Internet of vehicles intrusion detection method, system and equipment based on federal auto-encoder

By using the federal autoencoder and FedAvg algorithm in the intelligent Internet of Vehicles, the problems of data privacy, labeling cost and communication efficiency in Internet of Vehicles intrusion detection are solved, and efficient and secure intrusion detection is achieved, which improves detection accuracy and reduces communication overhead.

CN120151071APending Publication Date: 2025-06-13NAT UNIV OF DEFENSE TECH
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510420382.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

Smart vehicle networking faces severe cybersecurity threats, and traditional deep learning methods face huge challenges due to data privacy issues and high labeling costs.

Method used

The Internet of Vehicle Intrusion Detection Method based on the federal autoencoder is adopted, and the received CAN data is converted through the client to obtain a grayscale image, and unsupervised learning training is performed locally, and only the quantized model parameters are uploaded. The server side uses the FedAvg algorithm for global aggregation and reconstructs the supervised learning system for intrusion detection.

Benefits of technology

It effectively solves problems such as data privacy, labeling costs and communication efficiency, improves detection accuracy by 23%-37%, and reduces communication overhead by more than 60% while ensuring privacy and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151071A_ABST
    Figure CN120151071A_ABST
Patent Text Reader

Abstract

The invention relates to an Internet of Vehicles intrusion detection method, system and device based on a federal auto-encoder. The method comprises the following steps: performing format conversion on received CAN data through a client to obtain a grayscale image; and marking the grayscale image according to the timestamp of the grayscale image and the attack mode, uploading the marked data block as a training sample data set to a server, inputting the unmarked data block to a convolutional auto-encoder model of a corresponding client, carrying out a plurality of rounds of local unsupervised learning training, and updating the model. And quantifying the weight of the model after updating the model, so that the server inputs the training sample data set into the model for global aggregation by adopting a FedAvg algorithm. And updating the aggregated convolutional auto-encoder model to reconstruct a supervised learning system so as to detect the intrusion of CAN data in different clients in the Internet of vehicles. By adopting the method, the Internet of Vehicles intrusion detection precision can be improved, and the communication overhead can be greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of intelligent vehicle networking intrusion detection, and particularly to a vehicle networking intrusion detection method, system, computer device, and storage medium based on a federated autoencoder. Background Art

[0002] With the rapid development of the automotive industry towards the directions of intelligence, electrification, sharing, and networking (the "new four modernizations"), intelligent and connected vehicles (ICVs) have become a global strategic focus. To achieve vehicle intelligence, a large number of sensors and electronic control units (ECUs) are deployed in the vehicle and communicate through a controller area network (CAN) bus system, thus forming a complex in-vehicle network system.

[0003] Although the CAN bus provides high-speed, efficient, and low-cost in-vehicle communication, the deficiency of its security mechanism makes it extremely vulnerable to network attacks. Research shows that attackers can invade the CAN bus system through various channels (such as the on-board diagnostic interface (OBD-II) port) or by using wireless channels (such as WiFi, Bluetooth, GPS, and cellular networks). Once the invasion is successful, malicious instructions may lead to catastrophic consequences, such as controlling the vehicle's brakes, steering, or even acceleration, thus seriously threatening the safety of passengers and roads. Therefore, intelligent vehicle networking faces increasingly severe network security threats, and traditional deep learning methods face huge challenges due to data privacy issues and high annotation costs. Summary of the Invention

[0004] Based on this, it is necessary to provide a vehicle networking intrusion detection method, system, computer device, and storage medium based on a federated autoencoder for the above technical problems.

[0005] A vehicle networking intrusion detection method based on a federated autoencoder, the method includes:

[0006] Convert the format of the received CAN data through the client to obtain a grayscale image.

[0007] Mark the grayscale image according to the timestamp of the grayscale image and the attack pattern, upload the marked data block as a training sample data set to the server, and input the unmarked data block into the convolutional autoencoder model of the corresponding client for several rounds of local unsupervised learning training to obtain an updated convolutional autoencoder model.

[0008] Quantify the model weights of the updated convolutional autoencoder model so that the server uses the FedAvg algorithm to input the training sample data set into the convolutional autoencoder model on the server side for global aggregation.

[0009] Update the aggregated convolutional autoencoder model reconstruction supervised learning system in the server, and detect the intrusion of CAN data in different clients in the vehicle network according to the reconstructed supervised learning system.

[0010] A vehicle network intrusion detection system based on a federated autoencoder, the system includes:

[0011] A data conversion module for converting the received CAN data into a grayscale image through a client.

[0012] A model update module for marking the grayscale image according to the timestamp and attack pattern of the grayscale image, uploading the marked data block as a training sample data set to the server, and inputting the unmarked data block into the convolutional autoencoder model of the corresponding client for several rounds of local unsupervised learning training to obtain an updated convolutional autoencoder model.

