Intrusion detection method for edge node of Internet of Vehicles, electronic equipment and medium

By collecting and analyzing multi-layer data of edge nodes of the Internet of Vehicles, combining algorithms such as hybrid neural networks, high-sensitivity detection and defense against malicious intrusions are achieved, and the problem of lack of intrusion detection of edge nodes in the existing technology is solved, and the security and stability of the Internet of Vehicles are improved.

CN120090881AInactive Publication Date: 2025-06-03CHONGQING JINKANG NEW ENERGY VEHICLE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510571535.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-06-03
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the prior art, edge nodes of the Internet of Vehicles lack detection technology for malicious intrusions, which has led to the stable operation of the Internet of Vehicles and the privacy and security of users being threatened.

Method used

By collecting network traffic data, physical signal data and hardware electromagnetic data from edge nodes, combined with algorithms such as hybrid neural networks, high-sensitivity detection of cross-layer attacks is achieved, and targeted defense strategies are generated and implemented.

Benefits of technology

It significantly improves the detection ability of composite attacks, quickly recognizes new attack modes, and ensures the safe and stable operation of edge nodes at the Internet of Vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090881A_ABST
    Figure CN120090881A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, in particular to an intrusion detection method for an edge node of the Internet of Vehicles, electronic equipment and a medium. The intrusion detection of the edge node of the Internet of Vehicles comprises the following steps: collecting current network flow data, physical signal data and hardware electromagnetic data of the edge node; determining a current attack type of the edge node according to the network flow data, the physical signal data and the hardware electromagnetic data; and according to the attack type and the current state of the edge node, generating a current defense strategy and executing the defense strategy so as to carry out comprehensive and accurate intrusion detection on the edge node.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology. Specifically, it relates to an intrusion detection method, an electronic device, and a medium for an edge node of an Internet of Vehicles (IoV). Background Art

[0002] The edge nodes of the IoV include roadside units, mobile sensing vehicles, on-vehicle terminals, base stations, edge servers, etc. Among them, the roadside unit is the most common edge node in the IoV, which is used to collect and process data from vehicles and communicate with vehicles.

[0003] The IoV involves a large amount of vehicle, infrastructure, and user data. This information may be exploited by malicious attackers, for example, by tampering with communication data, forging identities, or stealing privacy information to disrupt traffic order or violate user privacy. Therefore, it is necessary to perform intrusion detection on edge nodes.

[0004] In the prior art, edge nodes lack detection technology for malicious intrusion, which is not conducive to the stable operation of the IoV and the privacy security of users. In view of this, the present application is proposed. Summary of the Invention

[0005] The purpose of the present application is to provide an intrusion detection method, an electronic device, and a medium for an edge node of the IoV to perform comprehensive and accurate intrusion detection on the edge node.

[0006] To achieve the above purpose, the present application adopts the following technical solutions: In a first aspect, the present application provides an intrusion detection method for an edge node of the IoV, including: Collecting the current network traffic data, physical signal data, and hardware electromagnetic data of the edge node; Determining the current attack type of the edge node according to the network traffic data, physical signal data, and hardware electromagnetic data; Generating a current defense strategy according to the attack type and the current state of the edge node and executing the defense strategy.

[0007] In a second aspect, the present application provides an electronic device, including: At least one processor, and a memory communicatively connected to at least one of the processors; Wherein, the memory stores instructions executable by at least one of the processors, and the instructions are executed by at least one of the processors so that at least one of the processors can execute the above-mentioned intrusion detection method for an edge node of the IoV.

[0008] In a third aspect, the present application provides a computer-readable storage medium, on which computer instructions are stored, and the computer instructions are used to cause a computer to execute the above-mentioned intrusion detection method for vehicle networking edge nodes.

[0009] Compared with the prior art, the beneficial effects of the present application are as follows: The intrusion detection method for vehicle networking edge nodes provided by the present application collects network traffic data, physical signal data, and hardware electromagnetic data of edge nodes, correlates data at the network layer, physical layer, and hardware layer, realizes highly sensitive detection of cross-layer attacks, significantly improves the detection ability for composite attacks, and quickly identifies new attack patterns. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0011] Figure 1 is a flowchart of the intrusion detection method for vehicle networking edge nodes provided by the present application; Figure 2 is a schematic structural diagram of the hybrid neural network provided by an embodiment of the present application; Figure 3 is a flowchart of another intrusion detection method for vehicle networking edge nodes provided by an embodiment of the present application; Figure 4 is a schematic structural diagram of the electronic device provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0012] The following will describe exemplary embodiments of the present application with reference to the accompanying drawings. Various details of the embodiments of the present application are included to assist understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present application. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted below.

