Intelligent Connected Vehicle Intrusion Detection Method Based on Time Series and Vehicle Dynamics

By combining deep learning time series prediction model, vehicle dynamics model and expert experience, the extended Kalman filtering and clustering method is adopted to realize joint detection of the intelligent connected vehicle network layer and the physical layer, solving the insufficient detection of existing detection methods under complex attacks, and improving the accuracy of vehicle state estimation and abnormal detection.

CN120185932BActive Publication Date: 2025-07-22HANGZHOU INTERNATIONAL INNOVATION INSTITUTE OF BEIHANG UNIVERSITY +1

Patent Information

Application Number
CN202510654182.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-07-22
Estimated Expiration
2045-05-21

AI Technical Summary

Technical Problem

When facing complex cross-level attacks, existing intelligent connected vehicle intrusion detection methods cannot accurately identify physical layer exceptions caused by network attacks, and lack joint analysis of the network layer and the physical layer, resulting in insufficient detection capabilities.

Method used

Using a deep learning time series prediction model and vehicle dynamics model combined with expert experience, a hyperspheric boundary envelope normal sample is constructed by extended Kalman filtering and fused vehicle state estimation, and a clustering method is used to detect intrusion attacks.

Benefits of technology

It significantly improves the accuracy of vehicle state estimation and the accuracy of detection of abnormal behaviors, enhances the adaptability and robustness of the system, and provides strong technical guarantees for the safety protection of intelligent connected vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185932B_ABST
    Figure CN120185932B_ABST
Patent Text Reader

Abstract

The present invention provides an intrusion detection method for intelligent connected vehicles based on time series and vehicle dynamics, belonging to the technical field of information security of intelligent connected vehicles. This method integrates a deep learning time series prediction model, a vehicle dynamics model, and expert experience. The high-level vehicle states of the autonomous driving system are predicted through the deep learning model, and the physical states are estimated by combining vehicle dynamics and expert experience to form a comprehensive state estimation. The extended Kalman filter is used to fuse the real-time measurement values to obtain the optimal state estimation. By calculating the residuals between the optimal estimation and the real-time measurement values, a historical residual data set is constructed, and the clustering method is adopted to learn the normal residual distribution. A hypersphere boundary is defined to envelope the normal samples, realizing accurate intrusion detection. The present invention significantly improves the accuracy of vehicle state estimation, the detection accuracy of abnormal behaviors, and the system security, providing technical support for the safety protection of intelligent connected vehicles.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security for intelligent connected vehicles, and particularly to an intrusion detection method for intelligent connected vehicles based on time series and vehicle dynamics. Background Art

[0002] Intelligent connected vehicles (ICVs) are an important future development direction of the automotive industry. ICVs can obtain a large amount of data in real time and interact with the external environment, other vehicles, and infrastructure through V2X communication, greatly improving traffic efficiency and driving experience. However, with the increasing networking and automation of intelligent connected vehicles, the information security risks faced by vehicles have increased significantly, and the attack surface of vehicles has been continuously expanding. Therefore, various intrusion detection methods have emerged, including rule-based detection, anomaly-based detection, machine learning-based detection, etc., in the hope of timely discovering information security events and alleviating automotive security risks.

[0003] However, these traditional detection methods have significant deficiencies. Currently, many methods rely solely on individual network traffic for detection. These methods usually use historical data modeling or rule setting to identify attacks, and often cannot accurately identify physical layer anomalies caused by network attacks when facing complex cross-layer attacks. Especially when facing advanced attacks, they lack effective detection capabilities; physics-based methods rely on vehicle state estimation for detection. Although they can monitor the physical state of the vehicle to a certain extent, they usually rely on a single dynamics model or sensor data and cannot comprehensively consider the impact of complex dynamic environments and driving behaviors on the vehicle state; most existing intrusion detection technologies focus on independent analysis of the network layer or the physical layer, lack joint analysis of the two, and fail to effectively integrate the security states of the network layer and the physical layer, resulting in a lack of global detection capabilities for the system.

[0004] Therefore, there is an urgent need for a brand-new intrusion detection method that enables ICVs to comprehensively consider the security of the vehicle network layer and the stability of the physical state in complex environments, quickly and accurately identify unknown attacks, and make up for the deficiencies of existing detection methods. Summary of the Invention

[0005] In order to overcome the deficiencies of the prior art, the purpose of the present invention is to provide an intrusion detection method for intelligent connected vehicles based on time series and vehicle dynamics, which significantly improves the accuracy of vehicle state estimation, the detection accuracy of abnormal behaviors, and system security, providing technical support for the security protection of intelligent connected vehicles.