[0013] An aggregation module for quantifying the model weights of the updated convolutional autoencoder model, so that the server uses the FedAvg algorithm to input the training sample data set into the convolutional autoencoder model on the server side for global aggregation.

[0014] An intrusion detection module for updating the aggregated convolutional autoencoder model reconstruction supervised learning system in the server, and detecting the intrusion of CAN data in different clients in the vehicle network according to the reconstructed supervised learning system.

[0015] A computer device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0016] Convert the received CAN data into a grayscale image through a client.

[0017] Mark the grayscale image according to the timestamp and attack pattern of the grayscale image, upload the marked data block as a training sample data set to the server, and input the unmarked data block into the convolutional autoencoder model of the corresponding client for several rounds of local unsupervised learning training to obtain an updated convolutional autoencoder model.

[0018] Quantify the model weights of the updated convolutional autoencoder model, so that the server uses the FedAvg algorithm to input the training sample data set into the convolutional autoencoder model on the server side for global aggregation.

[0019] Update the aggregated convolutional autoencoder model reconstruction supervised learning system in the server, and detect the intrusion of the CAN data in different clients in the vehicle network according to the reconstructed supervised learning system.

[0020] A computer-readable storage medium stores a computer program thereon, and when the computer program is executed by a processor, the following steps are implemented:

[0021] The CAN data received by the client is subjected to format conversion to obtain a grayscale image.

[0022] The grayscale image is marked according to the timestamp and attack mode of the grayscale image. The marked data blocks are uploaded to the server as a training sample data set, and the unmarked data blocks are input into the convolutional autoencoder model of the corresponding client for several rounds of local unsupervised learning training to obtain an updated convolutional autoencoder model.

[0023] The model weights of the updated convolutional autoencoder model are quantized so that the server uses the FedAvg algorithm to input the training sample data set into the convolutional autoencoder model on the server side for global aggregation.

[0024] The reconstructed supervised learning system of the convolutional autoencoder model after aggregation is updated in the server, and the intrusion of CAN data in different clients in the vehicle network is detected according to the reconstructed supervised learning system.

[0025] The above vehicle network intrusion detection method, system and device based on the federated autoencoder innovatively solve the core problems such as data privacy, annotation cost and communication efficiency in vehicle network intrusion detection. Aiming at the privacy leakage risk brought by traditional deep learning relying on centralized data, a federated mechanism is adopted to realize local data processing: after the client converts CAN data into a grayscale image, unsupervised training is completed locally, and only the quantized model parameters are uploaded instead of the original data, which not only avoids the outflow of sensitive information, but also aggregates the global model parameters through the FedAvg algorithm, enabling the server to construct a robust detection system by integrating multi-source features. At the annotation level, only key data blocks are marked as supervised samples by associating the attack mode with the timestamp, greatly reducing the annotation workload; at the same time, the unmarked data is used for pre-training of the autoencoder on the client side to fully explore the potential feature distribution and effectively make up for the deficiency of the annotated data. In terms of communication optimization, model weight quantization significantly compresses the volume of transmitted data. Combining with the parameter exchange paradigm of federated learning, the communication complexity is reduced from the linear level to the logarithmic level, which is especially suitable for the low-power and high-real-time scenarios of the vehicle network. Finally, the supervised learning system after global aggregation realizes anomaly detection through reconstruction error analysis. Its multi-modal feature fusion ability improves the detection accuracy by 23%-37% compared with the traditional method, and achieves the effect of reducing the communication overhead by more than 60% on the premise of ensuring privacy security, forming a vehicle network defense system that takes into account both efficiency and reliability. Description of the Drawings

[0026] Figure 1It is an application scenario diagram of an intrusion detection method for the Internet of Vehicles based on a federated autoencoder in an embodiment;

[0027] Figure 2 It is a schematic flowchart of an intrusion detection method for the Internet of Vehicles based on a federated autoencoder in an embodiment;

[0028] Figure 3 It is a schematic diagram of the communication process in an embodiment;

[0029] Figure 4 It is the feature pattern of the CTAT dataset in an embodiment, where (a) is the feature pattern of the grayscale image of the normal samples in the Car-Hacking dataset, and (b) is the feature pattern of the grayscale images of different classes in the CTAT dataset;

[0030] Figure 5 It is the structural diagram of a convolutional autoencoder model (CAE model) in an embodiment;

[0031] Figure 6 It is a schematic diagram of the error generated after quantization and dequantization of FP32 parameters in an embodiment;

[0032] Figure 7 It is a schematic diagram of the influence of different input sizes in an embodiment;

[0033] Figure 8 It is the structural block diagram of an intrusion detection system for the Internet of Vehicles based on a federated autoencoder in an embodiment;

[0034] Figure 9 It is the internal structural diagram of a computer device in an embodiment. Detailed implementation manners

[0035] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0036] The intrusion detection method for the Internet of Vehicles based on a federated autoencoder provided by the present application can be applied to a FSL-IoV overall architecture based on federated semi-supervised learning as shown in Figure 1 A FSL-IoV includes two main parts: a client and a server.

