Lightweight Internet of Vehicles intrusion detection method integrating multi-teacher distillation and boundary perception enhancement

By adopting multi-teacher distillation and boundary perception enhancement methods in vehicle network intrusion detection, the problems of high model complexity, data imbalance and limited generalization capabilities in the prior art are solved, and efficient and robust attack behavior recognition and early warning response are achieved.

CN120201435APending Publication Date: 2025-06-24GUANGZHOU UNIVERSITY
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202510482685.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The existing deep learning methods have problems such as high model complexity, data imbalance and limited generalization capabilities in vehicle intrusion detection, making it difficult to realize real-time detection on vehicle-mounted terminals and edge computing devices.

Method used

The lightweight Internet of Vehicles intrusion detection method that integrates multi-teacher distillation and boundary perception enhancement is adopted. The Internet of Vehicles traffic data is converted into two-dimensional image data through Gramian Angular Field technology, and the lightweight student model LAD Net is constructed, and the multi-teacher fusion model, boundary perception dynamic feature enhancement mechanism and adaptive distillation temperature regulation mechanism are optimized and trained.

Benefits of technology

The model's recognition performance for multiple complex attack types is improved, the problem of insufficient detection of a few types of attacks under data imbalance is solved, the model's performance in the inter-class boundary fuzzy samples is improved, and efficient and robust attack behavior recognition and early warning response is achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120201435A_ABST
    Figure CN120201435A_ABST
Patent Text Reader

Abstract

The invention relates to the field of Internet of Vehicles security, and particularly discloses a lightweight Internet of Vehicles intrusion detection method integrating multi-teacher distillation and boundary perception enhancement, which comprises the following steps: firstly, acquiring in-vehicle CAN bus flow data and out-vehicle network flow data, and dividing the data into a training set, a test set and a verification set; and the traffic data is converted into two-dimensional image data by using a Gramian Angular Field technology. Then, constructing a lightweight student model LAD Net, and adopting a multi-path feature extraction structure, a CBAM convolution attention module and a time convolution network TCN module; meanwhile, a multi-teacher fusion model is constructed based on a ResNet32 network, and optimization training is performed on the LAD Net through a boundary perception dynamic feature enhancement mechanism and an adaptive distillation temperature adjustment mechanism. And finally, the trained LAD Net is used for performing prediction and performance evaluation on the test set, so that the problems of high model complexity, data imbalance and insufficient generalization ability in the prior art are effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of vehicle networking security, and more specifically, to a lightweight vehicle networking intrusion detection method that combines multi-teacher distillation and boundary awareness enhancement. Background Art

[0002] With the rapid development of intelligent connected vehicles and vehicle networking (Vehicular Ad hoc Networks, VANET) technology, vehicle networking has improved traffic efficiency and safety through vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), and vehicle-to-cloud platform (V2C) interactions. However, its openness and the insecurity of wireless transmission, as well as the lack of authentication and encryption mechanisms in the controller area network (CAN bus), make vehicles vulnerable to DoS, fuzzing, and spoofing attacks, threatening the safety of passengers and drivers.

[0003] Regarding the security issues in vehicle networking, intrusion detection systems (IDSs), especially deep learning-based solutions, are receiving increasing attention due to their excellent feature extraction and anomaly detection capabilities. However, existing deep learning methods still have the following deficiencies:

[0004] Excessive model complexity: Current deep learning models usually have a large number of parameters and consume high computing resources, making it difficult to meet the real-time requirements of in-vehicle terminals and edge computing devices, resulting in an increase in detection latency.

[0005] Data imbalance problem: In actual vehicle networking scenarios, normal traffic data is much more than attack sample data, which makes the model tend to learn the features of normal data, thereby reducing the detection accuracy of minority-class attacks.

[0006] Limited generalization ability: The complexity of the vehicle networking environment and the continuous evolution of attack methods make existing models prone to missed detections and misjudgments when facing unknown attack types or variant attacks.

