Internet of vehicles intrusion detection system and method

Creating a digital twin model of vehicles through digital twin technology solves the problem that the existing Internet of Vehicle Intrusion Detection System cannot fully capture the complex syntax structure of network traffic and lacks in-depth analysis of data flow context information, achieving high adaptability and accuracy of the IDS system.

CN120017324AInactive Publication Date: 2025-05-16GUANGDONG UNIV OF TECH
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510060306.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing Internet of Vehicle Intrusion Detection System cannot fully capture the complex syntax structure of network traffic, and lacks in-depth analysis of data flow context information, resulting in low adaptability and accuracy.

Method used

Digital twin technology is used to create a digital twin model of the vehicle, collect real-time data through the data acquisition layer, the digital twin layer performs data analysis and feature extraction, and the application layer executes detection strategies and provides feedback to improve the adaptability and accuracy of the IDS system.

Benefits of technology

Through real-time analysis and strategy optimization of the digital twin model, it can fully capture the complex syntax structure of network traffic and deeply analyze the data flow context information, thereby significantly improving the adaptability and accuracy of the IDS system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017324A_ABST
    Figure CN120017324A_ABST
Patent Text Reader

Abstract

The invention discloses an Internet of Vehicles intrusion detection system and method, and relates to the technical field of vehicle network security. The system comprises a data acquisition layer used for acquiring vehicle real-time data; the digital twinborn layer is used for constructing a digital twinborn model according to the collected real-time information of the vehicle and carrying out vehicle networking intrusion detection according to the real-time data of the vehicle by utilizing the digital twinborn model so as to formulate a vehicle networking intrusion detection strategy; and the application layer is used for executing the Internet of Vehicles intrusion detection strategy and carrying out strategy effect feedback so as to carry out data updating on the Internet of Vehicles intrusion detection strategy. According to the system and the method, the complex grammar structure of the network flow can be fully captured, and the context information of the data flow can be deeply analyzed, so that the adaptability and the accuracy of the IDS system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vehicle network security, and in particular to a vehicle network intrusion detection system and method. Background Art

[0002] With the evolution of vehicle ad hoc networks (VANET) to the Internet of Vehicles (IoV) communication framework, the communication capabilities of vehicles have been significantly enhanced, which not only realizes the interconnection between vehicles, infrastructure, pedestrians and smart devices, but also introduces complex network security challenges. The automotive network architecture is usually divided into intra-vehicle network (IVN) and inter-vehicle network (EVN). IVN is responsible for the communication between ECUs and is mainly based on CAN bus technology. However, the CAN bus lacks an authentication mechanism and is vulnerable to IVN attack threats introduced by physical interfaces such as USB and OBD. EVN connects the vehicle to the external environment through V2X technology and faces EVN attack threats brought by wireless interfaces such as Wi-Fi, Bluetooth and cellular networks. The in-vehicle mobile Internet uploads data to the cloud through vehicles or devices such as RSU, providing the possibility of real-time data transmission and remote monitoring for the Internet of Vehicles.

[0003] In the IoT environment, digital twin technology has shown great potential, and can create digital entities to map physical entities and achieve two-way data flow. This technology has been widely used in manufacturing, construction, urban planning and other fields. In the field of Internet of Vehicles security, digital twin technology is used to simulate the vehicle environment, combined with on-board sensors, GPS systems, high-definition cameras and other equipment to collect dynamic data of the vehicle in real time, and synchronously perform intrusion detection at the network twin layer, so as to timely reflect the safety status of the vehicle.

[0004] Existing intrusion detection systems (IDS) mainly use methods such as anomaly detection, rule detection and signature detection. Among them, the methods based on rule detection and signature detection have limitations in detection efficiency and accuracy, especially in the face of the rapidly growing and diverse attack types in in-vehicle networks (IVNs) and extra-vehicle networks (EVNs), it is difficult to guarantee detection performance; anomaly detection methods based on traditional machine learning and deep learning have been favored by relevant researchers in recent years, but these methods cannot fully capture the complex grammatical structure of network traffic and lack in-depth analysis of data flow context information, resulting in low adaptability and accuracy of IDS systems. Summary of the invention

[0005] In order to overcome the problem that the prior art cannot fully capture the complex grammatical structure of network traffic and lacks in-depth analysis of data flow context information, resulting in low adaptability and accuracy of IDS systems, the purpose of the present invention is to propose a vehicle network intrusion detection system and method, which can fully capture the complex grammatical structure of network traffic and can perform in-depth analysis of data flow context information to improve the adaptability and accuracy of the IDS system.