[0006] To achieve the above purpose, the present invention provides the following solution:

[0007] An intrusion detection method for intelligent connected vehicles based on time series and vehicle dynamics, comprising the following steps:

[0008] S1. Perform time series prediction on in-vehicle network messages of a vehicle based on a deep learning model to obtain vehicle prediction states that cannot be directly calculated;

[0009] S2. Calculate vehicle physical states that can be directly solved based on a vehicle dynamics estimation model and expert experience;

[0010] S3. Combine the vehicle prediction states that cannot be directly calculated with the vehicle physical states that can be directly solved to form a comprehensive state estimation value of the vehicle. Based on the vehicle real-time state measurement values extracted from the in-vehicle network messages, fuse the vehicle real-time state measurement values with the comprehensive state estimation value of the vehicle through an extended Kalman filter algorithm to obtain an optimal state estimation value of the vehicle;

[0011] S4. Calculate the residual between the optimal state estimation value of the vehicle and the in-vehicle network real-time measurement values, and construct a data set in combination with historical residual data to obtain a system historical residual eigenvalue. Learn from the residual data based on a clustering method, identify normal residual distribution patterns, and define a hypersphere boundary to enclose normal samples to detect intrusion attacks on the vehicle.

[0012] Preferably, in S1, performing time series prediction on in-vehicle network messages of a vehicle based on a deep learning model to obtain vehicle prediction states that cannot be directly calculated includes:

[0013] Extract historical in-vehicle network messages based on the in-vehicle network of the same vehicle model; the extracted historical in-vehicle network messages include time stamps, CAN IDs, and data fields;

[0014] According to the extracted historical in-vehicle network messages, directly existing target states will be extracted as labels of the model, and target states that cannot be directly recorded will be derived and generated as labels through external sensors or relevant rules;

[0015] Preprocess the extracted label data, including data cleaning, normalization, and time alignment of the label data according to time series characteristics;

[0016] Perform continuous time series segmentation on the preprocessed label data using a sliding window method to generate input-output sample pairs; among them, the input is the features of several historical time steps, and the output is the target state of the next time step;

[0017] Based on a deep learning network traffic prediction model, input the generated input-output sample pairs into the model for training, and output vehicle prediction states that cannot be directly calculated by learning the historical patterns of vehicle state changes over time.

[0018] Preferably, the vehicle prediction states that cannot be directly calculated are:

[0019] ;

[0020] By utilizing t the vehicle state data at time - 1, predict t the target state at

[0021] Preferably, in S2, calculate the directly solvable vehicle physical state based on the vehicle dynamics estimation model and expert experience, including:

[0022] Establish a vehicle dynamics model: Describe vehicle motion using the vehicle's three - degree - of - freedom dynamics model, and predict the vehicle state through control inputs and in - vehicle network data;

[0023] Preliminary state estimation: Based on the vehicle's three - degree - of - freedom dynamics model, use the current - moment state information to predict the vehicle state at the next moment;

[0024] Introduce expert experience: Identify and correct specific events or behavior patterns that the vehicle's three - degree - of - freedom dynamics model cannot capture, and incorporate expert experience into the state estimation in the form of a weighting coefficient to dynamically adjust the estimation result;

[0025] Comprehensive estimation: Combine the corrections of the dynamics model and expert experience to obtain an accurate estimated value of the computable vehicle physical state.

[0026] Preferably, describe vehicle motion using the vehicle's three - degree - of - freedom dynamics model, predict the vehicle state through control inputs and in - vehicle network data, and predict the vehicle state at the next moment from the state information at the current moment, including:

[0027] The vehicle t state variables at , from the sensor measurement values in the in - vehicle network message at the previous moment:

[0028] ;

[0029] Based on this, predict the state of the vehicle at the next moment t :

[0030] ;

[0031] And describe the vehicle state change by a differential equation:

[0032] ;

[0033] Among them, the longitudinal acceleration: ;

[0034] The lateral acceleration: ;

[0035] The yaw acceleration: ;

[0036] In the formula, is the vehicle mass; is the position coordinate of the vehicle on the plane; are the longitudinal speed and lateral speed of the vehicle respectively; is the longitudinal traction force of the vehicle; is the longitudinal resistance of the vehicle; are the lateral forces of the front and rear tires respectively; is the vehicle heading angle; is the yaw rate; are the distances from the vehicle's center of mass to the front and rear axles respectively; is the moment of inertia of the vehicle about the vertical axis;

[0037] Then the current t formula for calculating the vehicle state at the moment:

[0038] ;

[0039] Among them:

[0040] .

[0041] Preferably, the state data of the dynamic calculation is weighted and corrected by expert experience. The correction of the expert experience is dynamically adjusted by the weighting coefficient. The finally obtained vehicle physical state that can be directly solved is:

[0042] ;

[0043] In the formula, is the state data calculated by the dynamic model; is the weighting coefficient, ; is the state data after weighted correction by expert experience; is the vehicle physical state that can be directly solved.