[0007] Although knowledge distillation and attention mechanisms (such as SE, CBAM, etc.) have been used to improve model performance, these methods still have some limitations. Specifically, traditional knowledge distillation methods adopt a static teacher guidance mechanism and cannot dynamically adjust the guiding role of the teacher model according to the complexity of attack samples and data distribution. Therefore, it is difficult to effectively address the data imbalance problem. In addition, most existing attention mechanisms adopt fixed weight allocation, lack adaptability, and still pay insufficient attention to the features of minority-class attacks.

[0008] Therefore, a lightweight vehicle networking intrusion detection method that combines multi-teacher distillation and boundary awareness enhancement is provided. Summary of the Invention

[0009] To solve the above technical problems, this application is proposed.

[0010] Specifically, according to one aspect of this application, a lightweight intrusion detection method for vehicle-to-everything (V2X) networks that combines multi-teacher distillation and boundary-aware enhancement is provided, which includes:

[0011] S1. Obtain in-vehicle Controller Area Network (CAN) bus traffic data and out-of-vehicle network traffic data as the V2X network traffic dataset, and divide the V2X network traffic dataset into a training set, a test set, and a validation set;

[0012] S2. Use the time series data to image conversion technology based on Gramian Angular Field to convert the V2X network traffic dataset into two-dimensional image data to obtain Gramian Angular Field (GAF) image data;

[0013] S3. Use a multi-path feature extraction structure, a Convolutional Block Attention Module (CBAM), and a Temporal Convolutional Network (TCN) module to construct a lightweight student model, namely Lightweight Anomaly Detection Network (LAD Net);

[0014] S4. Construct and train a multi-teacher fusion model based on the ResNet32 network;

[0015] S5. Optimize and train the lightweight student model LAD Net through the multi-teacher fusion model, a boundary-aware dynamic feature enhancement mechanism, and an adaptive distillation temperature adjustment mechanism based on the student prediction entropy value;

[0016] S6. Use the trained lightweight student model LAD Net to predict and evaluate the performance of the test set of the V2X network traffic data.

[0017] Among them, S5 includes: S51. Input the GAF image data into three groups of pre-trained teacher models and the lightweight student model LAD Net respectively, and output multi-source prediction probability distributions; among them, the prediction probability distribution output by each teacher model The calculation formula is expressed as:

[0018]

[0019] where t ∈ {T1, T2, T3} represents different teacher models, i represents the i-th input sample, represents the logits vector output by the teacher model; S52. Use the boundary-aware dynamic feature enhancement mechanism to adjust the attention weights of the CBAM in the lightweight student model LADNet; S53. Dynamically adjust the distillation temperature according to the student prediction entropy value using the adaptive distillation temperature adjustment mechanism; S54. Through the knowledge distillation loss L KD, Intermediate layer feature alignment loss L inter And the cross-entropy loss L between the student model and the true label ST Construct the total loss function for training the student model; S55, The trained and optimized lightweight student model LAD Net is solidified by parameters and converted into a lightweight model format suitable for edge deployment.

[0020] Preferably, the S2 includes: S21, Perform min-max normalization on the vehicle network traffic data to uniformly map the original data values into the interval [-1,1]. The normalization formula is expressed as:

[0021]

[0022] Where is the normalized data value, min(X) and max(X) are the minimum and maximum values in the time series data sequence respectively, and X = {x1, x2, …, x n} represents the vehicle network traffic data; S22, Map the normalized data to the polar coordinate system through angle transformation to obtain the angle value φ i of each data point. Among them, the angle value φ i is calculated by the following formula: Where

[0023] S23, Construct the Gramian Angular Field matrix, and the specific formula is expressed as:

[0024]

[0025] S24, Perform size adjustment operation on the Gramian Angular Field matrix to obtain GAF image data.

[0026] Preferably, the S52 includes: Calculate the entropy value of the prediction output of the lightweight student model LAD Net. The formula for calculating the entropy value is expressed as:

[0027]

[0028] Where is the prediction probability of the student model on the k-th class, and K is the total number of classes; Dynamically adjust the feature enhancement intensity of the CBAM convolutional attention module in the lightweight student model LAD Net according to the entropy value. The feature adjustment formula is expressed as:

[0029]

[0030] Among them, A is the attention weight calculated by the original CBAM convolutional attention module, A' is the dynamically adjusted attention weight, and λ is the weight scaling factor.