[0006] To achieve the purpose of the present invention, the present invention adopts the following technical solutions:

[0007] A vehicle networking intrusion detection system, the system comprising:

[0008] Data collection layer, used to collect real-time vehicle data;

[0009] The digital twin layer is used to build a digital twin model based on the collected real-time vehicle information, and use the digital twin model to perform Internet of Vehicles intrusion detection based on the real-time vehicle data to formulate an Internet of Vehicles intrusion detection strategy;

[0010] The application layer is used to execute the Internet of Vehicles intrusion detection strategy and provide feedback on the strategy effect to update the data of the Internet of Vehicles intrusion detection strategy.

[0011] In the above technical solution, the data acquisition layer includes all physical devices and sensors, which are responsible for collecting real-time data of the vehicle. These data provide original information for the vehicle's operating status, environmental conditions, driving behavior, etc., ensure the accuracy and integrity of the data, and provide reliable input for the digital twin layer and application layer; the digital twin layer is the core of the entire system. It creates a digital twin model of the vehicle based on the data collected by the physical layer. The digital twin model not only replicates the physical characteristics of the vehicle, but also simulates the behavior and response of the vehicle under various conditions, and optimizes the vehicle network intrusion detection strategy by simulating various attack scenarios. In addition, the digital twin layer is also responsible for processing real-time analysis of data, extracting key features, and generating insights and predictions useful to the application layer; the application layer is the interface of the end user, which converts the analysis results and detection decisions of the digital twin layer into actual actions and feedback; through the mutual cooperation between the data acquisition layer, the digital twin layer and the application layer, the complex grammatical structure of the network traffic can be fully captured, and the in-depth analysis of the data flow context information can be performed, thereby effectively improving the adaptability and accuracy of the IDS system.

[0012] Preferably, the sources of the real-time vehicle data acquired by the data acquisition layer include vehicle-mounted sensors, GPS positioning systems, high-definition cameras, and various communication interfaces in the vehicle-mounted network;

[0013] Wherein, the communication interface includes a USB port and an OBD-II port.

[0014] In the above technical solution, through the above physical devices, the real-time data of the vehicle can be effectively collected, and the accuracy and completeness of the data can be ensured, providing reliable input for the digital twin layer and application layer.

[0015] Preferably, the constructed digital twin model includes a data preprocessing module, a feature engineering module and a classifier module;

[0016] The data preprocessing module performs sample balancing and category label encoding processing on the real-time vehicle data, and transmits the processed data to the feature engineering module;

[0017] The feature engineering module extracts key features of the original network traffic data based on the real-time vehicle data after sample balancing and category label encoding, and selects a feature subset with the highest mutual information value based on the extracted key features to complete feature selection;

[0018] The classifier module performs vehicle network intrusion detection based on the selected features, classifies complex network attacks based on the detection results, and formulates vehicle network intrusion detection strategies based on the classification results.

[0019] Preferably, the data preprocessing module uses random sampling technology to perform sample balancing processing on various types of samples in the real-time vehicle data, and processes infinite values ​​and NaN values ​​in the data through the average value replacement strategy. At the same time, LabelEncoder is used to encode the category labels of text types.

[0020] In the above technical scheme, the data preprocessing module uses random sampling technology to perform sample balancing processing on various samples in the real-time vehicle data, which can effectively improve the digital twin model's ability to detect abnormal traffic in the actual scenario of the Internet of Vehicles, so as to ensure that the model has sufficient representativeness of attack types during the training process; the infinite values ​​and NaN values ​​in the data are processed through the average value replacement strategy to ensure the integrity and consistency of the data; the LabelEncoder is used to encode the category labels of the text type, which can effectively simplify the input of the model and improve the data processing efficiency of the model.