[0044] Preferably, in S3, the non-directly calculable vehicle predicted state is combined with the directly solvable vehicle physical state to form a comprehensive state estimate of the vehicle, including:

[0045] The directly solvable vehicle state estimate obtained from vehicle dynamics and expert experience and the non-directly calculable vehicle state estimate obtained from the deep learning time series prediction model , combined into a complete state estimate of the vehicle :

[0046] ;

[0047] In the above formula:

[0048] , represents the directly solvable vehicle dynamics state update, is the input at time;

[0049] , represents the state update of the deep learning time series model of the vehicle state that cannot be directly solved;

[0050] , represents the error term between the directly solvable vehicle state estimate obtained from vehicle dynamics and expert experience and the non-directly computable vehicle state estimate obtained from the deep learning time series prediction model, assumed to be Gaussian noise, where: , are respectively and the noises of.

[0051] Preferably, in S3, based on the vehicle real-time state measurement values extracted from the in-vehicle network messages, the vehicle real-time state measurement values are fused with the comprehensive state estimate of the vehicle through the extended Kalman filter algorithm to obtain the optimal state estimate of the vehicle, including:

[0052] Fusing through the extended Kalman filter algorithm, since and there is a coupling relationship between them, it is necessary to linearize :

[0053] ;

[0054] Where:

[0055] ;

[0056] ;

[0057] ;

[0058] In the formula, is the non-linear function of the vehicle state; is the Jacobian matrix of this function with respect to the state , used to approximate the state change; is the linearized part of the vehicle dynamics state equation with respect to the vehicle state ; is the linearized part of the deep learning model with respect to ;

[0059] The linearized state transition formula is:

[0060] ;

[0061] In the formula:

[0062] , ;

[0063] Among them, represents the derivative of the vehicle dynamics state equation with respect to the input;

[0064] Calculation of the optimal state estimate of the vehicle:

[0065] Extract from the CAN bus The complete state of the vehicle at time, i.e., the measured value:

[0066] ;

[0067] In the formula, H is the measurement matrix, including the predicted state of the vehicle that cannot be directly calculated and the physical state of the vehicle that can be directly solved;

[0068] Subsequent measurement noise:

[0069] ;

[0070] And linearize the measurement model:

[0071] ;

[0072] The result in the prediction stage is:

[0073] ;

[0074] ;

[0075] Among them, is the state predicted according to the state and input at time, is the covariance matrix of state estimation, is the process noise covariance matrix;

[0076] Subsequently, perform the correction stage to obtain:

[0077] ;

[0078] ;

[0079] ;

[0080] Among them, is the Kalman gain matrix, is the corrected covariance matrix, For the required Optimal estimate at the moment.

[0081] Preferably, in S4, calculate the residual between the optimal state estimate value of the vehicle and the real-time measurement value of the vehicle-mounted network, construct a data set in combination with historical residual data, obtain the system historical residual eigenvalue, and learn the residual data based on the clustering method to identify the normal residual distribution pattern, and define the hypersphere boundary to envelope the normal samples to detect the intrusion attack of the vehicle, including:

[0082] The optimal state estimate value of the vehicle And the real-time measurement value of the vehicle-mounted network Perform residual calculation to obtain :

[0083] Calculate the centroid c of the normal data set:

[0084] ;

[0085] Where n Is the historical length data, Is the Residual at the moment;

[0086] Define the maximum distance of the normal residual , that is, the radius of the hypersphere:

[0087] ;

[0088] According to the characteristics of the normal residual distribution, define the hypersphere boundary, and the normal residual should be located within the hypersphere:

[0089] ;

[0090] And perform multiple optimal estimates on the historical residual data to obtain the data set:

[0091] ;

[0092] Cluster the residual data, learn the residual distribution pattern at normal historical moments, and use the hypersphere boundary to define the distribution space of the normal state, include the normal samples within this space, and the abnormal samples are far away from this space to detect the intrusion attack of the vehicle.

[0093] Preferably, the intrusion attack detection of the vehicle includes two stages:

[0094] Training and calibration stage: When the intelligent connected vehicle is not under attack, use the normal data to train the attack detector to obtain the attack detection model, where the detection model envelopes the normal detection points within the range of the feature space. If the relevant features exceed the hypersphere boundary, that is , it is considered to be under an intrusion attack;

[0095] Detection stage: Input the sliding window data of the vehicle into the attack detection model, calculate the distance of each data point from the boundary of the hypersphere to obtain an anomaly score. If the anomaly score is not 0, it is considered that the vehicle is under a related attack.