[0013] Figure 1 is a flowchart of an intrusion detection method for vehicle networking edge nodes provided by this embodiment. This method can be executed by an electronic device, and the electronic device can be integrated in the vehicle networking edge node.

[0014] Optionally, the edge nodes in this embodiment include but are not limited to: 1) Roadside Edge Nodes (RSUs), such as computing nodes deployed on road infrastructure (such as traffic lights, street lights, roadside poles), integrating communication, computing, and storage capabilities to support real-time data processing; 2) Vehicle-mounted Edge Nodes (OECUs), which are high-performance computing devices built into vehicles, making local decisions such as braking and wheel diameter planning by fusing sensors such as radars and cameras; 3) Mobile Edge Servers (MES), which are movable edge servers mounted on mobile platforms, providing dynamic resource expansion and cooperative computing with neighboring vehicles; 4) Cellular Base Station Nodes, such as 5G base station edge computing nodes deployed by telecom operators.

[0015] See Figure 1 , the method provided in this embodiment includes the following operations: S110. Collect the current network traffic data, physical signal data, and hardware electromagnetic data of the edge node.

[0016] Optionally, the network traffic data is collected in real time through the network card deployed inside the edge node. For example, the transmission rate of data packets (unit: number of data packets per second), the proportion of data volume between different protocol types, and the abnormal port access frequency (unit: times per minute). Among them, the proportion of data volume between different protocol types is, for example, the proportion of the data volume transmitted using the Transmission Control Protocol (TCP) to the data volume transmitted using the User Datagram Protocol (UDP). Optionally, the physical signal data is collected in real time through the positioning module (such as the Global Positioning System) and wireless receiver deployed inside the edge node. For example, the mean and variance of the Received Signal Strength Indicator (RSSI) (unit: dBm) and the position offset of the Global Positioning System.

[0017] Optionally, the hardware electromagnetic data is the electrical and magnetic data of the electronic components inside the edge node, collected by current sensors and electromagnetic probes. The hardware electromagnetic data includes the average power consumption of the central processing unit (unit: mW), the variance of the memory power consumption fluctuation (unit: mW 2 ) and the peak value of electromagnetic radiation (unit: μV).

[0018] S120: Determine the current attack type of the edge node according to the network traffic data, the physical signal data, and the hardware electromagnetic data.

[0019] The intrusion detection method provided in this embodiment can detect communication layer attacks, data layer attacks and physical layer attacks, and realize comprehensive intrusion detection. Optionally, the attack types include but are not limited to man-in-the-middle attacks, false message injection, data poisoning, privacy leakage, hardware Trojans and side channel attacks.

[0020] When the edge node is subjected to different types of attacks, the network traffic data, physical signal data, and hardware electromagnetic data will have different performances. For example, when the edge node is attacked by a side channel, the electromagnetic radiation peak will be abnormal. When the edge node is injected with false messages, the physical signal data will be abnormal. This embodiment can determine the current attack type of the edge node by analyzing the network traffic data, physical signal data, and hardware electromagnetic data.

[0021] S130: Generate a current defense strategy according to the attack type and the current state of the edge node and execute the defense strategy.

[0022] The current state of the edge node includes the working state and endurance state of the edge node, and is the performance of the edge node under the current attack. This embodiment combines the attack type and the current state of the edge node to comprehensively generate a suitable defense strategy, thereby taking targeted precautions against specific attack types and improving the current state of the edge node.

[0023] Optional defense strategies include but are not limited to blocking Internet Protocol (IP), switching frequency bands, enabling Trusted Execution Environment (TEE), and resetting keys. Blocking Internet Protocol can prevent malicious nodes from continuously scanning ports of edge nodes. Switching frequency bands can counter wireless interference attacks. Enabling TEE can create a secure enclave to protect key processing logic and implement encrypted storage of sensitive data. Resetting keys can reduce the risk of key leakage.

[0024] The intrusion detection method for the edge node of the Internet of Vehicles provided in the embodiment of the present application collects the network traffic data, physical signal data and hardware electromagnetic data of the edge node, associates the data of the network layer, physical layer and hardware layer, realizes high-sensitivity detection of cross-layer attacks, significantly improves the detection capability of complex attacks, and quickly identifies new attack patterns.