[0037] The client pre-trains the model with unlabeled data, and the server fine-tunes the global parameters using limited labeled data. During the communication process (as shown in Figure 3) First, the server selects the clients participating in the learning and sends the initialized Convolutional Autoencoder (CAE) model to the clients (step 1). Next, these clients (in-vehicle devices) perform several rounds of local training on the CAE model based on unlabeled data to reduce the reconstruction error (step 2). It should be noted that in the Internet of Vehicles (IoV) environment, in-vehicle devices communicate frequently and contain sensitive information, so the cost of obtaining labeled data is high and it is difficult to implement. The clients only hold unlabeled data.

[0038] After the local training is completed, the clients send the quantized updated local model weights to the server, and the server performs global aggregation on the model weights through the FedAvg algorithm (step 3). Subsequently, the aggregated CAE model is further optimized on the server side: the decoder is removed, and the encoder part is connected to the Fully Connected Network (FCN) layer. Then, the server fine-tunes the model parameters using limited labeled data to complete the supervised learning (steps 4, 5, and 6).

[0039] Different from traditional federated learning methods, FSL-IoV not only completes the aggregation of the model on the server side but also adds a supervised learning step. Finally, the server sends the updated global CAE model back to the clients for further local updates, and at the same time deploys the trained supervised model to the in-vehicle devices for IoV intrusion detection (step 7).

[0040] Inspired by the working principle of the CAN bus system and the superior performance of convolutional neural networks in image classification tasks, this paper proposes a brand-new data conversion method. This method uses the patterns presented in the data fields of CAN messages to convert the data fields into images. Once an attacker injects a message, the patterns in the data fields will be destroyed. Therefore, through the data fields, the model can capture the characteristics of different categories of data packets and perform accurate classification. In addition, after converting the CAN message into a grayscale image, the plaintext content of the original fields (such as D0 - D7) is no longer transmitted, and the attacker can only obtain the image pixel values and cannot directly associate with the vehicle status.

[0041] In one embodiment, as Figure 2 shown, a method for IoV intrusion detection based on federated autoencoders is provided. Taking the application of this method to the Figure 1 FSL-IoV overall architecture as an example, it includes the following steps:

[0042] Step 202, the client performs format conversion on the received CAN data to obtain a grayscale image.

[0043] Step 204: Mark the grayscale images according to the timestamps of the grayscale images and the attack patterns, upload the marked data blocks as the training sample data set to the server, and input the unmarked data blocks into the convolutional autoencoder model of the corresponding client for several rounds of local unsupervised learning training to obtain an updated convolutional autoencoder model.

[0044] Step 206: Quantize the model weights of the updated convolutional autoencoder model so that the server uses the FedAvg algorithm to input the training sample data set into the convolutional autoencoder model on the server side for global aggregation.

[0045] Step 208: Update the reconstructed supervised learning system of the convolutional autoencoder model aggregated in the server, and detect the intrusion of the CAN data in different clients in the vehicle network according to the reconstructed supervised learning system.

[0046] In the above vehicle network intrusion detection method based on the federated autoencoder, by integrating federated learning and the semi-supervised autoencoder architecture, it innovatively solves the core problems such as data privacy, annotation cost, and communication efficiency in vehicle network intrusion detection. Aiming at the privacy leakage risk brought by the dependence of traditional deep learning on centralized data, a federated mechanism is adopted to realize local data processing: after the client converts the CAN data into grayscale images, it completes unsupervised training locally and only uploads the quantized model parameters instead of the original data, which not only avoids the outflow of sensitive information but also aggregates the global model parameters through the FedAvg algorithm, enabling the server to construct a robust detection system by integrating multi-source features. At the annotation level, only mark the key data blocks as supervised samples by associating the attack pattern with the timestamp, which greatly reduces the annotation workload; at the same time, use the unmarked data to pre-train the autoencoder on the client to fully explore the potential feature distribution and effectively make up for the deficiency of the annotated data. In terms of communication optimization, model weight quantization significantly compresses the volume of the transmitted data. Combining with the parameter exchange paradigm of federated learning, the communication complexity is reduced from the linear level to the logarithmic level, which is especially suitable for the low-power and high-real-time scenarios of the vehicle network. Finally, the globally aggregated supervised learning system realizes anomaly detection through reconstruction error analysis. Its multi-modal feature fusion ability improves the detection accuracy by 23%-37% compared with the traditional method, and achieves the effect of reducing the communication overhead by more than 60% on the premise of ensuring privacy security, forming a vehicle network defense system that takes into account both efficiency and reliability.

[0047] In one embodiment, the client converts the received CAN data from a table form into an image, divides the CAN data into several data blocks according to the timestamp and feature size of the network traffic data set, and converts the data blocks into several single-channel grayscale images of squares according to the key features of the data blocks.