[0031] Preferably, the S53 includes the following temperature adjustment function:

[0032]

[0033] Among them, T min and T max are the set minimum and maximum temperature values respectively, is the entropy of the student model's predicted distribution, and K is the total number of categories.

[0034] Preferably, the S54 includes the knowledge distillation loss L KD :

[0035]

[0036] Among them, represents the softmax output probability of the k-th teacher model in the c-th class, represents the soft logits of the student model's predicted distribution after temperature smoothing; the teacher weight is calculated using the dynamic confidence weighting method, and the specific formula is as follows:

[0037]

[0038] The intermediate layer feature alignment loss L inter :

[0039]

[0040] Among them, is the intermediate feature extracted by the k-th teacher model, F S is the student model's intermediate feature, r(·) is the alignment mapping function, is the dynamic weighting coefficient for intermediate layer supervision; the total loss function for training the student model is: L = L ST + αL KD + βL inter , where L ST is the cross-entropy loss between the student model and the true label, and α and β are the weight hyperparameters of the loss terms.

[0041] Compared with the prior art, a lightweight vehicle network intrusion detection method that combines multi-teacher distillation and boundary awareness enhancement provided by the present application has the following remarkable effects:

[0042] (1) By adopting the GAF time-series data to image technology, the original vehicle network traffic data is effectively converted into a two-dimensional image representation, thereby enhancing the expression ability of attack features and improving the recognition performance of the model for various complex attack types.

[0043] (2) Design an adaptive multi-teacher dynamic distillation mechanism to automatically optimize the knowledge transfer process, enabling the student model to more accurately learn different attack features captured by the teacher model, thus solving the problem of insufficient detection of minority-class attacks by traditional methods in the context of data imbalance.

[0044] (3) Design a boundary-aware dynamic feature enhancement strategy to effectively improve the performance of the model on samples with blurred class boundaries.

[0045] (4) The present invention has conducted extensive experimental evaluations on various publicly available in-vehicle network and out-of-vehicle network traffic data sets. The results confirm that the model trained by the present invention not only has better detection performance than the prior art, but also has high efficiency and generalization, and is applicable to actual vehicle network security protection scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] The embodiments of the present application will be described in more detail by combining the accompanying drawings. The above and other objects, features, and advantages of the present application will become more apparent. The accompanying drawings are used to provide a further understanding of the embodiments of the present application, and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application, and do not constitute a limitation to the present application. In the accompanying drawings, the same reference numerals generally represent the same components or steps.

[0047] Figure 1 The flowchart of the method according to the embodiment of the present application is illustrated.

[0048] Figure 2 The structural diagram of the lightweight student model according to the embodiment of the present application is illustrated.

[0049] Figure 3 The structural diagram of training the lightweight student model (multi-teacher distillation) according to the embodiment of the present application is illustrated. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0050] Hereinafter, the embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. It should be understood that the present application is not limited by the example embodiments described herein.

[0051] Embodiment:

[0052] Figure 1 The flowchart of the method according to the embodiment of the present application is illustrated, as Figure 1As shown, the lightweight vehicle network intrusion detection method integrating multi-teacher distillation and boundary-aware enhancement according to an embodiment of the present application includes: S1. Obtain in-vehicle CAN bus traffic data and out-of-vehicle network traffic data as a vehicle network traffic dataset, and divide the vehicle network traffic dataset into a training set, a test set, and a validation set; S2. Use the time series data to image conversion technology based on Gramian Angular Field to convert the vehicle network traffic dataset into two-dimensional image data to obtain GAF image data; S3. Use a multi-path feature extraction structure, a CBAM convolutional attention module, and a temporal convolutional network TCN module to construct a lightweight student model LAD Net; S4. Construct and train a multi-teacher fusion model based on the ResNet32 network; S5. Optimize and train the lightweight student model LAD Net through the multi-teacher fusion model, the boundary-aware dynamic feature enhancement mechanism, and the adaptive distillation temperature adjustment mechanism based on the student prediction entropy value; S6. Use the trained lightweight student model LAD Net to predict and evaluate the performance of the test set of the vehicle network traffic data.