[0025] In some technical solutions, a hybrid neural network is used to identify the attack type. Network traffic data, physical signal data, and hardware electromagnetic data are input into the hybrid neural network to obtain the current attack type of the edge node.

[0026] Among them, the hybrid neural network is used to: perform feature encoding and fusion on network traffic data, physical signal data, and hardware electromagnetic data to obtain input fusion features; perform deep feature extraction on the input fusion features to obtain deep features; perform sparse attention and normalization processing on the deep features to obtain the current attack type of the edge node.

[0027] In this embodiment, through the strong learning ability of the hybrid neural network for non-linear relationships, the current attack type of the edge node is learned. By fusing multi-source data and performing deep feature extraction, deep features that can reflect the characteristics of multi-source data are obtained. By performing sparse attention and normalization processing on the deep features, only some of the attention connections are retained, reducing the computational amount.

[0028] Figure 2 is a schematic structural diagram of the hybrid neural network provided by an embodiment of the present application. Figure 3 is a flowchart of another intrusion detection method for a vehicle network edge node provided by an embodiment of the present application, which refines the recognition process of the current attack type by the hybrid neural network. The method provided in this embodiment includes: S210. Collect the current network traffic data, physical signal data, and hardware electromagnetic data of the edge node. For details, refer to Figure 1 the description of the provided embodiment, which will not be elaborated here.

[0029] S220. Perform feature encoding on the network traffic data, physical signal data, and hardware electromagnetic data respectively to obtain corresponding feature vectors.

[0030] Optionally, a one-dimensional convolutional neural network (1-Dimensional Convolutional Neural Network, 1D-CNN) and a non-linear activation function (Rectified Linear Unit, ReLU) are used to encode the network traffic data to obtain the feature vector of the network traffic data V net, see formula (1): V net = ReLU(Conv1D( X net, W net)) ∈ R 64 ; Formula (1) Among them, X net ∈ R 60×3 : A time window is used to take values on the time series of the network traffic data to obtain the input matrix X net , the time window length is 60 seconds, and the 3D feature vector; W net∈R 3×64 : Convolution kernel weight matrix, the convolution kernel size is 3, and the output is a 64-dimensional feature vector.

[0031] Optionally, use the Short-Time Fourier Transform (STFT) neural network and the fully connected layer to encode the physical signal data to obtain the feature vector of the physical signal data V phy, see formula (2): V phy = Linear(STFT( X phy)) ∈ R 64 ; Formula (2) Among them, X phy ∈ R 60×2 : Take values on the time series of the physical signal data using a time window to obtain the input matrix X phy, the time window length is 60 seconds, 2-dimensional feature vector; STFT: The formula of the short-time Fourier transform, the window length is 64, and the step size is 8; Linear: The fully connected layer is used to reduce the dimension of the output of STFT to 64 dimensions.

[0032] Optionally, use the Long Short-Term Memory (LSTM) neural network and the fully connected layer to encode the hardware electromagnetic data to obtain the feature vector of the hardware electromagnetic data V hw , see formula (3): V hw = LSTM( X hw, W hw) ∈ R 64 ; Formula (3) Among them, X hw ∈ R 60×3 : Take values on the time series of the hardware electromagnetic data using a time window to obtain the input matrix X hw, the time window length is 60 seconds, 3-dimensional feature vector; W hw: LSTM neural network parameters, the hidden layer dimension is 32, and the output dimension is 64.

[0033] S230. Obtain the weight of each feature vector based on the attention mechanism; use the weight to perform weighted summation on the feature vectors to obtain the input fusion feature.

[0034] Input the aforementioned three feature vectors into the attention layer to obtain the weights of each feature vector. Formula (4) shows the operation of the attention layer: ; Formula (4) Among them,W q ∈R 64×64 、 W k ∈R 64×64 : They are, in sequence, the learnable target query matrix and the target key matrix; V i ∈R 64 : The encoded feature vector, see Formulas (1) to (3); α i ∈[0,1]: The normalized weight, reflecting the importance of each feature vector to the current attack, d is the dimension of the target query matrix and the target key matrix, which is 64 in this example.

[0035] According to Formula (5), the feature vectors are weighted and summed using the weights to obtain the input fusion feature V fused .

