CAN bus flow anomaly detection method based on unsupervised deep learning
By building an unsupervised deep learning model, extracting the features of vehicle CAN bus data and performing abnormal detection, the problem of difficult to identify unknown attacks in the prior art is solved, and real-time efficient abnormal detection of vehicle CAN bus data is achieved.
Patent Information
- Application Number
- CN202510202792.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-02-24
AI Technical Summary
The existing vehicle-mounted bus IDS technology is difficult to effectively identify unknown attacks, and the method based on the supervised learning model performs poorly when detecting unknown attacks.
Using the CAN bus traffic anomaly detection method based on unsupervised deep learning, data feature extraction and anomaly detection are carried out by building a deep learning model including feature embedding, timing decomposition, feature enhancement and prediction reconstruction modules.
Real-time monitoring and abnormal identification of vehicle CAN bus data is realized, the need for manual intervention is reduced, unknown attack patterns can be effectively identified, and high detection accuracy and wide applicability.
Smart Images

Figure CN120050098A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of vehicle information security, and particularly to a CAN bus traffic anomaly detection method based on unsupervised deep learning. Background Art
[0002] The existing research on in-vehicle bus IDS can be classified into three categories according to the methods adopted: rule-based methods, supervised machine learning model-based methods, and unsupervised machine learning model-based methods.
[0003] (M. Müter and N. Asaj, "Entropy-based anomaly detection for in-vehicle networks," in 2011 IEEE Intelligent Vehicles Symposium (IV), 2011, pp. 1110-1115: IEEE.) and (H. Olufowobi, C. Young, J. Zambreno, and G. Bloom, "SAIDuCANT: Specification-based automotive intrusion detection using controller area network (CAN) timing," IEEE Transactions on Vehicular Technology, vol. 69, no. 2, pp. 1484-1494, 2019.) adopted statistical analysis methods based on high-dimensional entropy and data frequency for IDS research; (V. Tanksale, "Intrusion detection for controller area network using support vector machines," presented at the 2019 IEEE 16th international conference on mobile ad hoc and sensor systems workshops (MASSW), 2019.) used machine learning models such as support vector machines (SVM) to analyze data features. Such statistical analysis methods and machine learning models usually adopt a fixed feature extraction mode, that is, designing an analysis model according to in-vehicle bus rules, so they are highly interpretable and easy to implement. However, the fixed feature extraction mode cannot effectively capture the complexity of attacks, is difficult to adapt to the requirements of different scenarios, and its accuracy and detection ability are difficult to meet the requirements of modern vehicles for IDS. In the latest research, researchers tend to use deep learning models to extract features and classify data traffic.(P.Cheng,M.Han,A.Li,and F.J.I.J.o.I.S.Zhang,"STC-IDS:Spatial–temporal correlation feature analyzing based intrusion detection system for intelligent connected vehicles,"vol.37,no.11,pp.9532-9561,2022.)Convert in-vehicle traffic into a two-dimensional binary matrix and extract the spatial features of in-vehicle traffic based on a convolutional neural network (CNN) model; (A.R.Javed,S.Ur Rehman,M.U.Khan,M.Alazab,and T.Reddy,"CANintelliIDS:Detecting in-vehicle intrusion attacks on a controller area network using CNN and attention-based GRU,"IEEE transactions on network science engineering,vol.8,no.2,pp.1456-1466,2021.)Further combine the self-attention mechanism with the gated recurrent unit (GRU) model to extract more valuable features and improve the detection accuracy.
[0004] The above methods are all based on supervised learning models, and most of them have high anomaly detection accuracy on datasets with known attack types. However, the limitation of these models is that they can only defend against known attack types existing in the training dataset and cannot cope with unknown attacks. In contrast, unsupervised learning models only require normal data for training without the need to include attack data, so they show greater robustness in detecting unknown attacks. (S. Zhuo, Nuo Li, and Kui Ren, "HistCAN: A real-time CAN IDS with enhanced historical traffic learning capability.") A hybrid autoencoder was constructed by combining CNN and multi-layer perceptron (MLP), and the anomaly score was detected by reconstructing the input sequence and analyzing the correlation between the original sequence and the reconstructed sequence. Although the autoencoder-based CAN IDS meets the requirements of unsupervised training, simple CNN or MLP networks are not sufficient to extract complex time series information from in-vehicle traffic data messages. It is found that models based on time series prediction analysis are more suitable for the feature analysis of in-vehicle network traffic data. The literature (A. Taylor, S. Leblanc, and N. Japkowicz, "Anomaly detection in automobile control network data with long short-term memory networks," in 2016 IEEE international conference on data science and advanced analytics (DSAA), 2016, pp. 130-139: IEEE) uses LSTM to predict future sequences for intrusion detection; (H. Sun, M. Chen, J. Weng, Z. Liu, and G. Geng, "Anomaly detection for in-vehicle network using CNN-LSTM with attention mechanism," IEEE Transactions on Vehicular Technology, vol. 70, no. 10, pp. 10880-10893, 2021.) further combines LSTM and attention mechanism for time series prediction. However, the performance of LSTM is still not sufficient to fully capture the long-term sequence information of in-vehicle bus messages; and the attention mechanism of neural networks poses greater challenges to hardware and inference time, making it difficult to meet the actual needs of intelligent connected vehicles. Summary of the Invention
[0005] The object of the present invention is to provide a CAN bus traffic anomaly detection method based on unsupervised deep learning in view of the deficiencies of the prior art.