[0048] In one embodiment, the grayscale images are labeled according to the timestamps of the grayscale images and the attack patterns of the data blocks. If all the data blocks of a certain grayscale image are normal samples, the grayscale image is marked as "normal". If the data blocks of a certain grayscale image contain attack samples, the attack type with the highest proportion in the data blocks of the grayscale image is marked.

[0049] In one embodiment, the convolutional autoencoder model includes: a decoder and an encoder. The specific steps for updating the aggregated convolutional autoencoder model in the server are as follows: Remove the decoder and connect the encoder to the fully connected network layer.

[0050] In one embodiment, the unlabeled data blocks are input into the encoder of the local convolutional autoencoder model of the corresponding client for encoding mapping to obtain the latent representation of the encoded data blocks:

[0051] Z = f(W 1 X + b 1 )

[0052] where X is the unlabeled data block, X = (x 1 , x 2 , …, x n ), W 1 is the weight matrix of the encoder, b 1 is the bias, f(·) is the activation function, and Z is the latent representation of the encoded unlabeled data block. The latent representation of the encoded data block reconstructs the unlabeled data block through the decoder to obtain the latent representation of the reconstructed data block:

[0053] X′ = f(W 2 Z + b 2 )

[0054] where X′ is the latent representation of the reconstructed data block, Z is the latent representation of the encoded unlabeled data block, W 2 is the weight matrix of the decoder, b 2 is the bias, and f(·) is the activation function. The reconstruction error is constructed based on the latent representation of the encoded data block and the latent representation of the reconstructed data block:

[0055]

[0056] where J(θ) is the reconstruction error, n is the number of unlabeled data blocks, θ is the training parameter, and θ ∈ {W 1 , b 1 , W 2 , b 2}, where RE(·) is the cost function. Optimize the model parameters of the convolutional autoencoder model of the client for each round of local unsupervised learning training of the unlabeled data block according to the reconstruction error, and obtain the updated convolutional autoencoder model.

[0057] In one embodiment, quantize the model weights of the updated convolutional autoencoder model:

[0058]

[0059] R′ f =S(Q i -Z)

[0060] where R′ t is the model weight, s is the scaling coefficient, Z is the zero point of the target quantization value, R t is the original floating-point parameter value, Q t is the target model parameter, According to the model weights, the server uses the FedAvg algorithm to input the training sample data set into the convolutional autoencoder model on the server side for global aggregation.

[0061] In one embodiment, perform weighted averaging on the received target model parameters in the server to obtain the global model parameters:

[0062]

[0063] where w global is the global model parameter, K is the number of clients participating in the optimization training, n k is the unlabeled data block trained by the k-th client, N is the total number of data blocks of the grayscale image, w k is the global model parameter of the local convolutional autoencoder model of the k-th client. Transmit the global model parameters back to each client in the vehicle network to update the aggregated convolutional autoencoder model reconstruction supervised learning system, and detect the intrusion of CAN data in different clients in the vehicle network in the reconstructed supervised learning system.

[0064] In one embodiment, the network traffic data is converted from tabular form to an image. First, the original 8-byte data field in Table 1 is extracted, split, and transformed into 8 features. The splitting results are shown in Table 2. The 8-byte data field of the CAN data packet is divided into 8 columns D0 - D7, and each column contains two hexadecimal values. Subsequently, the ID and the hexadecimal values in the data field are converted to decimal values. The value range of each byte is [0, 255], corresponding to the grayscale value [0, 255] of the pixel points in the image. Next, the data is normalized. Then, according to the timestamp and feature size of the network traffic dataset, the data samples are divided into data blocks. The dataset contains 8 key features (DATA[0] - DATA[7]). We convert the 8 features (32×32 = 1024 feature values) of 128 consecutive samples into an image with a shape of 32×32. Therefore, each converted image is a square single-channel grayscale image. Since these images are generated according to the timestamps of the data samples, the time series correlation of the original network data is retained during the conversion process. Finally, the converted images are labeled according to the attack patterns of the data blocks. If all samples in an image are normal samples, it is labeled as "normal". If an image contains attack samples, it is labeled as the attack type with the highest proportion in the data block. For example, if the proportion of DoS attack samples is the highest in a data block, the corresponding image is labeled as a DoS attack. After the above data conversion process, the finally generated image set is used as the input of the detection model.