[0036] V fused = α net V net + α phy V phy + α hw V hw ; Formula (5) This embodiment is based on the attention mechanism, which can dynamically adjust the weights of each feature vector according to the attack type, realize the dynamic fusion of multi-source feature vectors, capture the dynamic attack features, and solve the problem of insufficient sensitivity caused by fusing feature vectors with fixed weights.

[0037] S240. Use the adaptive convolution kernel adjustment module to determine the target convolution kernel size of the input fusion feature.

[0038] The adaptive convolution kernel adjustment module (Adaptive Convolution Kernel Control, ACKC) is a dynamic convolution technology used in deep learning, which can automatically adjust the parameters of the convolution kernel according to the input features. Dynamically adjust the convolution kernel size k based on Formula (6) to improve the feature resolution.

[0039] ; Formula (6) Among them, σ 2 : The input fusion feature V fused ∈R 64Local variance. The calculation method of local variance: take values on the input fused feature through a 3×3 sliding window, and calculate the variance within the sliding window; θ ∈R: learnable threshold, iterated through model training; k ∈{3,4}: dynamically adjusted convolutional kernel size; Sigmoid is an S-shaped non-linear activation function, is the floor symbol.

[0040] S250. Perform a convolution operation on the input fused feature using a convolutional kernel with the target convolutional kernel size to obtain a depth feature.

[0041] Based on a two-dimensional convolutional layer (Convolutional 2D, Conv2D) for the input fused feature V fused Perform a convolution operation to obtain a depth feature F out, see formula (7).

[0042] F out = Conv2D( V fused, K dyn); formula (7) where, K dyn ∈ R k×k : dynamic convolutional kernel, the size is determined by k determined.

[0043] S260. Perform a linear transformation on the depth feature to obtain a query matrix, a key matrix, and a value matrix; input the query matrix, the key matrix, and the value matrix into a sparse attention layer for sparse attention and normalization processing to obtain the current attack type of the edge node.

[0044] Exemplarily, map the depth feature F out to the query (Query), key (Key), and value (Value) spaces respectively through three different linear transformations (i.e., three different weight matrices) to obtain a query matrix (Q), a key matrix (K), and a value matrix (V). The operation of the sparse attention layer Attention sparse is shown in formula (8).

[0045] ; formula (8) In formula (8), Q , K , V ∈R 64×64 , are the query matrix, the key matrix, and the value matrix in sequence. Softmax normalization function, ⊙ is element-wise multiplication, d is the dimension, which is 64 in this example. M ∈ {0,1} 64×64: Binary mask. In this example, the proportion of non-zero elements in M is 30%. Only the first 30% of the attention connections are retained through formula (8) to reduce the computational complexity.

[0046] Due to the large number of parameters and high computational complexity of traditional convolutional neural networks, it is difficult to deploy them to resource-constrained edge nodes. In this embodiment, an adaptive convolutional kernel adjustment module is used to reduce the size of the convolutional kernel, and a sparse attention mechanism is used to limit the attention range, reducing the number of attention weights that need to be calculated, thereby reducing the computational complexity. This embodiment implements a lightweight hybrid neural network, and the number of parameters of the model is compressed to 0.98MB, which can be deployed on edge nodes; ensuring that the latency of attack type recognition by edge nodes ≤ 8ms, optimizing the end-to-end response latency, and meeting the real-time requirements of the vehicle network.

[0047] S270. Generate the current defense strategy according to the attack type and the current state of the node, and execute the defense strategy.

[0048] In this embodiment, before using the hybrid neural network to determine the attack type, the hybrid neural network needs to be trained, which specifically includes the following operations: The first step: Obtain training samples with attack type labels.

[0049] The training samples are network traffic data, physical signal data, and hardware electromagnetic data collected at historical moments of the edge node. The label is the known attack type.

[0050] The second step: Input the training samples into the untrained hybrid neural network, and iterate the parameters in the hybrid neural network with the aim of minimizing the loss function.

[0051] The parameters in the untrained hybrid neural network are initial values. It is necessary to iterate the parameters to minimize the loss function, so that the hybrid neural network has the ability to identify attack types.

[0052] Optionally, the loss function is constructed based on the gap between the label and the output of the hybrid neural network, so that the hybrid neural network can accurately identify the attack type.

[0053] Referring to formula (9) and formula (10), the loss function L is comprehensively constructed based on the gap between the label and the output of the hybrid neural network, the weight of each feature vector, and the convolutional kernel. It can enable the hybrid neural network to accurately identify the attack type while dynamically adjusting the weights of network traffic data, physical signal data, and hardware electromagnetic data, and dynamically adjusting the size of the convolutional kernel to reduce the computational complexity.