[0006] The object of the present invention is achieved by the following technical solutions: A CAN bus traffic anomaly detection method based on unsupervised deep learning, comprising the following steps:
[0007] (1) Generate a CAN bus attack test set: Collect vehicle CAN bus traffic data, perform data preprocessing, and use it as a training set; Design a message injection attack method for the CAN bus, perform injection attacks on a real vehicle, and collect data as a CAN injection test set;
[0008] (2) Construct an unsupervised deep learning anomaly detection model, including a feature embedding module, a time series decomposition module, a feature enhancement module, and a prediction reconstruction module; wherein, the feature embedding module is used to convert the CAN bus data sequence into a one-dimensional time series feature vector that can be trained by the model; the time series decomposition module is used to decompose the time series feature vector into multiple periodic components, and generate a two-dimensional feature map through a fast Fourier transform layer and a linear fully connected layer; the feature enhancement module is used to perform high-dimensional feature extraction on the two-dimensional feature map, and realize the feature dimension increase first and then dimension reduction through a multi-layer convolutional neural network; the prediction reconstruction module is used to convert the high-dimensional feature into a one-dimensional prediction sequence, and generate a prediction result consistent with the length of the input sequence through a flattening layer and a fully connected layer;
[0009] (3) Train the unsupervised deep learning anomaly detection model: Input the CAN bus data training set collected in step (1) into the unsupervised deep learning anomaly detection model designed in step (2), and use the reconstruction error between the output sequence and the input sequence as the loss function and anomaly score for model training;
[0010] (4) Detect the CAN bus traffic data: Input the CAN bus data test set collected in step (1) into the model trained in step (3), output the anomaly score, and judge whether the data is abnormal by comparing the anomaly score with the threshold. If there is abnormal data, an alarm is triggered.
[0011] Further, the step (1) includes the following sub-steps:
[0012] (1.1) Collect vehicle CAN bus data packets in the normal state; Obtain several groups of CAN bus binary data frames in different vehicle operating states, that is, the training set; Replay one of the groups in the original order on the vehicle CAN bus, and observe whether the vehicle generates corresponding responses without other operations;
[0013] (1.2) If the vehicle does not respond to the replay operation in step (1.1), it indicates that this operation cannot be injected as an attack data frame; if there is a response, divide the data frame group into two groups in the middle in sequence, inject them into the vehicle respectively to observe whether there is a response, and select the group with a response as the data frame group to be injected next time;
[0014] (1.3) Repeat the steps of grouping, replaying, and observing the response in step (1.2) until the remaining data frame group contains only one single data frame, which is the data frame that can be injected for attack; inject this data frame into the vehicle CAN bus at a certain time interval, and at the same time collect the CAN bus traffic data to obtain the attack data set under the injection of this data frame;
[0015] (1.4) Repeat the above steps for the data frame groups collected in different operations in step (1.1) to obtain multiple CAN bus attack data sets under the injection of different data frames, that is, the test set.