[0065] Table 1 Original Data

[0066]

[0067]

[0068] In one embodiment, as Figure 4 shows representative samples of different attack types in the Car-Hacking dataset and the Can-train-and-test (CTAT) dataset. From Figure 4(a) It can be seen that the grayscale image of the normal sample in the Car-Hacking dataset presents a stable and uniform characteristic pattern compared with other attack samples, which is manifested as a continuous grayscale distribution. This shows that under normal circumstances, the CAN data flow structure of the Internet of Vehicles is clear and regular. The grayscale image of the DoS attack sample contains a large number of black pixels and presents a highly irregular pattern. This attack makes the image close to pure black by causing frequent repetition of data packets or the appearance of high-frequency empty messages. Fuzzy attacks detect and mine potential vulnerabilities in the system by injecting unexpected, random or invalid data. When implementing fuzzy attacks, the data fields and data lengths are randomized, so its grayscale image shows a highly disordered, chaotic and irregular characteristic pattern. This grayscale image feature reflects the uncertainty and uncontrollability of the input data stream. The grayscale image of the gear attack shows certain regular lines or block features, indicating that the attack deliberately uses specific data messages for disguise, so that the structural information of the data stream can be partially retained. The grayscale image of the speed attack may show volatility and periodicity, and its grayscale changes may be related to the engine speed data, thus showing a specific characteristic pattern that is different from the normal sample. Similarly, from Figure 4 It can be observed in (b) that there are obvious differences in the feature patterns of grayscale images of different categories in the CTAT dataset.

[0069] In one embodiment, in the initial autoencoder, the input unit and the output unit are fully connected. This design may cause the loss of spatial information of the grayscale image dataset, which is not conducive to the extraction and compression of image features. To solve this problem, a convolutional autoencoder is introduced. Its core extracts local features of the original image through convolution and pooling operations. Compared with the fully connected network, the advantage of the convolutional autoencoder is the use of local connections and parameter sharing, which not only retains the spatial features of the image, but also significantly reduces the number of model parameters.

[0070] When applied to IoV intrusion detection in the federated semi-supervised learning scenario, the client uses a complete convolutional autoencoder, including an encoder and a decoder. This process is based on image compression coding and reconstruction and belongs to the category of unsupervised learning. On the server side, we remove the decoder in the convolutional autoencoder, connect the encoder directly to the fully connected layer, and connect it to the Softmax classifier to form a supervised learning system. Each client aggregates the parameters as the initial value. In the supervised learning process with labeled sample data, this connection provides reasonable parameters for the FSL-IoV model, thereby building an efficient IoV intrusion detection model. Figure 5 The CAE model structure used in this article is demonstrated. The structure is efficient and concise in design and is a lightweight deep neural network.

[0071] In one embodiment, the FSL-IoV algorithm still uses the FP32 data type during the model training phase. Before the client uploads the parameters, the FP32 data is quantized into a low-precision format (such as INT8), and the necessary dequantization back to the FP32 format is supported through the quantization method. This method effectively combines the FedAvg algorithm with the INT8-based quantization scheme, taking into account both communication efficiency and model accuracy.

[0072] Use S to represent the scaling factor and Z to represent the zero point of the target quantization value, and R f is the original floating-point parameter value. Q i represents the target model parameter. Then the expressions for S and Z are:

[0073]

[0074] The FP32 data can be converted to INT8 type through calculation:

[0075]

[0076] Conversely, the receiver can calculate the dequantization based on the data:

[0077] R′ f = S(Q i - Z)

[0078] This mapping realizes the linear transformation of the parameter range through the scaling factor S and the zero point Z. Importantly, the quantized parameter Q i no longer retains the continuous distribution characteristics of the original data:

[0079] 1) Information entropy reduction: Quantization discretizes high-precision floating-point numbers into low-precision integers, resulting in a significant decrease in the information entropy of the parameters. Even if an attacker intercepts Q i , it is difficult to reverse engineer and restore the exact value of the original parameter.

[0080] 2) Distribution fuzzification: Different original parameter values may be mapped to the same quantization value (for example, R f = 0.12 and R f ==.13 are both mapped to Q i = 5), thus blurring the characteristic distribution of the client's local data

[0081] and reducing the success rate of the membership inference attack.

[0082] Such as Figure 6As shown, the error generated after quantization and dequantization of FP32 parameters, although slightly affecting the model accuracy, is essentially random and irreversible. Attackers cannot infer the statistical characteristics of the original data from the error pattern because the quantization process introduces uniformly distributed noise (determined by the global calculation of S and Z). This feature enables FSL-IoV to protect privacy while still being able to restore the model performance through fine-tuning.

[0083] In one of the embodiments, the dataset is divided into a training set (80%) and a test set (20%), and the Dirichlet data splitting strategy (α = 0.1) is used to split the distribution of the private dataset. The experiment uses the Python 3.7 programming language and develops a deep learning model based on the PyTorch framework. Table 3 outlines the model parameters and settings used in the simulation experiment. In the scenario of partially labeled data, we randomly extract training set samples from the fully labeled dataset and delete their labels. By default, the number of unlabeled data is 4 times that of labeled data.

[0084] In terms of hardware, the training of the deep learning model is completed on a PC equipped with a 64-bit Windows 11 operating system. The device configuration includes an Intel(R) Core(TM) Ultra 9285K 3.70GHz processor, an NVIDIA GeForce RTX 4090 GPU (24GB video memory), and 96GB of memory. The deployment and testing of the model are carried out on a Raspberry Pi 4 (8GB of memory) and an NVIDIA Jetson Nano development kit (2GB of memory) to simulate the in-vehicle device environment in a vehicle network.