[0054] ; formula (9) ; formula (10) In formulas (9) and (10), is the cross-entropy loss function, which measures the gap between the attack types recognized by the model and the label y; C is the number of attack types, c is the number of the attack type, is the one-hot encoding represented by the c-th label; represents the probability of the c-th type of attack recognized by the hybrid neural network model. is the L1 regularization coefficient, which can be 0.01 and is used to control the sparsity of the attention weights (i.e., the weights of the feature vectors) . is the L2 regularization coefficient, which can be 0.001 and is used to suppress the overfitting of the dynamic convolution kernel . is the attention weight 's L1 norm; is 's squared L2 norm.

[0055] When performing the aforementioned second step, a privacy-enhanced federated learning mode is adopted.

[0056] Optionally, first, the local training samples of each edge node are input into the untrained hybrid neural network to determine the iterative gradient of the current round in the hybrid neural network for the purpose of minimizing the loss function. The training samples of each edge node are not shared and are trained locally alone, which will obtain different parameter iterative gradients.

[0057] Then, dynamic noise injection is performed on the iterative gradient of the current round through each edge node to obtain the perturbed gradient of the current round. See Formulas (11) and (12). The perturbed gradient of the current round is sent to the cloud server through each edge node.

[0058] ; Formula (11) ; Formula (12) In Formula (11), s max is the global maximum sensitivity, is the query function sensitivity, Lap is the Laplace noise generation function, si is the gradient sensitivity of the i-th edge node, which is used to measure the magnitude of the gradient change, is the iterative gradient of the i-th edge node, is the perturbed gradient of the i-th edge node, is the privacy budget, which is used to control the noise intensity.

[0059] This step can enhance the privacy of gradients through dynamic noise injection, and by using dynamic noise instead of fixed noise, the accuracy loss of the model can be minimized.

[0060] The cloud server performs a weighted operation on the perturbed gradients of the current round of each edge node, the global model parameters of the current round, and the historical momentum of the global model parameters to obtain the global model parameters of the next round. See Equation (13).

[0061] ; Equation (13) where θ t ∈R n : The global model parameters after the t -th round (i.e., the current round) of training, representing the state of the current model. θ t+1 ∈R n : The new global model parameters updated after the t +1-th round (i.e., the next round). η ∈R + : A scalar hyperparameter used to control the step size of parameter updates. w i ∈[0,1]: The weight coefficient of the i-th edge node, reflecting the contribution ratio of the edge node to the global model. β ∈[0,1): A scalar hyperparameter that controls the memory strength of the historical update direction. : Represents the direction and magnitude of the previous parameter update, i.e., the historical momentum of the global model parameters.

[0062] Finally, the cloud server sends the global model parameters θ t+1 of the next round to each edge node and returns the training operations of the next round for each edge node until the training termination condition is met.

[0063] This step can accelerate model convergence and reduce the number of rounds of federated learning through momentum weighted aggregation by the cloud server.

[0064] In some embodiments, a Double Deep Q-Network (DDQN) is used to generate the current defense strategy. DDQN is a deep learning-based reinforcement learning algorithm designed to address the overestimation problem in traditional Deep Q-Network (DQN) caused by the non-separation of action selection and value evaluation. The core idea is to use two neural networks: the Main Network and the Target Network, to be responsible for action selection and value evaluation respectively, thereby improving the stability and performance of the algorithm.

[0065] Optionally, the attack type and the current state of the edge node are input into the double deep Q-network to obtain the current defense strategy.

[0066] Among them, the recognition of the attack type can be referred to the description of the above embodiment, which will not be elaborated here. The current state of the edge node includes: 1) node load, such as the utilization rate of the central processing unit (unit: %); 2) network latency, such as communication delay (unit: ms); 3) remaining power, that is, the remaining battery power of the edge node (unit: %).

[0067] The attack type and the current state of the edge node constitute the following state space J: J = {attack type, node load, network latency, remaining power}; Equation (14) Multiple defense strategies are constituted into the following action space Z: Z = {block IP, switch frequency band, enable TEE, reset key}; Equation (15) The main network is used to select an action z according to the current state j and calculate the corresponding Q value The target network is used to calculate the future state and the future action under the target Q value .

[0068] The target network in this embodiment is used to avoid overestimation, see Equation (16).