[0016] Further, the step (2) includes the following sub-steps:
[0017] (2.1) Based on the CAN bus data obtained in step (1), input it into the feature embedding module to obtain a one-dimensional feature vector that can be trained by the model; the feature embedding module consists of a feature encoder and a position encoder; the feature encoder is a layer of linear fully connected network, which is used to convert the shallow low-dimensional CAN traffic into deep multi-dimensional time series features; the position encoding is to map the position information of each data frame into a two-dimensional space by combining sine and cosine functions, giving strong correlation to the data with close time distance and weak correlation to the data with far time distance; the outputs of the two encoders are directly added to obtain the output vector of the feature embedding module;
[0018] (2.2) Based on the time series feature vector obtained in step (2.1), input it into the time series decomposition module to obtain a two-dimensional feature map; the time series decomposition module consists of a fast Fourier transform layer and multiple linear fully connected layers in parallel. Input the result vector of the feature embedding module in step (2.1) into the fast Fourier transform layer to obtain multiple periods contained in the sequence, decompose the original sequence into vector groups with different lengths and different numbers according to the k different time periods with the strongest intensity, input each vector group into the corresponding fully connected layer according to different periods, and add a new dimension to the output vector for parallel operation to obtain a two-dimensional feature map;
[0019] (2.3) Based on the two-dimensional feature map obtained in step (2.2), input it into the feature enhancement module to obtain high-dimensional features; the feature enhancement module consists of two layers of convolutional neural networks. The first layer contains a 4-channel convolutional layer, and the convolutional kernel sizes of each channel are 1x1, 3x3, 5x5, and 7x7 respectively. The convolutional stride is 1 for all channels. After convolution, the number of channels becomes one-fourth of the original feature map. The boundary padding of the convolution ensures that the size of the two-dimensional feature map remains unchanged. After convolution of each channel, they are stacked according to the channel dimension of the output feature map to form a high-dimensional feature map with four times the number of input channels. The result of the first layer of convolution is subjected to GeLU activation processing and then input into the second layer; the convolutional structure of the second layer is the same as that of the first layer. The number of input channels is four times the original number of channels, and the number of output channels is the original number of channels, forming an inverted residual structure to complete feature enhancement; the output of the convolutional layer is subjected to GeLU activation as the result of the enhancement module;
[0020] (2.4) Based on the high-dimensional features obtained in step (2.3), input them into the prediction and reconstruction module to obtain a prediction sequence; the prediction and reconstruction module consists of a flattening layer and a fully connected layer. Use the flattening layer to convert the high-dimensional feature map into a one-dimensional feature vector, and the fully connected layer aligns the length of the feature vector with the input vector to generate a prediction sequence; the prediction sequence output by the prediction and reconstruction module is the output data of the model.
[0021] Further, step (3) includes the following sub-steps:
[0022] (3.1) Process the data packets collected in step (1), extract the ID of the CAN data as the first feature, process the timestamp of the CAN data, extract the time interval between adjacent CAN frames as the second feature, and extract the time interval of CAN frames with the same ID as the third feature. The three features of each CAN frame are combined into a feature vector at each time point of the time series;
[0023] (3.2) Window the feature vectors obtained in step (3.1). Take a window for every 100 frames, and slide 1 frame each time to get a new window; input the sequence of 100-frame feature vectors in a window into the model designed in step (2) to obtain an output sequence; calculate the root mean square error between the output prediction vector sequence and the next window of the input sequence as the loss function for model training, and use the backpropagation algorithm to train the model;
[0024] (3.3) Calculate the root mean square error values obtained by inferring the data of each window in the training set on the optimal model in step (3.2), and average them to obtain the anomaly scoring threshold of this training set.
[0025] Further, the specific process of step (4) is as follows:
[0026] Collect CAN bus data in real time using the method in step (1), process the collected data into feature vectors in units of windows by the method in step (3.1), input them into the model after the training in step (3.2), calculate the root mean square error between the output predicted sequence feature vectors and the next window vector of the input vector to obtain the anomaly score of the window; compare the obtained anomaly score with the anomaly score threshold obtained in step (3.3). If it is higher than the threshold, it indicates that the window contains abnormal data. If it is lower than the threshold, it indicates that all the data in the window is normal data; if multiple consecutive windows contain abnormal data, it indicates that there is an obvious anomaly in the data stream, and the system gives an alarm prompt.
[0027] To achieve the above object, the present invention also provides a CAN bus traffic anomaly detection device based on unsupervised deep learning, including one or more processors for implementing the above-mentioned CAN bus traffic anomaly detection method based on unsupervised deep learning.
[0028] To achieve the above object, the present invention also provides an electronic device, including a memory and a processor, the memory is coupled to the processor; wherein, the memory is used to store program data, and the processor is used to execute the program data to implement the above-mentioned CAN bus traffic anomaly detection method based on unsupervised deep learning.
[0029] To achieve the above object, the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the above-mentioned CAN bus traffic anomaly detection method based on unsupervised deep learning.