[0096] According to the specific embodiments provided by the present invention, the following technical effects are disclosed by the present invention:

[0097] (1) By combining a deep learning time series prediction model, a vehicle dynamics model, and expert experience, the present invention realizes the joint detection of the network layer and the physical layer, overcomes the limitations of traditional detection methods, significantly improves the comprehensive detection ability of intelligent connected vehicles, and can accurately identify physical layer anomalies caused by network attacks.

[0098] (2) The present invention not only improves the accuracy of vehicle state estimation and the accuracy of anomaly detection, but also enhances the adaptability and robustness of the system through an extended Kalman filter and a dynamic detection mechanism based on residual clustering, providing a strong technical guarantee for the safety protection of intelligent connected vehicles and significantly improving the overall safety of the vehicle. BRIEF DESCRIPTION OF THE DRAWINGS

[0099] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0100] Figure 1 It is a flowchart of an intrusion detection method for an intelligent connected vehicle based on time series and vehicle dynamics according to the present invention;

[0101] Figure 2 It is a schematic diagram of the principle of an intrusion detection method for an intelligent connected vehicle based on time series and vehicle dynamics according to the present invention;

[0102] Figure 3 It is a schematic diagram of the principle of step S1 provided in Embodiment 1 of the present invention;

[0103] Figure 4 It is a schematic diagram of the principle of step S2 provided in Embodiment 1 of the present invention;

[0104] Figure 5 It is a schematic diagram of the principle of step S3 provided in Embodiment 1 of the present invention;

[0105] Figure 6 It is a schematic diagram of the principle of step S4 provided in Embodiment 1 of the present invention. Detailed implementation mode

[0106] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative work shall fall within the protection scope of the present invention.

[0107] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation modes.

[0108] Embodiment 1

[0109] As Figure 1 and Figure 2 shown, the present invention provides an intrusion detection method for intelligent connected vehicles based on time series and vehicle dynamics, including the following steps:

[0110] S1. Perform time series prediction on the in-vehicle network messages of the vehicle based on a deep learning model to obtain the vehicle prediction state that cannot be directly calculated;

[0111] S2. Calculate the vehicle physical state that can be directly solved based on the vehicle dynamics estimation model and expert experience;

[0112] S3. Combine the vehicle prediction state that cannot be directly calculated with the vehicle physical state that can be directly solved to form a comprehensive state estimation value of the vehicle. Based on the vehicle real-time state measurement value extracted from the in-vehicle network message, fuse the vehicle real-time state measurement value and the comprehensive state estimation value of the vehicle through the extended Kalman filter algorithm to obtain the optimal state estimation value of the vehicle;

[0113] S4. Calculate the residual between the optimal state estimation value of the vehicle and the in-vehicle network real-time measurement value, and construct a data set in combination with historical residual data to obtain the system historical residual feature value. Learn from the residual data based on the clustering method, identify the normal residual distribution pattern, and define the hyper-sphere boundary to enclose the normal samples to detect the intrusion attack of the vehicle.

[0114] Referring to Figure 3 the schematic diagram of step S1 provided, in S1, performing time series prediction on the in-vehicle network messages of the vehicle based on a deep learning model to obtain the vehicle prediction state that cannot be directly calculated includes:

[0115] Extract historical in-vehicle network messages based on the in-vehicle network of the same vehicle model; the extracted historical in-vehicle network messages include time stamps, CAN IDs, and data fields;

[0116] Based on the extracted historical in-vehicle network messages, the directly existing target states will be extracted as the labels of the model, and for the target states that cannot be directly recorded, labels will be generated through external sensors or relevant rules.

[0117] Preprocess the extracted label data, including data cleaning, normalization, and time alignment of the label data according to the characteristics of the time series.

[0118] Use the sliding window method to segment the preprocessed label data into continuous time series, generating input-output sample pairs; among them, the input is the features of several historical time steps, and the output is the target state of the next time step.

[0119] Based on the deep learning-based network traffic prediction model, input the generated input-output sample pairs into the model for training, and by learning the historical patterns of vehicle state changes over time, output the vehicle prediction states that cannot be directly calculated.

[0120] Among them, the vehicle prediction states that cannot be directly calculated are:

[0121] ;

[0122] By using t the vehicle state data at time -1, predict the t target state at time

[0123] Referring to Figure 4 the schematic diagram of step S2 provided, in S2, calculate the directly solvable vehicle physical states based on the vehicle dynamics estimation model and expert experience, including:

[0124] Establish a vehicle dynamics model: Describe vehicle motion using the vehicle's three - degree - of - freedom dynamics model, and predict vehicle states through control inputs and in - vehicle network data.

[0125] Preliminary state estimation: Based on the vehicle's three - degree - of - freedom dynamics model, use the current - moment state information to predict the vehicle's next - moment state.