[0021] Preferably, the feature engineering module uses a mutual information feature selection method to extract key features of the original network traffic data;

[0022] And according to the extracted key features, the mutual information value between the features and the target variable is calculated to screen out the features with the strongest correlation. The expression is:

[0023]

[0024] Calculate the mutual information between each feature and the target variable, and select the feature subset with the highest mutual information value;

[0025] Among them, X represents the feature variable, Y represents the target variable, p(x,y) is the joint probability distribution, and p(x) and p(y) are the marginal probability distributions respectively.

[0026] Preferably, after completing feature selection, the real-time vehicle data is divided into a training set and a test set, and several rounds of iterative optimization training are set to optimize the parameters of the digital twin model;

[0027] The feature engineering module uses the SMOTE algorithm to balance the samples in the training set, and the expression is:

[0028] x′=x+γ·(x n -x k )

[0029] The feature engineering module uses Token Embeddings technology to perform text conversion on the test set and the balanced training set, and converts the data into a word segmentation form suitable for DistilBERT and inputs it into the classifier module;

[0030] Among them, x represents the original sample, x n represents its nearest neighbor sample in the feature space, x k represents another randomly selected sample, and γ represents a random number.

[0031] In the above technical scheme, the mutual information feature selection method is used to extract the key features of the original network traffic data, which can effectively retain the features that have a significant impact on the classification results and remove irrelevant features, thereby reducing the dimension of the data while ensuring the classification performance of the model; according to the extracted key features, the mutual information value between the feature and the target variable is calculated, and the features with the strongest correlation are screened out, which can further improve the detection accuracy of the model; the SMOTE algorithm is used to balance the samples in the training set, which can increase the number of minority class samples to balance the category distribution, thereby improving the generalization ability of the model for attack detection; the Token Embeddings technology is used to convert the test set and the balanced training set into text, and the data is converted into a segmentation form suitable for DistilBERT, which can effectively improve the efficiency of the model in processing data.

[0032] Preferably, the classifier module allocates corresponding vector representations according to the word segmentation form of DistilBERT, and uses a multi-head self-attention mechanism to process the vector representations in parallel to capture the deep connection between features, expressed as:

[0033]

[0034] Combine the feedforward neural network and layer normalization mechanism to perform vehicle network intrusion detection, and classify complex network attacks based on the detection results. The expression is:

[0035] FFN=max(0,XW1+b1)W2+b2

[0036]

[0037] Among them, Q represents query, K represents key, V represents value, and d k represents the dimension of the key, represents the scaling factor for normalization, X represents the input, W1 and b1 represent the learnable parameters of the first GELU fully connected layer, W2 and b2 represent the learnable parameters of the second fully connected layer, μ represents the mean, σ represents the standard deviation, and γ and β represent learnable parameters.

[0038] Preferably, the classifier module adopts a classifier based on the DistilBERT model.

[0039] In the above technical scheme, a multi-head self-attention mechanism is used to process the vector representation in parallel to capture the deep connection between features, and combined with a feedforward neural network and a layer normalization mechanism for vehicle network intrusion detection, which can further enhance the nonlinear expression and generalization capabilities of the model, thereby improving the classification performance of complex network attacks, so that the complex grammatical structure of network traffic can be fully captured, and in-depth analysis of the contextual information of the data flow can be performed, thereby effectively improving the adaptability and accuracy of the IDS system.

[0040] Preferably, after completing feature selection, the feature engineering module divides the vehicle real-time data into 80% training set and 20% test set.

[0041] Preferably, the digital twin model is a digital twin model based on an intrusion detection system IDS; the application layer includes a visualization tool and a user interface.

[0042] In the above technical scheme, a digital twin model based on the intrusion detection system IDS is constructed, which can effectively conduct a full study of the existing intrusion detection system IDS, so as to fully capture the complex grammatical structure of network traffic and conduct in-depth analysis of data flow context information, thereby effectively improving the adaptability and accuracy of the IDS system; the application layer includes visualization tools and user interfaces, which enable vehicle managers, security analysts and drivers to intuitively understand the vehicle's operating status, network traffic, potential threats and IDS response measures.

[0043] A method for detecting intrusion in an Internet of Vehicles, the method comprising the following steps:

[0044] Collect real-time vehicle data;

[0045] Based on the collected real-time vehicle information, a digital twin model is constructed, and the digital twin model is used to perform Internet of Vehicles intrusion detection based on the real-time vehicle data to formulate an Internet of Vehicles intrusion detection strategy;

[0046] Execute the IoV intrusion detection strategy and provide feedback on the strategy effect to update the data of the IoV intrusion detection strategy.