[0030] The beneficial effects of the present invention are as follows: by adopting unsupervised deep learning technology to construct a CAN bus intrusion detection model, it realizes the real-time monitoring and anomaly recognition of vehicle CAN bus data, and greatly reduces the need for manual intervention; this method first proposes an unsupervised learning intrusion detection method for CAN bus. Without the need for abnormal data for training, it can effectively identify potential attack behaviors, realize early warning of unknown attack patterns, and ensure high detection accuracy similar to supervised learning. It realizes real-time and efficient intrusion detection of a large amount of CAN bus data, and its effect is better than the prior art, with wide applicability and transferability. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 It is the overall structure diagram of the CAN bus anomaly detection model designed by the method of the present invention;
[0032] Figure 2 It is the structure schematic diagram of the device of the present invention;
[0033] Figure 3 It is the schematic diagram of an electronic device of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0034] Here, exemplary embodiments will be described in detail, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present invention as detailed in the appended claims.
[0035] The present invention will be described in detail below with reference to the accompanying drawings. Without conflict, the features in the following embodiments and implementation manners can be combined with each other.
[0036] The core technology of the present invention is to design a CAN (Controller Area Network) bus anomaly detection model based on unsupervised deep learning, and to implement a data set generation, model training, and anomaly detection method based on this, so as to achieve an efficient, accurate CAN bus traffic anomaly detection method with the ability to identify unknown attacks.
[0037] See Figure 1 , the present invention proposes a CAN bus traffic anomaly detection method based on unsupervised deep learning, including the following steps:
[0038] (1) Generate a CAN bus attack test set: Based on the normal traffic data of the CAN bus of a real vehicle, perform data preprocessing as the training set; design a message injection attack method for the CAN bus, perform injection attacks on a real vehicle, and collect data as the CAN injection test set; specifically including the following sub-steps:
[0039] (1.1) Selection of injection attack frames: Collect the CAN bus data packets of the vehicle in the normal state; design experimental operations, select several electronic control units (ECUs) that may transmit data on the CAN bus, perform relevant operations on the vehicle while collecting the binary data frames in the operation state, and obtain several data frame traffic groups containing individual operations, that is, the training set; replay one of the groups in the original order on the vehicle CAN bus and observe whether the vehicle generates a response corresponding to the operation;
[0040] (1.2) Group replay: If the vehicle does not generate a response to the replay operation in step (1.1), it means that this operation cannot be injected as an attack data frame; if the vehicle has corresponding actions, it means that the CAN bus message controlling this operation is in this data frame group; divide the frame traffic group with a response into two groups before and after in the middle according to the time stamp order, and inject them into the vehicle twice to observe whether a corresponding response is generated. If there is still a response, it means that the specific message exists in this group;
[0041] (1.3) Data collection: Repeat the steps of grouping, replaying, and observing responses in step (1.2) multiple times until only one data frame remains in the data frame group, which is the control information corresponding to this operation on the CAN bus; Inject this data frame into the vehicle CAN bus at a certain time interval (in this embodiment, it can be 10 milliseconds, 20 milliseconds, or 50 milliseconds), and simultaneously collect the CAN bus traffic data to obtain an attack data set under the injection of this data frame.
[0042] Repeat the experiment for the data frame groups collected in different operations according to the above method to obtain multiple CAN bus attack data sets under different data frame injections, that is, the CAN injection test set.
[0043] (2) Construction of the anomaly detection neural network model: Design a neural network model according to the timing characteristics of the CAN bus to construct an effective unsupervised deep learning anomaly detection model. The neural network model consists of a feature embedding module, a feature extraction module, a feature prediction module, and a reconstruction module; The feature embedding module is responsible for converting the CAN bus data sequence into a feature vector; The feature extraction module is responsible for converting the data into deep feature information; The feature prediction module is responsible for using the deep features to predict the corresponding feature vector of the next data; The reconstruction module is responsible for re-encoding the feature vector into the initial sequence format. The unsupervised deep learning anomaly detection model mainly includes a feature embedding module, a time series decomposition module, a feature enhancement module, and a prediction reconstruction module.
[0044] (2.1) Based on the CAN bus data sequence obtained in step (1), input it into the feature embedding module to obtain a one-dimensional feature vector that can be trained by the model, that is, the timing feature vector.
[0045] Feature embedding module: The feature embedding module consists of two parts: a feature encoder and a position encoder;
[0046] The feature encoder is a layer of trainable linear fully connected network used to convert shallow low-dimensional CAN traffic into deep multi-dimensional timing features;
[0047] Position encoding is to map the position information of each data frame into a two-dimensional space using a combination of sine and cosine functions, giving strong correlation to data with close time distances and weak correlation to data with far time distances;
[0048] The outputs of the two encoders are directly added to obtain the output vector of the feature embedding module.