[0126] Introduce expert experience: Identify and correct specific events or behavior patterns that the vehicle's three - degree - of - freedom dynamics model cannot capture, and incorporate expert experience into the state estimation in the form of weighted coefficients to dynamically adjust the estimation results.

[0127] Comprehensive estimation: Combine the corrections of the dynamics model and expert experience to obtain an accurate estimated value of the calculable vehicle physical state.

[0128] In the above process, first, a preliminary state estimation is performed based on the vehicle's dynamic model, and the state of the vehicle at the next moment is predicted through control inputs and in-vehicle network message data. The dynamic model provides a theoretical basis for the vehicle's motion behavior. However, since the model itself cannot fully cover the complex factors in actual driving, such as driver behavior, environmental changes, sensor errors, etc., the estimation relying solely on the dynamic model may not reflect the true state of the vehicle. To make up for this deficiency, this embodiment introduces expert experience. Expert experience is the long-term accumulation of driving behavior and vehicle state, which can identify and correct specific events or behavior patterns that cannot be captured by the dynamic model. Expert experience is usually incorporated into the state estimation process in the form of weighted correction. Specifically, the preliminary state estimation provided by the dynamic model can be corrected by expert experience, and expert experience dynamically adjusts the estimation result based on real-time driving behavior, environmental information, and the vehicle's dynamic response. In this process, expert experience is not a simple static correction, but a dynamic adjustment based on real-time data and specific situations. The input of expert experience can come from multiple aspects, such as:

[0129] Cockpit domain information: such as the feedback of the steering wheel, instrument panel, and the operating states of the accelerator pedal and brake pedal;

[0130] Driver behavior: such as sudden driver behavior patterns like hard acceleration and hard braking;

[0131] Advanced Driver Assistance System (ADAS): such as the feedback of systems like lane keeping and automatic braking.

[0132] Through the weighted adjustment of expert experience, the accuracy of state estimation is improved, and accurate state correction can be provided when the vehicle exhibits special behaviors or complex scenarios. The final vehicle state estimation can better conform to the actual driving environment and the true state of the vehicle.

[0133] Specifically, the vehicle motion is described using the vehicle's three-degree-of-freedom dynamic model, and the vehicle state is predicted through control inputs and in-vehicle network data. The vehicle state at the next moment is predicted from the state information at the current moment, including:

[0134] The vehicle t state variables at the moment, which are the sensor measurement values from the in-vehicle network messages at the previous moment:

[0135] ;

[0136] Based on this, the state of the vehicle at the next moment t is predicted:

[0137] ;

[0138] And the vehicle state change is described by a differential equation:

[0139] ;

[0140] Among them, longitudinal acceleration: ;

[0141] Lateral acceleration: ;

[0142] Yaw acceleration: ;

[0143] In the formula, is the vehicle mass; is the position coordinate of the vehicle on the plane; are the longitudinal speed and lateral speed of the vehicle respectively; is the longitudinal traction force of the vehicle; is the longitudinal resistance of the vehicle; are the lateral forces of the front and rear tires respectively; is the vehicle heading angle; is the yaw rate; are the distances from the vehicle center of mass to the front and rear axles respectively; is the moment of inertia of the vehicle about the vertical axis;

[0144] Then the calculation formula for the vehicle state at the current t moment:

[0145] ;

[0146] Among them:

[0147] .

[0148] In addition, the state data of the dynamic calculation is weighted and corrected through expert experience. The correction of expert experience is dynamically adjusted through the weighting coefficient. The finally obtained vehicle physical state that can be directly solved is:

[0149] ;

[0150] In the formula, is the state data calculated by the dynamic model; is the weighting coefficient; is the state data after weighted correction by expert experience; is the vehicle physical state that can be directly solved. is the weighting coefficient, which reflects the contribution ratio of the vehicle dynamics model and expert experience in state estimation. Under normal circumstances, the prediction of the vehicle dynamics model occupies a larger proportion. When the system detects abnormalities or the driving behavior does not match the model prediction, the proportion of expert experience will be increased accordingly for correction. For example, when the steering wheel turns sharply, it may indicate that the driver is making an emergency avoidance or a sharp turn. At this time, expert experience can increase the weights of the steering angle and speed estimation to correct the steering angle or vehicle speed that may be underestimated by the dynamics model.

[0151] As shown in Table 1, several typical expert experience inputs and their corresponding correction methods are listed, showing how to perform weighted correction on the vehicle state through real-time events.