[0085] Table 3 Model Parameters

[0086]

[0087] The experiment is evaluated on two standard vehicle network security datasets, specifically including the Car-Hacking and Can-train-and-test9 (CTAT) datasets. Among them, the Car-Hacking dataset was collected in 2018 through the OBD-II port in a CAN message injection attack, and this dataset is widely used in related research on simulating in-vehicle network intrusion detection. The CTAT dataset is the latest CAN dataset released in 2024, containing CAN data from four vehicles produced by two different companies, which were collected during real vehicle network operations. This dataset covers a large amount of normal vehicle traffic and 5 types of different attack traffic. The sample types, quantities, and their descriptions of the two datasets are shown in detail in Table 4.

[0088] Table 4 Sample Types, Quantities, and Their Descriptions

[0089]

[0090] Furthermore, a confusion matrix was adopted to comprehensively evaluate the classification performance of the model, and the following performance metrics were calculated therefrom, including accuracy, Recall, Precision, and F1-score.

[0091]

[0092] Among them, TP is true positive, FP is false positive, FN is false negative, and TN is true negative.

[0093] In addition, since in-vehicle devices usually have low computing performance, to more clearly evaluate the efficiency of the proposed method, this paper records the time and memory occupancy required for inference on in-vehicle devices. An efficient vehicle networking intrusion detection system should be able to achieve real-time detection while ensuring a high performance score.

[0094] The input size refers to the size of the continuous traffic samples in the Car-Hacking dataset after being converted into images through the above data conversion method. In the experiment, we extracted 8 important features (DATA[0]-DATA[7]) from the CAN traffic data field, grouped them, and then converted them into images. To verify the optimal input size, we tested different numbers of continuous samples (8, 32, 72, 128, 200, and 288), and the generated image sizes were 8×8, 16×16, 24×24, 32×32, 40×40, and 48×48 respectively. This experiment was trained and tested based on the FSL-IoV model, and the parameter settings are shown in Table 3. The evaluation metrics were accuracy and F1-score. The final experimental results are as Figure 7 shown.

[0095] Figure 7The results show that as the input size increases, the accuracy and F1-score of the model first increase and then decrease. When the input image size is 32×32, the performance reaches the optimal level, with an accuracy of 98.83% and an F1-score of 94.14%. Smaller input sizes (such as 8×8) limit the learning of effective features due to insufficient detailed information, resulting in lower model performance. Larger input sizes (such as 48×48) require integrating 288 consecutive samples, which may contain data of multiple categories and are prone to feature confusion when generating a single image. Although the change in input size has a certain impact on performance, the accuracy under all test conditions is higher than 94%, and the F1-score is higher than 90%. This indicates that the data conversion method proposed in this paper can effectively capture the visual and deep features of CAN traffic data. In the actual application of in-vehicle networks, selecting 128 consecutive samples as the input has more advantages in terms of generality. Therefore, this paper uses 32×32 as the final input image size.

[0096] Four comparative experiments were designed and conducted, and the specific descriptions are as follows: a) Without using weight quantization; b) Using weight quantization only when the client uploads model parameters (adopted in this paper); c) Using weight quantization only when the server distributes model parameters; d) Using weight quantization for both upload and distribution. The experimental parameter settings are shown in Table 3, and the accuracy, F1-score, and communication overhead are used as evaluation indicators. The final results are shown in Table 5.

[0097] Table 5 Influence of Weight Quantization

[0098]

[0099] According to the analysis in Table 5, each method shows different performances in terms of accuracy, F1-score, and communication overhead. The accuracy of method a) is 98.86%, and the F1-score is 94.21%, but the communication overhead is the highest, reaching 226.76MB. The accuracy of method b) slightly decreases to 98.83%, the F1-score is 94.14%, and the communication overhead is significantly reduced to 116.27MB, indicating that the performance hardly deteriorates after using weight quantization. The accuracy and F1-score of method c) are 98.21% and 93.25% respectively, and the communication overhead is 116.92MB. The accuracy and F1-score of method d) decrease to 98.17% and 92.98% respectively, but the communication overhead is greatly reduced, only 56.71MB.

[0100] Generally speaking, without weight quantization (Method a), the model performance is the best, but the communication cost is the highest. Method b) shows a relatively balanced performance. Its accuracy only drops by 0.03% and the F1-score drops by 0.07%, while the communication overhead is significantly reduced to 116.27 MB, fully demonstrating that this method can achieve a good balance between high performance and low communication overhead. Although the communication overhead of Method c) is similar to that of Method b), Method b) has more advantages in terms of accuracy and F1-score. Method d), although minimizing the communication overhead, comes at the cost of a significant drop in model performance.

[0101] Method b) only uses weight quantization when the client uploads model parameters, fully considering that the server will perform fine-tuning training to recover the accuracy loss, which demonstrates its feasibility and advantages in practical applications. Especially in an environment with limited network bandwidth or high latency, choosing Method b) can not only significantly reduce the communication overhead but also maintain a high model accuracy, which is of great significance for the practical promotion of FSL-IoV.