[0049] (2.2) Based on the timing feature vector obtained in step (2.1), input it into the time series decomposition module to obtain a two-dimensional feature map.
[0050] Temporal Decomposition Module: The temporal decomposition module consists of a Fast Fourier Transform layer (FFT layer) and multiple linear fully connected layers in parallel;
[0051] The FFT layer is used to extract the periodic components of the time series. The result vector of the feature embedding module described in (2.1) is input into the FFT layer, and the FFT is performed on the input sequence to obtain multiple periodic numerical values contained in the time series. The same original sequence is decomposed according to the three different time period lengths with the strongest intensity, and three groups of vector groups with different numbers and each with the respective period as the length are obtained;
[0052] The linear fully connected layer is used to align the lengths of the temporal feature vectors obtained by decomposing different periods. Each vector group is input into the fully connected layer with different parameters according to the period, and feature vectors of the same length are output; By adding a new dimension and performing a parallel operation on the feature vectors, several two-dimensional feature maps of the same size can be obtained;
[0053] (2.3) Based on the two-dimensional feature maps obtained in step (2.2), input them into the feature enhancement module to obtain high-dimensional features.
[0054] Feature Enhancement Module: The feature enhancement module consists of two layers of convolutional neural networks;
[0055] The overall structures of the two layers of convolutional neural networks are the same; it includes convolutional operations with four channels, and the kernel sizes of the convolutional kernels in each channel are 1x1, 3x3, 5x5, and 7x7 respectively, and the convolutional stride is 1, and the size of the feature map remains unchanged before and after the convolutional calculation; A GeLU activation function is set after the convolutional layer to add a non-linear factor;
[0056] In the first layer, the number of channels after convolution remains unchanged, and the four convolutional result feature maps are stacked to form a high-dimensional feature map with four times the number of input channels;
[0057] In the second layer, the number of input channels is set to four times the original number of channels, and the output is the original number of channels. The number of channels of the feature map does not change in the input and output of the feature enhancement module; An inverse residual structure of first increasing the dimension and then decreasing the dimension is formed inside the feature enhancement module to achieve the feature enhancement effect; The output of the convolutional layer is activated by GeLU as the result of the enhancement module.
[0058] (2.4) Based on the high-dimensional features obtained in step (2.3), input them into the prediction and reconstruction module to obtain a one-dimensional prediction sequence.
[0059] Prediction and Reconstruction Module: The prediction and reconstruction module consists of a flattening layer and a fully connected layer;
[0060] The output of the feature enhancement module is a two-dimensional feature map. The flattening layer is used to convert the two-dimensional matrix into a one-dimensional feature vector. The fully connected layer aligns the length of the feature vector with the input vector, that is, converts the length to be equal to the window length, to generate the prediction sequence. The prediction sequence output by the prediction reconstruction module is the output data of the model.
[0061] (3) Training of the neural network: Input the normal CAN bus data collected in step (1) into the neural network designed in step (2). Use the reconstruction error between the output sequence and the input sequence as the loss function and the anomaly score to train the model, and realize anomaly detection. Specifically, it includes the following sub-steps:
[0062] (3.1) Data feature extraction: Process the data packets collected in step (1), extract the ID of the CAN data as the first feature, process the timestamp of the CAN data, extract the time interval between adjacent CAN frames as the second feature, extract the time interval of CAN frames with the same ID as the third feature, and merge the three features of each CAN frame into the feature vector at each time point of the time series;
[0063] (3.2) Model training: Based on the CAN frame feature vector sequence calculated in step (3.1), this method windows it, takes a window for every 100 frames, and slides 1 frame each time to get a new window; each time the model selects the feature vector sequence data of 100 frames in a window as the model input;
[0064] The model output is a prediction vector sequence. Calculate the root mean square error between this output sequence and the data sequence of the next window of the input as the loss function of the model, and use the backpropagation algorithm to train the model;
[0065] (3.3) Threshold selection: The training strategy in step (3.2) improves the model's prediction ability for normal data. When abnormal data is input into the model, it will generate an incorrect prediction sequence; therefore, calculate the root mean square error values obtained by inferring all normal window data in the training set on the optimal model in step (3.2), and use the extreme value theory algorithm to find the anomaly score threshold of this training set.
[0066] (4) Anomaly detection of traffic data: Use the method in step (1) to collect CAN bus data in real time, process the collected data into window-based feature vectors in the same way as in step (3.1), input them into the model after the training in step (3.2), calculate the root mean square error between the output prediction sequence feature vector and the vector of the next window of the input vector, and the anomaly score of the window can be obtained; compare the obtained anomaly score with the anomaly score threshold obtained in step (3.3). If it is higher than the threshold, it means that the window contains abnormal data, and if it is lower than the threshold, it means that all the data in the window is normal; if multiple consecutive windows contain abnormal data, it means that there is an obvious anomaly in the data stream, and the system gives an alarm prompt.