[0047] Compared with the prior art, the present invention has the following beneficial effects:

[0048] The present invention provides an Internet of Vehicles intrusion detection system and method, wherein the data acquisition layer includes all physical devices and sensors, and is responsible for collecting real-time data of the vehicle. The data provides original information for the vehicle's operating status, environmental conditions, driving behavior, etc., ensures the accuracy and integrity of the data, and provides reliable input for the digital twin layer and the application layer; the digital twin layer is the core of the entire system, and it creates a digital twin model of the vehicle based on the data collected by the physical layer. The digital twin model not only replicates the physical characteristics of the vehicle, but also simulates the behavior and response of the vehicle under various conditions, and optimizes the Internet of Vehicles intrusion detection strategy by simulating various attack scenarios. In addition, the digital twin layer is also responsible for processing real-time analysis of data, extracting key features, and generating insights and predictions useful to the application layer; the application layer is the interface of the end user, and it converts the analysis results and detection decisions of the digital twin layer into actual actions and feedback; through the mutual cooperation between the data acquisition layer, the digital twin layer and the application layer, the complex grammatical structure of the network traffic can be fully captured, and the in-depth analysis of the data flow context information can be performed, thereby effectively improving the adaptability and accuracy of the IDS system. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1 A schematic diagram of a vehicle networking intrusion detection system framework provided in an embodiment of the present application;

[0050] Figure 2 A schematic diagram of the structure of a digital twin model provided in an embodiment of the present application;

[0051] Figure 3 A flowchart of a method for detecting intrusion into a connected vehicle provided by an embodiment of the present application;

[0052] Figure 4 Confusion matrix heat map of the CICIoT2023 data set provided in the embodiment of the present application;

[0053] Figure 5 Confusion matrix heat map of the CICIDS2018 data set provided in the embodiment of the present application;

[0054] Figure 6Confusion matrix heat map of the CICIoV2024 dataset provided in the embodiment of the present application;

[0055] Figure 7 This is a heat map of the confusion matrix of the Car-Hacking dataset provided in an embodiment of the present application. DETAILED DESCRIPTION

[0056] In order to facilitate the understanding of the present invention, the present invention will be described more fully below with reference to the relevant drawings. Preferred embodiments of the present invention are provided in the drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosure of the present invention more thorough and comprehensive.

[0057] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art of the present invention. The terms used herein in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more related listed items.

[0058] Embodiment 1:

[0059] This embodiment provides a vehicle networking intrusion detection system. Figure 1 , the system comprising:

[0060] Data collection layer, used to collect real-time vehicle data;

[0061] The digital twin layer is used to build a digital twin model based on the collected real-time vehicle information, and use the digital twin model to perform Internet of Vehicles intrusion detection based on the real-time vehicle data to formulate an Internet of Vehicles intrusion detection strategy;

[0062] The application layer is used to execute the Internet of Vehicles intrusion detection strategy and provide feedback on the strategy effect to update the data of the Internet of Vehicles intrusion detection strategy.

[0063] As a preferred embodiment, Figure 1 ,The sources of real-time vehicle data acquired by the data acquisition layer include vehicle-mounted sensors, GPS positioning systems, high-definition cameras, and various communication interfaces in the vehicle network;

[0064] Wherein, the communication interface includes a USB port and an OBD-II port, etc.

[0065] It can be understood that through the above-mentioned physical devices, the real-time data of the vehicle can be effectively collected, and the accuracy and completeness of the data can be ensured, providing reliable input for the digital twin layer and application layer.

[0066] In this embodiment, the data acquisition layer includes all physical devices and sensors, which are responsible for collecting real-time data of the vehicle. These data provide original information for the vehicle's operating status, environmental conditions, driving behavior, etc., ensure the accuracy and integrity of the data, and provide reliable input for the digital twin layer and application layer; the digital twin layer is the core of the entire system. It creates a digital twin model of the vehicle based on the data collected by the physical layer. The digital twin model not only replicates the physical characteristics of the vehicle, but also simulates the behavior and response of the vehicle under various conditions, and optimizes the vehicle network intrusion detection strategy by simulating various attack scenarios. In addition, the digital twin layer is also responsible for processing real-time analysis of data, extracting key features, and generating insights and predictions that are useful to the application layer; the application layer is the interface for end users, which converts the analysis results and detection decisions of the digital twin layer into actual actions and feedback; through the mutual cooperation between the data acquisition layer, the digital twin layer and the application layer, the complex grammatical structure of network traffic can be fully captured, and the in-depth analysis of the data flow context information can be performed, thereby effectively improving the adaptability and accuracy of the IDS system.