[0102] It should be understood that although Figure 2-3 the steps in the flowchart of Figure 2-3 are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover,

[0103] In one embodiment, as Figure 8 shown, a vehicle network intrusion detection system based on a federated autoencoder is provided, including: a data conversion module 802, a model update module 804, an aggregation module 806, and an intrusion detection module 808, where:

[0104] The data conversion module 802 is used to convert the received CAN data through the client to obtain a grayscale image.

[0105] The model update module 804 is used to mark the grayscale image according to the timestamp of the grayscale image and the attack pattern, upload the marked data block as a training sample data set to the server, and input the unmarked data block into the convolutional autoencoder model of the corresponding client for several rounds of local unsupervised learning training to obtain an updated convolutional autoencoder model.

[0106] An aggregation module 806 is configured to quantify the model weights of the updated convolutional autoencoder model, so that the server uses the FedAvg algorithm to input the training sample dataset into the convolutional autoencoder model on the server side for global aggregation.

[0107] An intrusion detection module 808 is configured to update the aggregated convolutional autoencoder model in the server to reconstruct the supervised learning system, and detect the intrusion of CAN data in different clients in the vehicle network according to the reconstructed supervised learning system.

[0108] For the specific limitations of the vehicle network intrusion detection system based on the federated autoencoder, reference can be made to the limitations of the vehicle network intrusion detection method based on the federated autoencoder in the above text, which will not be elaborated here. Each module in the above vehicle network intrusion detection system based on the federated autoencoder can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0109] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram is shown. The computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store vehicle network intrusion detection data based on the federated autoencoder. The network interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a vehicle network intrusion detection method based on the federated autoencoder.

[0110] In one embodiment, a computer device is provided. The computer device can be a terminal, and its internal structure diagram can be as Figure 9As shown in the figure. The computer device includes a processor, a memory, a network interface, a display screen, and an input system connected by a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a vehicle network intrusion detection method based on a federated autoencoder. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input system of the computer device can be a touch layer covered on the display screen, or buttons, trackballs, or touchpads provided on the computer device housing, or an external keyboard, touchpad, or mouse, etc.

[0111] Those skilled in the art can understand that Figure 8-9 the structure shown in the figure is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0112] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the following steps are implemented:

[0113] Convert the received CAN data through the client to obtain a grayscale image.

[0114] Mark the grayscale image according to the timestamp of the grayscale image and the attack pattern, upload the marked data block as a training sample data set to the server, and input the unmarked data block into the convolutional autoencoder model of the corresponding client for several rounds of local unsupervised learning training to obtain an updated convolutional autoencoder model.

[0115] Quantize the model weights of the updated convolutional autoencoder model so that the server uses the FedAvg algorithm to input the training sample data set into the convolutional autoencoder model on the server side for global aggregation.

[0116] Update the reconstructed supervised learning system of the convolutional autoencoder model after aggregation in the server, and detect the intrusion of the CAN data in different clients in the vehicle network according to the reconstructed supervised learning system.

[0117] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the following steps are implemented:

[0118] The client converts the received CAN data into a grayscale image.

[0119] Mark the grayscale image according to the timestamp of the grayscale image and the attack mode, upload the marked data blocks as a training sample data set to the server, and input the unmarked data blocks into the convolutional autoencoder model of the corresponding client for several rounds of local unsupervised learning training to obtain an updated convolutional autoencoder model.

[0120] Quantize the model weights of the updated convolutional autoencoder model so that the server uses the FedAvg algorithm to input the training sample data set into the convolutional autoencoder model on the server side for global aggregation.

[0121] Update the reconstructed supervised learning system of the convolutional autoencoder model aggregated in the server, and detect the intrusion of the CAN data in different clients in the vehicle network according to the reconstructed supervised learning system.

[0122] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to memory, storage, database or other media used in the various embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0123] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.

[0124] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.

Claims

1. A method for intrusion detection in Internet of Vehicles based on federated autoencoders, characterized in that: Applied to an intrusion detection communication network, the intrusion detection communication network comprises: a plurality of clients and servers; The method comprises: The client performs format conversion on the received CAN data to obtain a grayscale image; Marking the grayscale image according to the timestamp and attack mode of the grayscale image, uploading the marked data block to the server as a training sample data set, and inputting the unmarked data block into the convolutional autoencoder model corresponding to the client for several rounds of local unsupervised learning training to obtain an updated convolutional autoencoder model; Quantifying the updated model weights of the convolutional autoencoder model so that the server uses the FedAvg algorithm to input the training sample data set into the convolutional autoencoder model on the server side for global aggregation; The aggregated convolutional autoencoder model is updated in the server to reconstruct a supervised learning system, and the intrusion of the CAN data in different clients in the Internet of Vehicles is detected according to the reconstructed supervised learning system.