[0067] Example:
[0068] Data was extracted from a Tesla Model 3, attacks targeting the vehicle's door lock, headlights, horn, and brakes were designed, control of the above components was achieved on the CAN bus, and the CAN bus attack dataset of the present invention was obtained by collecting attack data. An implementation example of the CAN bus anomaly detection model of the present invention was implemented on a device equipped with an Intel Core i7-13700K processor and 32GB of memory. By using all the parameter values listed in the specific implementation manner, it can be seen from the experimental results that the method of the present invention is superior to the existing methods in terms of anomaly detection effect, can accurately identify abnormal data frames in the CAN bus, and can effectively distinguish normal data from abnormal data; the detection performance of the experimental verification model under different attack types was verified, and the results show that this method can accurately identify abnormal traffic in unknown attack scenarios and exhibits excellent generalization ability. As shown in Table 1 below, compared with traditional detection methods (DCNN, HistCAN, LSTM, Hybrid Model), this method performs excellently in identifying complex time-series data attacks and can be applied to the real-time anomaly detection system of vehicle CAN buses.
[0069] Table 1 Anomaly detection effect data of this method and existing methods:
[0070] Detection accuracy Denial-of-service attack Malicious injection attack Fuzzy attack DCNN 0.764 0.799 0.821 HistCAN 0.368 0.562 0.306 LSTM 0.642 0.737 0.791 Hybrid Model 0.666 0.677 0.744 This method 0.973 0.959 0.873
[0071] Corresponding to the embodiment of the CAN bus traffic anomaly detection method based on unsupervised deep learning described above, the present invention also provides an embodiment of a CAN bus traffic anomaly detection device based on unsupervised deep learning.
[0072] See Figure 2 , the CAN bus traffic anomaly detection device based on unsupervised deep learning provided by the embodiment of the present invention includes one or more processors for implementing the CAN bus traffic anomaly detection method based on unsupervised deep learning in the above embodiment.
[0073] The embodiment of the CAN bus traffic anomaly detection device based on unsupervised deep learning of the present invention can be applied to any device with data processing capabilities, and the any device with data processing capabilities can be a device or apparatus such as a computer. The device embodiment can be implemented by software, or by hardware, or by a combination of software and hardware. Taking software implementation as an example, as a logically meaningful device, it is formed by the processor of any device with data processing capabilities where it is located reading the corresponding computer program instructions in the non-volatile memory into the memory for operation. From the hardware level, such as Figure 2As shown, it is a hardware structure diagram of any device with data processing capabilities where the CAN bus traffic anomaly detection device based on unsupervised deep learning of the present invention is located. Except for Figure 2 the shown processor, memory, network interface, and non-volatile memory, any device with data processing capabilities where the device in the embodiment is located usually may further include other hardware according to the actual functions of the device with data processing capabilities, which will not be elaborated herein.
[0074] For the implementation processes of the functions and roles of each unit in the above device, please refer to the implementation processes of the corresponding steps in the above method for details, which will not be elaborated herein.
[0075] For the device embodiment, since it basically corresponds to the method embodiment, relevant parts can refer to the partial description of the method embodiment. The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of the present invention. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0076] Corresponding to the embodiment of the method for detecting CAN bus traffic anomalies based on unsupervised deep learning described above, an embodiment of the present application further provides an electronic device, including: one or more processors; a memory for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the method for detecting CAN bus traffic anomalies based on unsupervised deep learning as described above. As Figure 3 shown, it is a hardware structure diagram of any device with data processing capabilities where the method for detecting CAN bus traffic anomalies based on unsupervised deep learning provided by the embodiment of the present application is located. Except for Figure 3 the shown processor, memory, DMA controller, disk, and non-volatile memory, any device with data processing capabilities where the device in the embodiment is located usually may further include other hardware according to the actual functions of the device with data processing capabilities, which will not be elaborated herein.
[0077] Corresponding to the embodiment of the method for detecting CAN bus traffic anomalies based on unsupervised deep learning described above, an embodiment of the present invention further provides a computer-readable storage medium, on which a program is stored. When the program is executed by a processor, the method for detecting CAN bus traffic anomalies based on unsupervised deep learning in the above embodiment is implemented.