[0152] Table 1 Expert Experience

[0153] ;

[0154] Refer to Figure 5 the schematic diagram of step S3 provided. In S3, the vehicle prediction state that cannot be directly calculated is combined with the vehicle physical state that can be directly solved to form a comprehensive state estimate of the vehicle, including:

[0155] The vehicle state estimate that can be directly solved obtained from vehicle dynamics and expert experience and the vehicle state estimate that cannot be directly calculated obtained from the deep learning time series prediction model are combined into a complete state estimate of the vehicle :

[0156] ;

[0157] In the above formula:

[0158] represents the update of the directly solvable vehicle dynamics state, is the input at time

[0159] represents the state update of the deep learning time series model of the vehicle state that cannot be directly solved;

[0160] represents the error term between the directly solvable vehicle state estimate obtained from vehicle dynamics and expert experience and the non-directly calculable vehicle state estimate obtained from the deep learning time series prediction model, assumed to be Gaussian noise, where: , are respectively and the noises of.

[0161] Specifically, in S3, based on the vehicle real-time state measurement values extracted from in-vehicle network messages, the vehicle real-time state measurement values are fused with the comprehensive state estimation values of the vehicle through the extended Kalman filter algorithm to obtain the optimal state estimation values of the vehicle, including:

[0162] When fusing through the extended Kalman filter algorithm, since and have a coupling relationship, it is necessary to linearize :

[0163] ;

[0164] Among them:

[0165] ;

[0166] ;

[0167] ;

[0168] In the formula, is the non-linear function of the vehicle state; is the Jacobian matrix of this function with respect to the state , which is used to approximate the state change; is the linearized part of the vehicle dynamics state equation with respect to the vehicle state ; is the linearized part of the deep learning model with respect to ;

[0169] The linearized state transition formula is:

[0170] ;

[0171] In the formula:

[0172] , ;

[0173] Among them, represents the derivative of the vehicle dynamics state equation with respect to the input;

[0174] Calculation of the optimal state estimation values of the vehicle:

[0175] Extract the complete state of the vehicle at from the CAN bus, that is, the measurement value:

[0176] ;

[0177] In the formula, His the measurement matrix, including the predicted vehicle state that cannot be directly calculated and the vehicle physical state that can be directly solved;

[0178] Subsequently, the measurement noise:

[0179] ;

[0180] And linearize the measurement model:

[0181] ;

[0182] The result in the prediction stage is:

[0183] ;

[0184] ;

[0185] Among them, is the state predicted according to the state and input at time, is the covariance matrix of state estimation, is the process noise covariance matrix;

[0186] Subsequently, perform the correction stage to obtain:

[0187] ;

[0188] ;

[0189] ;

[0190] Among them, is the Kalman gain matrix, is the corrected covariance matrix, is the required optimal estimate at time.

[0191] Referring to the schematic diagram of step S4 provided in Figure 6 , in S4, calculate the residual between the optimal state estimate value of the vehicle and the real-time measurement value of the vehicle network, and construct a data set in combination with historical residual data to obtain the system historical residual eigenvalue, and learn the residual data based on the clustering method to identify the normal residual distribution pattern, and define the hypersphere boundary to enclose the normal samples to detect the intrusion attack of the vehicle, including:

[0192] The optimal state estimate value of the vehicle and the real-time measurement value of the vehicle network are used for residual calculation to obtain :

[0193] Calculate the centroid c of the normal data set:

[0194] ;

[0195] Wherein, n is the historical length data, is the residual at the

[0196] Define the maximum distance of the normal residual , that is, the radius of the hypersphere:

[0197] ;

[0198] According to the characteristics of the normal residual distribution, define the hypersphere boundary, and the normal residual should be located within the hypersphere:

[0199] ;

[0200] And perform multiple optimal estimations on the historical residual data to obtain a data set:

[0201] ;

[0202] Cluster the residual data, learn the residual distribution pattern at normal historical moments, and use the hypersphere boundary to define the distribution space of the normal state. Include normal samples within this space, and abnormal samples are far from this space to detect vehicle intrusion attacks.

[0203] Specifically, the vehicle intrusion attack detection includes two stages:

[0204] Training and calibration stage: When the intelligent connected vehicle is not under attack, use normal data to train the attack detector to obtain an attack detection model. In the detection model, the normal detection points are enveloped within a certain range in the feature space. If the relevant features exceed the hypersphere boundary, that is , it is considered that an intrusion attack has occurred;

[0205] Detection stage: Input the sliding window data of the vehicle into the attack detection model, calculate the distance between each data point and the hypersphere boundary to obtain an anomaly score. If the anomaly score is not 0, it is considered that the vehicle has been attacked.