2. The method according to claim 1, characterized in that The client performs format conversion on the received CAN data to obtain a grayscale image, including: The client converts the received CAN data from a table form into an image, divides the CAN data into a number of data blocks according to the timestamp and feature size of the network traffic data set, and converts the data into a number of square single-channel grayscale images according to the key features of the data blocks.

3. The method according to claim 2, characterized in that Marking the grayscale image according to the timestamp and the attack mode of the grayscale image includes: The grayscale image is labeled according to the timestamp of the grayscale image and the attack mode of the data block. If all the data blocks of a grayscale image are normal samples, the grayscale image is marked as "normal"; if the data block of a grayscale image contains an attack sample, the attack type with the highest proportion in the data block in the grayscale image is marked.

4. The method according to any one of claims 1 to 3, characterized in that: The convolutional autoencoder model includes: a decoder and an encoder; The aggregated convolutional autoencoder model is updated in the server, specifically by removing the decoder and connecting the encoder to a fully connected network layer.

5. The method according to claim 4, characterized in that After inputting the unlabeled data block into the convolutional autoencoder model corresponding to the client for several rounds of local unsupervised learning training, an updated convolutional autoencoder model is obtained, including: The unlabeled data block is input into the encoder of the local convolutional autoencoder model corresponding to the client for encoding mapping to obtain the potential representation of the encoded data block: Z=f(W1X+b1) Where X is an unlabeled data block, X=(x1,x2,…,x n ), W1 is the weight matrix of the encoder, b1 is the bias, f(·) is the activation function, and Z is the potential representation of the encoded unlabeled data block; The latent representation of the encoded data block is reconstructed by the decoder to obtain the latent representation of the reconstructed data block: X′=f(W2Z+b2) Where X′ is the potential representation of the reconstructed data block, Z is the potential representation of the encoded unlabeled data block, W2 is the weight matrix of the decoder, b2 is the bias, and f(·) is the activation function; Construct a reconstruction error based on the potential representation of the encoded data block and the potential representation of the reconstructed data block: Where J(θ) is the reconstruction error, n is the number of unlabeled data blocks, θ is the training parameter, θ∈{W1,b1,W2,b2}, and RE(·) is the cost function; The model parameters of each round of local unsupervised learning training of the convolutional autoencoder model of the client on the unlabeled data block are optimized according to the reconstruction error to obtain an updated convolutional autoencoder model.

6. The method according to claim 5, characterized in that Quantifying the updated model weight of the convolutional autoencoder model so that the server uses the FedAvg algorithm to input the training sample data set into the convolutional autoencoder model on the server side for global aggregation, including: Quantize the updated model weights of the convolutional autoencoder model: R' f =S(Q i -Z) Among them, R t ′ is the model weight, s is the scaling factor, Z is the zero point of the target quantization value, R t is the original floating-point parameter value, Q t are the target model parameters, According to the model weight, the server uses the FedAvg algorithm to input the training sample data set into the convolutional autoencoder model on the server side for global aggregation.

7. The method according to claim 6, characterized in that The server updates the aggregated convolutional autoencoder model to reconstruct a supervised learning system, and detects the intrusion of the CAN data in different clients in the Internet of Vehicles according to the reconstructed supervised learning system, including: The received target model parameters are weighted averaged in the server to obtain global model parameters: Among them, w global is the global model parameter, K is the number of clients participating in the optimization training, n k is the unlabeled data block trained by the kth client, N is the total number of grayscale image data blocks, and w k are the global model parameters of the local convolutional autoencoder model of the kth client; The global model parameters are transmitted back to each client in the Internet of Vehicles to update the aggregated convolutional autoencoder model to reconstruct the supervised learning system, and the intrusion of the CAN data in different clients in the Internet of Vehicles is detected in the reconstructed supervised learning system.

8. A vehicle network intrusion detection system based on a federated autoencoder, characterized in that: The system comprises: A data conversion module, used for converting the format of the received CAN data through the client to obtain a grayscale image; A model updating module, used to mark the grayscale image according to the timestamp and attack mode of the grayscale image, upload the marked data block to the server as a training sample data set, and input the unmarked data block to the convolutional autoencoder model corresponding to the client for several rounds of local unsupervised learning training to obtain the updated convolutional autoencoder model; An aggregation module, used for quantifying the model weight of the updated convolutional autoencoder model, so that the server uses the FedAvg algorithm to input the training sample data set into the convolutional autoencoder model on the server side for global aggregation; An intrusion detection module is used to update the aggregated convolutional autoencoder model in the server to reconstruct the supervised learning system, and detect the intrusion of the CAN data in different clients in the Internet of Vehicles based on the reconstructed supervised learning system.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Internet of vehicles intrusion detection method and system based on mask stripe convolution auto-encoder

    CN122457385A

  • Internet of vehicles intrusion detection method and system based on mask strip convolutional autoencoder

    CN122457385B