[0078] The computer-readable storage medium may be an internal storage unit of any data processing-capable device described in any of the foregoing embodiments, such as a hard disk or a memory. The computer-readable storage medium may also be any data processing-capable device, such as a plug-in hard disk, a Smart Media Card (SMC), an SD card, a Flash Card, etc. equipped on the device. Further, the computer-readable storage medium may also include both an internal storage unit of any data processing-capable device and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by any data processing-capable device, and may also be used to temporarily store the data that has been output or is to be output.
[0079] The foregoing is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the scope of protection of the present invention.
[0080] The above embodiments are only used to illustrate the design concept and features of the present invention, and the purpose is to enable those skilled in the art to understand the content of the present invention and implement it accordingly. The scope of protection of the present invention is not limited to the above embodiments. Therefore, any equivalent changes or modifications made based on the principles and design concepts disclosed by the present invention shall be within the scope of protection of the present invention.
Claims
1. A CAN bus traffic anomaly detection method based on unsupervised deep learning, characterized in that: The following steps are involved: (1) Generate a CAN bus attack test set: Collect vehicle CAN bus traffic data and perform data preprocessing as a training set; design a CAN bus message injection attack method, perform injection attacks on real vehicles, and collect data as a CAN injection test set; (2) Constructing an unsupervised deep learning anomaly detection model, comprising a feature embedding module, a time series decomposition module, a feature enhancement module and a prediction reconstruction module; wherein the feature embedding module is used to convert the CAN bus data sequence into a one-dimensional time series feature vector that can be trained by the model; the time series decomposition module is used to decompose the time series feature vector into multiple periodic components, and generate a two-dimensional feature map through a fast Fourier transform layer and a linear fully connected layer; the feature enhancement module is used to extract high-dimensional features from the two-dimensional feature map, and realize the feature dimension increase and then dimension reduction through a multi-layer convolutional neural network; the prediction reconstruction module is used to convert the high-dimensional features into a one-dimensional prediction sequence, and generate a prediction result consistent with the length of the input sequence through a flattening layer and a fully connected layer; (3) training the unsupervised deep learning anomaly detection model: inputting the CAN bus data training set collected in step (1) into the unsupervised deep learning anomaly detection model designed in step (2), and training the model using the reconstruction error between the output sequence and the input sequence as the loss function and anomaly score; (4) Detecting CAN bus traffic data: Input the CAN bus data test set collected in step (1) into the model trained in step (3), output an anomaly score, and compare the anomaly score with the threshold to determine whether the data is abnormal. If abnormal data exists, an alarm is triggered.
2. The CAN bus traffic anomaly detection method based on unsupervised deep learning according to claim 1 is characterized in that: The step (1) comprises the following sub-steps: (1.1) Collect vehicle CAN bus data packets under normal conditions; obtain several CAN bus binary data frame groups under different vehicle operation conditions, i.e., training sets; replay one of the groups in its original order on the vehicle CAN bus to observe whether the vehicle generates a corresponding response without other operations; (1.2) If the vehicle does not respond to the replay operation in step (1.1), it means that the operation cannot be injected as an attack data frame; if there is a response, the data frame group is divided into two groups in the middle in sequence, and injected into the vehicle to observe whether there is a response, and the group with a response is selected as the data frame group for the next injection; (1.3) Repeat the steps of grouping, replaying, and observing the response in step (1.2) until the remaining data frame group contains only one single data frame, which is the data frame that can be injected into the attack; inject this data frame into the vehicle CAN bus at a certain time interval, and collect the CAN bus traffic data at the same time to obtain the attack data set under this data frame injection; (1.4) Repeat the above steps for the data frame groups collected by different operations in step (1.1) to obtain a CAN bus attack data set under multiple groups of different data frame injections, namely, a test set.