[0206] In this article, specific examples are used to elaborate on the principles and implementation methods of the present invention. The descriptions of the above embodiments are only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. An intrusion detection method for intelligent connected vehicles based on time series and vehicle dynamics, characterized in that Including the following steps: S1. Perform time series prediction on the in-vehicle network messages of the vehicle based on a deep learning model to obtain the vehicle prediction state that cannot be directly calculated; S2. Calculate the directly solvable vehicle physical state based on the vehicle dynamics estimation model and expert experience; S3. Combine the vehicle prediction state that cannot be directly calculated with the directly solvable vehicle physical state to form a comprehensive state estimation value of the vehicle. Based on the vehicle real-time state measurement value extracted from the in-vehicle network message, fuse the vehicle real-time state measurement value and the comprehensive state estimation value of the vehicle through the extended Kalman filter algorithm to obtain the optimal state estimation value of the vehicle; S4. Calculate the residual between the optimal state estimation value of the vehicle and the in-vehicle network real-time measurement value, and construct a data set in combination with historical residual data to obtain the system historical residual eigenvalue. Based on the clustering method, learn the residual data to identify the normal residual distribution pattern, and define the hypersphere boundary to enclose the normal samples to detect the intrusion attack of the vehicle; Including: clustering the residual data, learning the residual distribution pattern at normal historical moments, and using the hypersphere boundary to define the distribution space of the normal state, including the normal samples in this space and keeping the abnormal samples away from this space to detect the intrusion attack of the vehicle; The intrusion attack detection of the vehicle includes two stages: Training and calibration phase: When the intelligent connected vehicle is not under attack, the attack detector is trained using normal data to obtain an attack detection model. In the detection model, the normal detection points are enclosed within the range in the feature space. If the relevant features exceed the hypersphere boundary, that is , it is considered to be under an intrusion attack; Detection stage: Input the sliding window data of the vehicle into the attack detection model, calculate the distance between each data point and the hypersphere boundary to obtain the anomaly score. If the anomaly score is not 0, it is considered that the vehicle is under relevant attacks.

2. The intelligent networked vehicle intrusion detection method based on time series and vehicle dynamics according to claim 1, wherein, In S1, performing time series prediction on the in-vehicle network messages of the vehicle based on a deep learning model to obtain the vehicle prediction state that cannot be directly calculated, including: Extracting historical in-vehicle network messages based on the in-vehicle network of the same vehicle model; the extracted historical in-vehicle network messages include time stamps, CAN IDs, and data fields; According to the extracted historical in-vehicle network messages, the directly existing target state will be extracted as the label of the model, and the target state that cannot be directly recorded will be derived and generated as a label through external sensors or relevant rules; Preprocessing the extracted label data, including data cleaning, normalization processing, and time alignment of the label data according to the time series characteristics; Using the sliding window method to perform continuous time series segmentation on the preprocessed label data to generate input-output sample pairs; where the input is the features of several historical time steps, and the output is the target state of the next time step; Based on the deep learning network traffic prediction model, input the generated input-output sample pairs into the model for training, and output the vehicle prediction state that cannot be directly calculated by learning the historical pattern of the vehicle state changing over time.

3. An intrusion detection method for intelligent connected vehicles based on time series and vehicle dynamics according to claim 2, characterized in that The vehicle prediction state that cannot be directly calculated is: ; By utilizing t the vehicle state data at time - 1, predict t the target state at the moment.

4. An intrusion detection method for intelligent connected vehicles based on time series and vehicle dynamics according to claim 3, characterized in that, In S2, calculating the directly solvable vehicle physical state based on the vehicle dynamics estimation model and expert experience, including: Establishing a vehicle dynamics model: Describing the vehicle motion using the vehicle's three-degree-of-freedom dynamics model, and predicting the vehicle state through control inputs and in-vehicle network data; Initial state estimation: Based on the vehicle's three-degree-of-freedom dynamic model, use the state information at the current moment to predict the vehicle's state at the next moment; Introduce expert experience: Identify and correct specific events or behavior patterns that the vehicle's three-degree-of-freedom dynamic model cannot capture, incorporate expert experience into the state estimation in the form of weighted coefficients, and dynamically adjust the estimation results; Comprehensive estimation: Combine the dynamics model and the correction of expert experience to obtain an accurate estimated value of the vehicle's physical state that can be calculated.