[0067] As a preferred embodiment, see Figure 1 and Figure 2 ,The constructed digital twin model includes data preprocessing module, feature engineering module and classifier module;

[0068] The data preprocessing module performs sample balancing and category label encoding processing on the real-time vehicle data, and transmits the processed data to the feature engineering module;

[0069] The feature engineering module extracts key features of the original network traffic data based on the real-time vehicle data after sample balancing and category label encoding, and selects a feature subset with the highest mutual information value based on the extracted key features to complete feature selection;

[0070] The classifier module performs vehicle network intrusion detection based on the selected features, classifies complex network attacks based on the detection results, and formulates vehicle network intrusion detection strategies based on the classification results.

[0071] As a preferred embodiment, see Figure 2 The data preprocessing module uses random sampling technology to balance the samples of various types in the real-time vehicle data, and uses the average value replacement strategy to process the infinite values ​​and NaN values ​​in the data. At the same time, LabelEncoder is used to encode the category labels of the text type.

[0072] It can be understood that the data preprocessing module uses random sampling technology to perform sample balancing processing on various samples in the real-time vehicle data, which can effectively improve the digital twin model's ability to detect abnormal traffic in actual vehicle networking scenarios, so as to ensure that the model has sufficient representativeness of attack types during the training process; the infinite values ​​and NaN values ​​in the data are processed through the average value replacement strategy to ensure the integrity and consistency of the data; the LabelEncoder is used to encode the category labels of the text type, which can effectively simplify the input of the model and improve the data processing efficiency of the model.

[0073] As a preferred embodiment, see Figure 2 ,The feature engineering module uses the feature selection method of mutual information to extract key features of the original network traffic data;

[0074] And according to the extracted key features, the mutual information value between the features and the target variable is calculated to screen out the features with the strongest correlation. The expression is:

[0075]

[0076] Calculate the mutual information between each feature and the target variable, and select the feature subset with the highest mutual information value;

[0077] Among them, X represents the feature variable, Y represents the target variable, p(x,y) is the joint probability distribution, and p(x) and p(y) are the marginal probability distributions respectively.

[0078] Preferably, after completing feature selection, the real-time vehicle data is divided into a training set and a test set, and several rounds of iterative optimization training are set to optimize the parameters of the digital twin model;

[0079] The feature engineering module uses the SMOTE algorithm to balance the samples in the training set, and the expression is:

[0080] x′=x+γ·(x n -x k )

[0081] The feature engineering module uses Token Embeddings technology to perform text conversion on the test set and the balanced training set, and converts the data into a word segmentation form suitable for DistilBERT and inputs it into the classifier module;

[0082] Among them, x represents the original sample, x n represents its nearest neighbor sample in the feature space, x k represents another randomly selected sample, and γ represents a random number, usually drawn from a uniform distribution U(0,1).

[0083] In some embodiments, after completing feature selection, the feature engineering module divides the vehicle real-time data into an 80% training set and a 20% test set.

[0084] It can be understood that the feature selection method of mutual information is used to extract the key features of the original network traffic data, which can effectively retain the features that have a significant impact on the classification results and remove irrelevant features, thereby reducing the dimension of the data while ensuring the classification performance of the model; according to the extracted key features, the mutual information value between the features and the target variables is calculated, and the features with the strongest correlation are screened out, which can further improve the detection accuracy of the model; the SMOTE algorithm is used to balance the samples in the training set, which can increase the number of minority class samples to balance the category distribution, thereby improving the model's generalization ability for attack detection; the Token Embeddings technology is used to convert the test set and the balanced training set into text, and the data is converted into a segmentation form suitable for DistilBERT, which can effectively improve the efficiency of the model in processing data.