3. The CAN bus traffic anomaly detection method based on unsupervised deep learning according to claim 2 is characterized in that: The step (2) comprises the following sub-steps: (2.1) Based on the CAN bus data obtained in step (1), the feature embedding module is input to obtain a one-dimensional feature vector that can be trained by the model; The feature embedding module is composed of a feature encoder and a position encoder; the feature encoder is a layer of linear fully connected network, which is used to convert shallow low-dimensional CAN traffic into deep multi-dimensional time series features; Position encoding uses a combination of sine and cosine functions to map the position information of each data frame into a two-dimensional space, giving strong correlation to data with close time distance and weak correlation to data with long time distance. The outputs of the two encoders are directly added to obtain the output vector of the feature embedding module. (2.2) Based on the time series feature vector obtained in step (2.1), the time series decomposition module is input to obtain a two-dimensional feature map; the time series decomposition module is composed of a fast Fourier transform layer and multiple linear fully connected layers in parallel, the result vector of the feature embedding module in step (2.1) is input into the fast Fourier transform layer to obtain multiple periods contained in the sequence, and the original sequence is decomposed into vector groups of different lengths and numbers according to the k different time periods with the strongest intensity, and each vector group is input into the corresponding fully connected layer according to different periods, and the output vector is added with a new dimension for parallel operation to obtain a two-dimensional feature map; (2.3) Based on the two-dimensional feature map obtained in step (2.2), the feature enhancement module is input to obtain high-dimensional features; the feature enhancement module is composed of two layers of convolutional neural network, the first layer includes a 4-channel convolution layer, the convolution kernel size of each channel is 1x1, 3x3, 5x5, 7x7, the convolution step size is 1, the number of channels after convolution becomes one-fourth of the original feature map, the convolution boundary filling ensures that the size of the two-dimensional feature map remains unchanged, and each channel is superimposed according to the channel dimension of the output feature map after convolution to form a high-dimensional feature map with four times the number of input channels; the result of the first layer of convolution is processed by GeLU activation and then input to the second layer; The convolution structure of the second layer is consistent with that of the first layer. The number of input channels is four times the original number of channels, and the number of output channels is one times the original number of channels, forming an inverse residual structure to complete feature enhancement; the output of the convolution layer is GeLU activated as the result of the enhancement module; (2.4) Based on the high-dimensional features obtained in step (2.3), the prediction sequence is input into the prediction reconstruction module; the prediction reconstruction module consists of a flattening layer and a fully connected layer. The flattening layer is used to convert the high-order feature map into a one-dimensional feature vector. The fully connected layer aligns the length of the feature vector with the input vector to generate a prediction sequence; the prediction sequence output by the prediction reconstruction module is the output data of the model.
4. The CAN bus traffic anomaly detection method based on unsupervised deep learning according to claim 3 is characterized in that: The step (3) comprises the following sub-steps: (3.1) Process the data packets collected in step (1), extract the ID of the CAN data as the first feature, process the timestamp of the CAN data, extract the time interval between adjacent CAN frames as the second feature, extract the time interval of CAN frames containing the same ID as the third feature, and merge the three features of each CAN frame into a feature vector at each time point of the time series; (3.2) Window the feature vector obtained in step (3.1), draw a window every 100 frames, and slide 1 frame each time to get a new window; input the feature vector sequence of 100 frames in a window into the model designed in step (2) to obtain the output sequence; calculate the root mean square error between the output prediction vector sequence and the next window of the input sequence as the loss function of model training, and use the back propagation algorithm to train the model; (3.3) Calculate the root mean square error value of each window data in the training set inferred on the optimal model in step (3.2), and average it to obtain the anomaly score threshold of this training set.
5. The CAN bus traffic anomaly detection method based on unsupervised deep learning according to claim 4 is characterized in that: The specific process of step (4) is as follows: Use the method of step (1) to collect CAN bus data in real time, process the collected data into feature vectors in units of windows as in step (3.1), input them into the model after training in step (3.2), calculate the root mean square error between the output prediction sequence feature vector and the next window vector of the input vector, and obtain the abnormality score of the window; compare the obtained abnormality score with the abnormality score threshold obtained in step (3.3); if it is higher than the threshold, it means that the window contains abnormal data; if it is lower than the threshold, it means that the window is full of normal data; if multiple consecutive windows contain abnormal data, it means that there is obvious abnormality in the data stream, and the system alarm prompts.
6. A CAN bus traffic anomaly detection device based on unsupervised deep learning, characterized in that: It includes one or more processors for implementing the CAN bus traffic anomaly detection method based on unsupervised deep learning as described in any one of claims 1-5.
7. An electronic device comprising a memory and a processor, characterized in that: The memory is coupled to the processor; wherein the memory is used to store program data, and the processor is used to execute the program data to implement the CAN bus traffic anomaly detection method based on unsupervised deep learning as described in any one of claims 1-5 above.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by the processor, the CAN bus traffic anomaly detection method based on unsupervised deep learning as described in any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Vehicle-mounted CAN bus network abnormity detection method and system
CN110275508A
Vehicle ECU safety test method and device
CN112532716A
Time sequence anomaly detection method based on neighborhood information fusion attention mechanism
CN116680105A
CAN-FD anomaly detection method based on time sequence content attention and long and short term memory network
CN117176421A
Cited By
Vehicle CAN bus information legality judgment method, device and equipment and storage medium
CN120910586A