedding, the total embedding is obtained, and its expression is: in, Indicates the network traffic data of the Internet of Vehicles The total embedding of Indicates the network traffic data of the Internet of Vehicles The total embedding is input into a plurality of transformer encoder layers to obtain first data; the first data is input into a linear layer to output second data; the proportion of the Internet of Vehicles network traffic data in the historical sequence is randomly replaced, and the Internet of Vehicles network traffic data is randomly masked; the second data corresponding to the masked Internet of Vehicles network traffic data is input into a Softmax layer to obtain the probability that each Internet of Vehicles network traffic data in the sequence belongs to the masked Internet of Vehicles network traffic data; the detection model is trained using a cross entropy loss to determine the trained detection model; Obtain the current sequence of vehicle network traffic data of the target vehicle; Input the current sequence of vehicle network traffic data into the trained detection model to obtain the detection result of whether it has been invaded; The processing of each transformer encoder layer includes: The multi-head self-attention mechanism is used to process the data input to the transformer encoder layer to obtain the attention value; its expression is: Q (j,n,l) =X (j,l) W (Q,n) K (j,n,l) =X (j,l) W (K,n) V (j,n,l) =X (j,l) W (V,n) Among them, Q (j,n,l) is the query vector of the nth attention head corresponding to the jth sequence of IoV network traffic data of the lth transformer encoder layer, X (j,l) represents the input data corresponding to the j-th sequence of the IoV network traffic data of the l-th transformer encoder layer, K (j,n,l) is the keyword vector of the nth attention head corresponding to the jth sequence of IoV network traffic data of the lth transformer encoder layer, V (j,n,l) is the value vector of the nth attention head corresponding to the jth sequence of IoV network traffic data of the lth transformer encoder layer, W (Q,n) represents the weight matrix of the query vector Q of the nth attention head, W (K,n) represents the weight matrix of the keyword vector K of the nth attention head, W (V,n) represents the weight matrix of the value vector V of the nth attention head, represents the weighted sum of the values ​​of the nth attention head corresponding to the jth sequence of the IoV network traffic data of the lth transformer encoder layer, σ represents the Softmax function, and d represents Q (j,l) , K (j,l) or V (j,l) The dimension of the vector; Using a first residual network to process the attention value to obtain first intermediate data; Processing the first intermediate data using a position feedforward network to obtain second intermediate data; The second intermediate data is processed by the second residual network to obtain the output data of the current layer as the input of the next layer; The output of the last transformer encoder layer is used as the first data.

2. A vehicle network intrusion detection method according to claim 1, characterized in that: Processing the first intermediate data using a position feedforward network to obtain second intermediate data includes: That (j,l) )=[W1E (j,l) ] + W2 Among them, z(E (j,l) ) represents the second intermediate data corresponding to the j-th sequence of the Internet of Vehicles network traffic data of the l-th transformer encoder layer, E (j,l) represents the first intermediate data corresponding to the j-th sequence of the Internet of Vehicles network traffic data of the l-th transformer encoder layer, W1 represents the first projection matrix, W2 represents the second projection matrix, represents the hadarmard product, [] + Gets the maximum value of an element.

3. The vehicle networking intrusion detection method according to claim 1, characterized in that: Inputting the first data into a linear layer and outputting second data comprises: in, represents the second data corresponding to the t-th vehicle network traffic data in the j-th sequence, W m represents the second embedding weight matrix, represents the first data corresponding to the t-th vehicle network traffic data in the j-th sequence, b m Indicates the second deviation.

4. The vehicle networking intrusion detection method according to claim 1, characterized in that: The second data corresponding to the masked IoV network traffic data is input into the Softmax layer to obtain the probability distribution of the masked IoV network traffic data at each position in the sequence, including: in, represents the probability distribution of the vehicle network traffic data of the u-th mask in the j-th sequence at each position in the sequence, σ is the Softmax function, represents the second data corresponding to the vehicle network traffic data of the jth sequence and the uth mask, W c represents the third embedding weight matrix, b c Indicates the third deviation.

5. A vehicle network intrusion detection method according to claim 4, characterized in that: The detection model is trained using cross entropy loss to determine the trained detection model, including: Among them, L MASK represents the predicted value, represents the IoV network traffic data of the u-th mask in the j-th sequence, I represents the number of sequences, R is the total number of masked masks in the j-th sequence, and N is the number of training samples.

Citation Information

Patent Citations

  • Internet of vehicles intrusion detection method based on spatial-temporal feature parallel analysis

    CN116506858A

  • Deep learning method and device for network intrusion detection and identification, storage medium and computer equipment

    CN118260593A