[0085] As a preferred embodiment, see Figure 2 , the classifier module assigns the corresponding vector representation according to the word segmentation form of DistilBERT, and uses a multi-head self-attention mechanism to process the vector representation in parallel to capture the deep connection between features. The expression is:

[0086]

[0087] Combine the feedforward neural network and layer normalization mechanism to perform vehicle network intrusion detection, and classify complex network attacks based on the detection results. The expression is:

[0088] FFN=max(0,XW1+b1)W2+b2

[0089]

[0090] Among them, Q represents query, K represents key, V represents value, and d k represents the dimension of the key, represents the scaling factor for normalization, X represents the input, W1 and b1 represent the learnable parameters of the first GELU fully connected layer, W2 and b2 represent the learnable parameters of the second fully connected layer, μ represents the mean, σ represents the standard deviation, and γ and β represent learnable parameters.

[0091] In some embodiments, the classifier module uses a classifier based on the DistilBERT model.

[0092] In some embodiments, the digital twin model is a digital twin model based on an intrusion detection system IDS; the application layer includes a visualization tool and a user interface.

[0093] In this embodiment, a multi-head self-attention mechanism is used to perform parallel processing of vector representations to capture the deep connections between features, and combined with a feedforward neural network and a layer normalization mechanism for Internet of Vehicles intrusion detection, which can further enhance the nonlinear expression and generalization capabilities of the model, thereby improving the classification performance of complex network attacks, so that the complex grammatical structure of network traffic can be fully captured, and in-depth analysis of data flow context information can be performed, thereby effectively improving the adaptability and accuracy of the IDS system.

[0094] Constructing a digital twin model based on the intrusion detection system IDS can effectively conduct a full study of the existing intrusion detection system IDS, so as to fully capture the complex grammatical structure of network traffic and conduct in-depth analysis of data flow context information, thereby effectively improving the adaptability and accuracy of the IDS system; the application layer includes visualization tools and user interfaces, which enable vehicle managers, security analysts and drivers to intuitively understand the vehicle's operating status, network traffic, potential threats and IDS response measures.

[0095] Embodiment 2:

[0096] This implementation provides a vehicle networking intrusion detection method, see Figure 3 , the method comprises the following steps:

[0097] Step S1: Collecting real-time vehicle data;

[0098] Step S2: constructing a digital twin model based on the collected real-time vehicle information, and using the digital twin model to perform Internet of Vehicles intrusion detection based on the real-time vehicle data to formulate an Internet of Vehicles intrusion detection strategy;

[0099] Step S3: Execute the Internet of Vehicles intrusion detection strategy and provide feedback on the strategy effect to update the data of the Internet of Vehicles intrusion detection strategy.

[0100] In this embodiment, based on the Internet of Vehicles intrusion detection system described in Embodiment 1, a corresponding Internet of Vehicles intrusion detection method is provided to implement the functions of the Internet of Vehicles intrusion detection system, thereby effectively improving the adaptability and accuracy of the IDS system.

[0101] Embodiment three:

[0102] This embodiment is based on the vehicle networking intrusion detection system described in Embodiment 1 and Embodiment 2, and provides corresponding experimental data for illustration, as follows:

[0103] The present invention uses a variety of data sets to train and test the IDS model to improve its adaptability in the Internet of Vehicles environment.

[0104] Two data sets in the intra-vehicle network and inter-vehicle network scenarios are selected to conduct experimental verification of the intrusion detection system proposed in the present invention, specifically including:

[0105] Vehicle-to-vehicle scenario dataset: The CICIDS2018 and CICIoT2023 datasets from the Canadian Institute for Cybersecurity contain a variety of attack types and provide real network traffic data in an off-vehicle network environment. The CICIoT2023 dataset covers 33 attack types in seven categories, including DDoS, DoS, reconnaissance, Web attacks, brute force cracking, camouflage, and Mirai, and is suitable for comprehensive detection of network attacks.

[0106] The CICIDS2018 dataset contains common attack behaviors such as brute force attacks, Heartbleed, Botnet, DoS and DDoS, Web application attacks, and internal penetration, providing the model with rich samples of off-vehicle network threats.