[0069] ; Equation (16) Among them, is the learning rate, is the discount factor, is the reward.

[0070] This embodiment dynamically generates a defense strategy through DDQN, which can improve the response efficiency to new attacks; reduce resource overhead and avoid over-defense.

[0071] Based on the above description, the embodiments of the present application balance privacy protection and defense efficiency by dynamically fusing multi-source data features and applying algorithms such as an adaptive convolution kernel adjustment module, a sparse attention layer, and DDQN, and solve the problem of the contradiction between security and resources unique to edge nodes in the vehicle network; at the same time, it can effectively solve problems such as cross-layer composite attack detection blind spots, insufficient dynamic environment adaptability, and the contradiction between edge-side resource constraints and efficiency in the defense of vehicle network edge nodes.

[0072] As Figure 4 shown, this embodiment provides an electronic device, including: at least one processor; and A memory communicatively connected to at least one of the processors; wherein, The memory stores instructions executable by at least one of the processors, and the instructions are executed by at least one of the processors to enable at least one of the processors to execute the above method. At least one processor in the electronic device can execute the above method, and thus has at least the same advantages as the above method.

[0073] Optionally, the electronic device further includes an interface for connecting various components, including a high-speed interface and a low-speed interface. Each component is interconnected using different buses and can be mounted on a common motherboard or otherwise as needed. The processor can process instructions executed within the electronic device, including instructions for storing graphical information in the memory or on the memory to display a GUI (Graphical User Interface) on an external input / output device (such as a display device coupled to the interface). In other embodiments, if necessary, multiple processors and multiple memories can be used together, and / or multiple buses and multiple memories can be used together. Similarly, multiple electronic devices (such as a server array, a set of blade servers, or a multi-processor system) can be connected, and each device provides part of the necessary operations. Figure 4 Taking one processor 301 as an example.

[0074] The memory 302, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to the intrusion detection method of the vehicle networking edge node in the embodiments of the present application. The processor 301 executes various functional applications and data processing of the device by running the software programs, instructions, and modules stored in the memory 302, that is, implements the above-mentioned intrusion detection method of the vehicle networking edge node.

[0075] The memory 302 may mainly include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the terminal, etc. In addition, the memory 302 may include high-speed random access memory and may also include non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some instances, the memory 302 may further include a memory remotely provided with respect to the processor 301, and these remote memories can be connected to the device through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0076] The electronic device may further include: an input device 303 and an output device 304. The processor 301, the memory 302, the input device 303 and the output device 304 may be connected by a bus or other means. Figure 4 Taking the connection via the bus as an example.

[0077] The input device 303 can receive input digital or character information. The output device 304 may include a display device, an auxiliary lighting device (e.g., an LED), a tactile feedback device (e.g., a vibration motor), etc. The display device may include, but is not limited to, a liquid crystal display (LCD), a light emitting diode (LED) display, and a plasma display. In some embodiments, the display device may be a touch screen.

[0078] This embodiment provides a computer-readable storage medium, on which computer instructions are stored, and the computer instructions are used to cause a computer to execute the above method. The computer instructions on the computer-readable storage medium are used to cause a computer to execute the above method, and thus have at least the same advantages as the above method.

[0079] The medium in this application may adopt any combination of one or more computer-readable media. The medium may be a computer-readable signal medium or a computer-readable storage medium. The medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the medium (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the medium may be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device.

[0080] The computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which computer-readable program code is carried. Such a propagated data signal may take various forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, and the computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device.

[0081] The program code contained on a computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wire, optical fiber cable, RF (Radio Frequency), etc., or any suitable combination of the foregoing.

[0082] The computer program code for performing the operations of the present application can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or, alternatively, can be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0083] It should be understood that various forms of the flow shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present application can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution disclosed in the present application can be achieved, and no limitation is made herein.

[0084] The above specific embodiments do not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present application shall be included within the protection scope of the present application.

Claims

1. A method for intrusion detection of an edge node of an Internet of Vehicles, characterized in that: include: Collect the current network traffic data, physical signal data and hardware electromagnetic data of edge nodes; Determine the current attack type of the edge node according to the network traffic data, physical signal data and hardware electromagnetic data; According to the attack type and the current state of the edge node, a current defense strategy is generated and executed.