[0053] In the embodiment of the present application, in S1, obtain in-vehicle CAN bus traffic data and out-of-vehicle network traffic data as a vehicle network traffic dataset, and divide the vehicle network traffic dataset into a training set, a test set, and a validation set. Among them, the in-vehicle CAN bus traffic data includes normal traffic and various injection attack traffic, and the out-of-vehicle network traffic data includes normal WIFI and cellular network traffic, as well as various injected attack traffic.

[0054] Specifically, in the embodiments of the present application, all the data used are from publicly available standard datasets. Among them, two datasets are used for the in-vehicle CAN bus traffic data: the Car-Hacking dataset and the newly publicly available CICIOV2024 dataset. The Car-Hacking dataset is provided by the Hacker and Countermeasure Research Laboratory (HCR Lab), and the data comes from the CAN bus traffic recorded by actual vehicles through the OBD-II interface, including attacks such as Denial of Service (DoS) attacks, Fuzzy attacks, Gear spoofing, RPM spoofing, etc., as well as normal traffic data. The CICIOV2024 dataset is provided by the Canadian Institute of Cybersecurity (CIC). Through a large number of experiments on the internal electronic control unit (ECU) of Ford cars in 2019, detailed communication data of the in-vehicle CAN bus was captured, covering two types of attacks: Spoofing attacks and Denial of Service attacks (DoS), as well as the corresponding normal traffic data. For the out-of-vehicle network traffic data, the CICIDS2017 dataset is used. The CICIDS2017 dataset is jointly provided by the Canadian Institute of Cybersecurity (CIC) and the Communications Security Establishment (CSE), and includes normal network traffic and various typical network attack traffic data, such as brute-force FTP, brute-force SSH, DoS attacks, DDoS attacks, Botnets, Port Scan and other attack types.

[0055] The specific categories and sample distributions of the above three datasets are summarized in Tables 1, 2, and 3. The present invention divides all the obtained Internet of Vehicles traffic data into a training set, a test set, and a validation set according to a ratio of 7:2:1 for model training, optimization, and performance evaluation.

[0056] Class Label Number of Samples Normal 15,226,830 DoS 587,521 Fuzzy 491,847 RPM spoofing 654,897 Gear spoofing 597,252

[0057] Table 1 Summary of the sample distribution of the Car-Hacking dataset

[0058]

[0059] Table 2 Summary of the sample distribution of the CICIOV2024 dataset

[0060]

[0061] Table 3 Summary of the sample distribution of the CICIDS2017 dataset

[0062] In the embodiments of the present application, in S2, the vehicle - to - everything (V2X) traffic data set is converted into two - dimensional image data by using the time - series data - to - image technology based on Gramian Angular Field (GAF) to obtain GAF image data. It should be understood that the normal traffic data in the V2X traffic data is much more than the attack sample data, which causes the model to tend to learn the characteristics of normal data, thereby reducing the detection accuracy of minority - class attacks. The image after GAF conversion can more intuitively represent the dynamic changes of the time series. In the form of an image, it is easier to strengthen the characteristics of minority - class attack samples, thereby improving the detection ability of minority - class attacks. Therefore, in order to more effectively capture the potential attack behavior characteristics in V2X traffic data, the present invention proposes to use the Gramian Angular Field (GAF) method to convert the one - dimensional V2X traffic data obtained in step S1 into two - dimensional image data to retain and highlight the amplitude characteristics and time - series correlation of the time - series data.