[0107] In-vehicle network scenario dataset: For in-vehicle networks, this paper uses the Car-Hacking and CICIoV2024 datasets. These datasets cover CAN bus communication data, including timestamp, CAN ID, DLC (data length code), and 8-byte data field (DATA[0]-DATA[7]), providing reliable training samples for the model in detecting abnormal CAN bus communication, ensuring the effectiveness of the model in detecting internal network intrusion behavior.

[0108] The above four data sets are attacked and tested by using four evaluation indicators: accuracy, precision, recall, and F1 score. The effect of the intrusion detection system proposed by the present invention is measured. The two data sets in the in-vehicle network scenario both achieve 100% accuracy. The confusion matrix heat map is shown in Figure 2. Figure 4 , Figure 5 , Figure 6 and Figure 7 shown.

[0109] The two datasets of the vehicle-to-vehicle network scenario are compared with other deep learning models, and the verification results are shown in Table 1, Table 2, Table 3 and Table 4 respectively.

[0110] Experiments show that the intrusion detection system of the present invention can be fully tested in a variety of attack scenarios in a connected vehicle environment, so as to comprehensively deal with diverse attacks inside and outside the vehicle in practical applications.

[0111] Table 1 Comparison of evaluation indicators of intrusion detection systems on the CICIoT2023 dataset

[0112] Model accuracy Accuracy Recall F1 score CNN 0.7814 0.7894 0.7814 0.7700 LSTM 0.7717 0.7791 0.7717 0.7629 BiLSTM 0.7832 0.7905 0.7832 0.7739 RNN 0.7507 0.7618 0.7507 0.7383 Model of the present invention 0.8396 0.8397 0.8396 0.8382

[0113] Table 2 Comparison of evaluation indicators of intrusion detection systems on the CICIDS2018 dataset

[0114] Model accuracy Accuracy Recall F1 score CNN 0.8748 0.8904 0.8748 0.8702 LSTM 0.8735 0.8768 0.8735 0.8724 BiLSTM 0.8782 0.8867 0.8782 0.8759 RNN 0.1811 0.3707 0.1811 0.0774 Model of the present invention 0.9097 0.9119 0.9097 0.9094

[0115] Table 3 Comparison of evaluation indicators of intrusion detection systems on the CICioV2024 dataset

[0116] Model accuracy Accuracy Recall F1 score CNN 1.0000 1.0000 1.0000 1.0000 LSTM 1.0000 1.0000 1.0000 1.0000 BiLSTM 1.0000 1.0000 1.0000 1.0000 RNN 1.0000 1.0000 1.0000 1.0000 Model of the present invention 1.0000 1.0000 1.0000 1.0000

[0117] Table 4 Comparison of evaluation indicators of intrusion detection systems on the Car-Hacking dataset

[0118] Model accuracy Accuracy Recall F1 score CNN 0.6434 0.7444 0.6434 0.6359 LSTM 0.6400 0.6655 0.6400 0.6369 BiLSTM 0.6462 0.7292 0.6462 0.6444 RNN 0.9944 0.9945 0.9944 0.9944 Model of the present invention 1.0000 1.0000 1.0000 1.0000

[0119] In the intrusion detection system of the Internet of Vehicles of the present invention, the system relies on digital twin technology to create a digital mapping of the virtual vehicle, and realizes a two-way data flow between the physical environment and the digital twin environment by synchronously collecting vehicle sensor data, thereby reducing data transmission delays and meeting the needs of real-time intrusion detection. The real-time update mechanism of the digital twin layer enables the model to obtain the analysis results of the digital mapping in the physical vehicle and achieve rapid response.

[0120] The above descriptions are merely embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A vehicle network intrusion detection system, characterized in that: The system comprises: Data collection layer, used to collect real-time vehicle data; The digital twin layer is used to build a digital twin model based on the collected real-time vehicle information, and use the digital twin model to perform Internet of Vehicles intrusion detection based on the real-time vehicle data to formulate an Internet of Vehicles intrusion detection strategy; The application layer is used to execute the Internet of Vehicles intrusion detection strategy and provide feedback on the strategy effect to update the data of the Internet of Vehicles intrusion detection strategy.

2. The vehicle networking intrusion detection system according to claim 1, characterized in that: The real-time vehicle data acquired by the data collection layer comes from vehicle-mounted sensors, GPS positioning systems, high-definition cameras, etc.