5. An intrusion detection method for intelligent connected vehicles based on time series and vehicle dynamics according to claim 4, characterized in that, Describe the vehicle motion using the vehicle's three-degree-of-freedom dynamic model, predict the vehicle state through control inputs and in-vehicle network data, and predict the vehicle state at the next moment from the state information at the current moment, including: Vehicle t State variable at a moment , sensor measurement values from in - vehicle network messages at the previous moment: ; To predict the state of the vehicle at the next moment t : ; And describe the vehicle state change by differential equations: ; Among them, longitudinal acceleration: ; Lateral acceleration: ; Yaw acceleration: ; Wherein, is the vehicle mass; is the position coordinate of the vehicle on the plane; are the longitudinal speed and lateral speed of the vehicle respectively; is the longitudinal traction force of the vehicle; is the longitudinal resistance of the vehicle; are the side slip forces of the front and rear tires respectively; is the heading angle of the vehicle; is the yaw rate; are the distances from the vehicle's center of mass to the front and rear axles respectively; is the moment of inertia of the vehicle about the vertical axis; Then the current t Calculation formula for the vehicle state at the moment: ; Where: 。 6. The intelligent networked vehicle intrusion detection method based on time series and vehicle dynamics according to claim 5, characterized in that The state data calculated by dynamics is weighted and corrected by expert experience. The correction of expert experience is dynamically adjusted by weighted coefficients. The finally obtained vehicle physical state that can be directly solved is: ; In the formula, is the state data calculated by the kinetic model; is the weighting coefficient, ; is the state data after weighted correction by expert experience; is the vehicle physical state that can be directly solved.

7. An intrusion detection method for intelligent connected vehicles based on time series and vehicle dynamics according to claim 6, characterized in that, In S3, combine the non-directly calculable vehicle prediction state with the directly solvable vehicle physical state to form a comprehensive state estimation value of the vehicle, including: The directly solvable vehicle state estimation values obtained from vehicle dynamics and expert experience and the non-directly computable vehicle state estimation values obtained from the deep learning time series prediction model are combined into the complete state estimation of the vehicle : ; In the above formula: , representing the directly solvable vehicle dynamics state update, is the input at the moment; , representing the state update of a deep learning time series model of vehicle states that cannot be directly solved; , representing the error term between the directly solvable vehicle state estimation value obtained from vehicle dynamics and expert experience and the indirectly computable vehicle state estimation value obtained from the deep learning time series prediction model, assumed to be Gaussian noise, where: , are respectively and noise.

8. An intrusion detection method for intelligent connected vehicles based on time series and vehicle dynamics according to claim 7, characterized in that, In S3, based on the vehicle real-time state measurement values extracted from in-vehicle network messages, fuse the vehicle real-time state measurement values with the comprehensive state estimation value of the vehicle through the extended Kalman filter algorithm to obtain the optimal state estimation value of the vehicle, including: Fusion is performed by the extended Kalman filter algorithm. Since there is a coupling relationship between and , linearization of is required: ; Where: ; ; ; wherein, is a non-linear function of the vehicle state; is the Jacobian matrix of the function with respect to the state for approximating the state change; is the linearized part of the vehicle dynamics state equation with respect to the vehicle state ; is the linearized part of the deep learning model with respect to ; The linearized state transition formula is: ; In the formula: , ; Among them, represents the derivative of the vehicle dynamics state equation with respect to the input; Calculation of the vehicle's optimal state estimation value: Extract from the CAN bus The complete vehicle state at a given moment, i.e., the measured values: ; In the formula, H is a measurement matrix, including the predicted vehicle state that cannot be directly calculated and the physical vehicle state that can be directly solved; Subsequent measurement noise: ; And linearize the measurement model: ; The result in the prediction stage is: ; ; wherein, is the predicted state based on the state and input at time, is the covariance matrix of state estimation, is the process noise covariance matrix; Subsequently, perform the correction stage to obtain: ; ; ; Among them, is the Kalman gain matrix, is the corrected covariance matrix, is the optimal estimate at the required 9. An intrusion detection method for intelligent connected vehicles based on time series and vehicle dynamics according to claim 8, characterized in that, In S4, calculate the residual between the optimal state estimation value of the vehicle and the in-vehicle network real-time measurement value, construct a data set in combination with historical residual data to obtain the system historical residual eigenvalue, and learn from the residual data based on the clustering method to identify the normal residual distribution pattern, and define the hypersphere boundary to envelope the normal samples to detect the intrusion attack of the vehicle, including: The optimal state estimation value of the vehicle and the real-time measurement values of the in-vehicle network are used to calculate the residuals, resulting in : Calculate the centroid of the normal data set : ; Among them, is historical length data, is the residual at the Define the maximum distance of the normal residual , which is the radius of the hypersphere: ; According to the characteristics of the normal residual distribution, define the hypersphere boundary, and the normal residual should be inside the hypersphere: ; And perform multiple optimal estimations on the historical residual data to obtain the data set: 。

Citation Information

Patent Citations

  • Malicious user detection method based on residual mean value in vehicle cooperation dynamic tracking

    CN111292538A

  • Dynamic data flow clustering method for network intrusion behavior detection

    CN117150322A

Cited By

  • Method for predicting and blocking abnormal behaviors of intelligent networked automobiles based on diffusion model

    CN122262955A