[0063] Specifically, the GAF time - series - to - image process of S2 is as follows:

[0064] (1) Perform min - max normalization on the V2X traffic data to uniformly map the original data values into the interval [-1, 1]. The normalization formula is as follows:

[0065]

[0066] Where is the normalized data value, min(X) and max(X) are the minimum and maximum values in the time - series data sequence respectively, and X = {x1, x2, …, x n} represents the V2X traffic data.

[0067] (2) Map the normalized data to the polar coordinate system through angle transformation. The angle value φ i of each data point is calculated by the following formula:

[0068] Where

[0069] (3) According to the above - mentioned angle value φ i, further construct the Gramian Angular Field matrix (GAF matrix). The GAF matrix is a two-dimensional image representation form obtained by calculating the cosine value of the angle between any two data points. According to the specific calculation method, GAF can be divided into two types: Gramian Angular Summation Field (GASF) and Gramian Angular Difference Field (GADF). In the embodiment of the present application, GASF is adopted, and its calculation method is as follows:

[0070]

[0071] The symmetric matrix finally obtained by the above process is of size n×n, and each element clearly reflects the mutual relationship and time structure between data points. The generated GAF image can effectively capture and highlight the feature expression of time-series data under attack behavior, laying a solid foundation for subsequent feature learning based on convolutional neural networks.

[0072] (4) Perform a Resize operation on the symmetric matrix generated by the above GAF to obtain GAF image data. In this way, the unity requirement of the input of the subsequent neural network model can be met. For example, the image data is uniformly adjusted to a fixed-size image input, such as 32×32 or 64×64 pixel sizes, by bilinear interpolation or nearest-neighbor interpolation methods.

[0073] Through the above GAF time-series data to image method, the feature capture ability for attack behavior is significantly improved, especially beneficial to the accurate recognition of complex attack behaviors by the subsequent lightweight student model LAD Net and teacher model ResNet32, thus improving the overall performance of the vehicle network intrusion detection task.

[0074] In the embodiment of the present application, in S3, a lightweight student model LAD Net is constructed by using a multi-path feature extraction structure, a CBAM convolutional attention module, and a temporal convolutional network TCN module. In order to achieve efficient intrusion detection in the resource-constrained edge environment of the vehicle network, the present application proposes a lightweight student model LAD Net (Lightweight Attention Distillation Network). As Figure 2 shown, this model takes the GAF image as the input and is composed of a multi-path feature extraction structure, a convolutional attention mechanism, and a time-series modeling network. Its specific construction process includes:

[0075] 1>. Use a multi-path feature extraction structure to perform multi-scale feature extraction on GAF image data to obtain multi-scale feature maps. Specifically, the model first compresses the channels of the input GAF image through 1×1 convolution to reduce the subsequent computational burden. Then, the compressed feature map is divided into three parallel paths: the first path directly retains the original features to enhance the shallow feature expression during final fusion; the second path extracts middle-level features through 3×3 depthwise separable convolution and is divided into two sub-branches, one for direct fusion and the other for concatenating with the features of the third path; after concatenating with the sub-branch of the second path, the third path extracts high-level abstract attack features through depth convolution. This multi-path structure not only ensures computational efficiency but also constructs a multi-scale, low-redundancy, and high-resolution feature expression mechanism.

[0076] 2>. Use the CBAM convolutional attention module to enhance the features of key regions in the multi-scale feature map. Specifically, after feature fusion, the model introduces the convolutional attention module CBAM (Convolutional Block Attention Module) to enhance the expression ability of key region features. The CBAM module consists of two sub-modules: channel attention and spatial attention. The former generates attention weights in the channel dimension through max-pooling and average-pooling operations to enhance the model's attention to highly discriminative feature channels; the latter generates a spatial attention map to guide the model to focus on the image regions where attack behaviors may occur. CBAM is embedded between feature fusion and temporal modeling, effectively improving the model's ability to identify blurred boundary attack samples.

[0077] 3>. Input the enhanced feature map into the Temporal Convolutional Network (TCN) module for temporal modeling. TCN captures long-term dependencies through a multi-layer dilated convolution structure without increasing the model complexity, and models the evolution pattern of vehicle network attack behaviors in the time dimension. This structure not only retains the computational efficiency of the convolutional network but also significantly enhances the model's ability to understand sequence information.