3. The vehicle networking intrusion detection system according to claim 1, characterized in that: The constructed digital twin model includes data preprocessing module, feature engineering module and classifier module; The data preprocessing module performs sample balancing and category label encoding processing on the real-time vehicle data, and transmits the processed data to the feature engineering module; The feature engineering module extracts key features of the original network traffic data based on the real-time vehicle data after sample balancing and category label encoding, and selects a feature subset with the highest mutual information value based on the extracted key features to complete feature selection; The classifier module performs vehicle network intrusion detection based on the selected features, classifies complex network attacks based on the detection results, and formulates vehicle network intrusion detection strategies based on the classification results.

4. The vehicle networking intrusion detection system according to claim 3, characterized in that: The data preprocessing module uses random sampling technology to perform sample balancing processing on various samples in the real-time vehicle data, and processes infinite values ​​and NaN values ​​in the data through the average value replacement strategy. At the same time, LabelEncoder is used to encode the category labels of text types.

5. The vehicle networking intrusion detection system according to claim 3, characterized in that: The feature engineering module uses a mutual information feature selection method to extract key features of raw network traffic data; According to the extracted key features, the mutual information value between the features and the target variable is calculated to screen out the features with the strongest correlation. The expression is: Calculate the mutual information between each feature and the target variable, and select the feature subset with the highest mutual information value; Among them, X represents the feature variable, Y represents the target variable, p(x,y) is the joint probability distribution, and p(x) and p(y) are the marginal probability distributions respectively.

6. The vehicle networking intrusion detection system according to claim 5, characterized in that: After completing feature selection, the real-time vehicle data is divided into a training set and a test set, and several rounds of iterative optimization training are set to optimize the parameters of the digital twin model; The feature engineering module uses the SMOTE algorithm to balance the samples in the training set, and the expression is: x′=x+γ·(x n -x k ) The feature engineering module uses Token Embeddings technology to perform text conversion on the test set and the balanced training set, and converts the data into a word segmentation form suitable for DistilBERT and inputs it into the classifier module; Among them, x represents the original sample, x n represents its nearest neighbor sample in the feature space, x k represents another randomly selected sample, and γ represents a random number.

7. The vehicle networking intrusion detection system according to claim 3, characterized in that: The classifier module assigns corresponding vector representations according to the word segmentation form of DistilBERT, and uses a multi-head self-attention mechanism to process the vector representations in parallel to capture the deep connection between features. The expression is: Combine the feedforward neural network and layer normalization mechanism to perform vehicle network intrusion detection, and classify complex network attacks based on the detection results. The expression is: FFN=max(0,XW1+b1)W2+b2 Among them, Q represents query, K represents key, V represents value, and d k represents the dimension of the key, represents the scaling factor for normalization, X represents the input, W1 and b1 represent the learnable parameters of the first GELU fully connected layer, W2 and b2 represent the learnable parameters of the second fully connected layer, μ represents the mean, σ represents the standard deviation, and γ and β represent learnable parameters.

8. The vehicle networking intrusion detection system according to claim 7, characterized in that: The classifier module adopts a classifier based on the DistilBERT model.

9. The vehicle networking intrusion detection system according to claim 6, characterized in that: After completing feature selection, the feature engineering module divides the vehicle real-time data into 80% training set and 20% test set.

10. A vehicle network intrusion detection method, characterized in that: The method comprises the following steps: Collect real-time vehicle data; Based on the collected real-time vehicle information, a digital twin model is constructed, and the digital twin model is used to perform Internet of Vehicles intrusion detection based on the real-time vehicle data to formulate an Internet of Vehicles intrusion detection strategy; Execute the IoV intrusion detection strategy and provide feedback on the strategy effect to update the data of the IoV intrusion detection strategy.

Citation Information

Patent Citations

  • Internet of vehicles intrusion detection method and device based on improved convolutional neural network

    CN114157513A

  • Attack pattern extraction method based on phrase similarity

    CN115759081A

  • Vehicle intrusion detection system and method based on Hybrid OfficientNet model

    CN119106712A

  • Cyber digital twin simulator for automotive security assessment based on attack graphs

    US20220150270A1

  • Artificial Intelligence-based Quantified Cyber Defense Control Model

    US20240314158A1