2. The intrusion detection method for an edge node of an Internet of Vehicles according to claim 1, characterized in that: Determining the current attack type of the edge node according to the network traffic data, the physical signal data, and the hardware electromagnetic data, including: Inputting the network traffic data, physical signal data and hardware electromagnetic data into a hybrid neural network to obtain the current attack type of the edge node; Among them, the hybrid neural network is used to: perform feature encoding and fusion on the network traffic data, physical signal data and hardware electromagnetic data to obtain input fusion features; perform deep feature extraction on the input fusion features to obtain deep features; perform sparse attention and normalization processing on the deep features to obtain the current attack type of the edge node.

3. The intrusion detection method for an edge node of an Internet of Vehicles according to claim 2, characterized in that: The network traffic data, physical signal data and hardware electromagnetic data are feature encoded and fused to obtain input fusion features, including: Performing feature encoding on the network traffic data, physical signal data and hardware electromagnetic data respectively to obtain corresponding feature vectors; Get the weight of each feature vector based on the attention mechanism; The weights are used to perform weighted summation on the feature vectors to obtain input fusion features.

4. The intrusion detection method for an edge node of an Internet of Vehicles according to claim 3, characterized in that: Performing deep feature extraction on the input fusion feature to obtain deep features includes: Adopting an adaptive convolution kernel adjustment module to determine a target convolution kernel size of the input fusion feature; A convolution operation is performed on the input fusion feature using a convolution kernel of the target convolution kernel size to obtain a deep feature.

5. The intrusion detection method for an edge node of an Internet of Vehicles according to claim 2, characterized in that: Perform sparse attention and normalization processing on the deep features to obtain the current attack type of the edge node, including: Performing a linear transformation on the deep features to obtain a query matrix, a key matrix, and a value matrix; The query matrix, key matrix and value matrix are input into the sparse attention layer for sparse attention and normalization processing to obtain the current attack type of the edge node.

6. The intrusion detection method for an edge node of an Internet of Vehicles according to any one of claims 1 to 5, characterized in that: Generate a current defense strategy according to the attack type and the current state of the edge node, including: Inputting the attack type and the current state of the edge node into a dual-depth Q network to obtain a current defense strategy; The current status includes node load, network delay and remaining power.

7. The intrusion detection method for an edge node of an Internet of Vehicles according to claim 4, characterized in that: Before inputting the network traffic data, physical signal data and hardware electromagnetic data into the hybrid neural network to obtain the current attack type of the edge node, the method further includes: Obtain training samples with attack type labels; Inputting the training samples into an untrained hybrid neural network, and iterating the parameters of the hybrid neural network for the purpose of minimizing a loss function; The loss function is constructed based on the gap between the label and the output of the hybrid neural network, the weight of each feature vector and the convolution kernel.

8. The intrusion detection method for an edge node of an Internet of Vehicles according to claim 7, characterized in that: Inputting the training sample into an untrained hybrid neural network, iterating the parameters of the hybrid neural network for the purpose of minimizing the loss function, including: Inputting local training samples into an untrained hybrid neural network through each edge node, and determining the iterative gradient of the current round in the hybrid neural network for the purpose of minimizing the loss function; Dynamically injecting noise into the iterative gradient of the current round through each edge node to obtain the perturbation gradient of the current round, and sending the perturbation gradient of the current round to the cloud server; The cloud server performs weighted operations on the perturbation gradient of the current round of each edge node, the global model parameters of the current round, and the historical momentum of the global model parameters to obtain the global model parameters of the next round; and sends the global model parameters of the next round to each edge node, and returns the training operation of the next round of each edge node until the training deadline is met.

9. An electronic device, characterized in that: include: at least one processor, and a memory communicatively coupled to at least one of the processors; Wherein, the memory stores instructions that can be executed by at least one of the processors, and the instructions are executed by at least one of the processors so that at least one of the processors can execute the intrusion detection method for the edge node of the Internet of Vehicles described in any one of claims 1-8.

10. A computer-readable storage medium, characterized in that: The medium stores computer instructions, and the computer instructions are used to enable a computer to execute the intrusion detection method for an edge node of an Internet of Vehicles according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Signal type identification method and system based on fusion feature and group convolution ViT network

    CN117743946A

  • Abnormal access defense method and device, electronic equipment, vehicle and storage medium

    CN117955666A

  • Data processing method, device and equipment and readable storage medium

    CN118333105A

  • New energy station network intrusion intelligent detection and active defense system

    CN119628948A

  • Mine network security operation system

    CN119728294A