[0078] 4>. Process the feature map output by the TCN module through global average pooling to convert it into a fixed-length vector, and input this fixed-length vector into a Softmax classifier for attack type prediction, finally achieving fast and accurate identification of various attack behaviors in the vehicle network environment.

[0079] That is, the LAD Net model achieves lightweight through a multi-path convolution structure, enhances the feature perception ability by introducing CBAM, and combines TCN to capture temporal features, achieving a good balance between model complexity and detection performance. It has been verified that this model not only outperforms traditional methods in terms of attack detection accuracy, but also due to its efficient structure, is suitable for practical deployment in resource-constrained scenarios such as vehicle terminals and edge nodes.

[0080] In the embodiment of this application, in S4, a multi-teacher fusion model is constructed and trained based on the ResNet32 network. In order to effectively improve the recognition performance of the lightweight student model for complex attack features, the present invention uses the GAF image data generated in step S2 as the model input, and through three different training processes on the ResNet32 model, teacher models with different feature capture capabilities are respectively obtained to provide rich attack feature expressions.

[0081] Specifically, in S4, the differential training strategy of the multi-teacher model is as follows:

[0082] The first training (basic teacher model, Teacher-1): Use the standard cross-entropy loss function (CrossEntropy Loss) to perform basic training on the ResNet32 network to obtain the weight W of the basic teacher model T1 that can better capture conventional attack features T1 , where the training objective function is defined as:

[0083]

[0084] The second training (data augmentation teacher model, Teacher-2): On the basis of the basic model training, introduce a random data augmentation strategy (Data Augmentation), such as randomly rotating, translating, cropping or adding slight noise, etc., to perturb the GAF image data. The weight of the data augmentation teacher model T2 obtained by training is W T2 . The data augmentation method makes the model have stronger robustness and enhanced sensitivity to complex or highly interfering attack patterns.

[0085] The third training (generalization enhancement teacher model, Teacher-3): On the basis of the second training, further adjust the training strategy, change the optimization algorithm (such as Adam, SGD or Adagrad) or optimization hyperparameters (learning rate, weight decay, batch size, etc.), and perform training under a wider data distribution to obtain the weight W of the generalization enhancement teacher model T3 with stronger generalization performance T3 . This model shows better generalization recognition ability when dealing with unknown or variant attack types.

[0086] The teacher model ResNet32 after three times of training, although using the same network structure, due to differences in strategies, data, or parameter adjustments during the training process, obtained differentiated weights with different attack feature capture capabilities, forming a "multi - perspective" attack feature expression of the teacher model. Based on this, the above - mentioned ResNet32 teacher model obtained through three different training strategies can provide richer and more diverse attack feature representations for the subsequent knowledge distillation training of the lightweight student model LAD Net, thereby effectively improving the attack feature capture ability and generalization performance of the student model.

[0087] Specifically, the ResNet32 network is a classic deep convolutional neural network with good feature extraction and generalization capabilities, suitable for image classification tasks. The ResNet32 network in the present invention is stacked by a number of residual modules. Each residual module consists of two convolutional layers and realizes the effective propagation of information through skip connections, thereby alleviating the problem of gradient disappearance in the training of deep networks. The calculation process of each residual block can be expressed as follows: Let the input feature be x, and the calculation process of the residual block is: y = F(x, W)+x, where F is the residual mapping function, W is the convolutional network parameter, x is the input feature, and y is the output of the residual block.

[0088] In the embodiment of the present application, the S5 optimizes and trains the lightweight student model LAD Net through a multi - teacher fusion model, a boundary - aware dynamic feature enhancement mechanism, and an adaptive distillation temperature adjustment mechanism based on the student prediction entropy value. After completing the construction of the student model structure and the training of the teacher model, it enters the overall training stage, and through the combination of the aforementioned multi - teacher dynamic distillation mechanism, adaptive temperature control mechanism, and boundary - aware feature enhancement mechanism, it conducts end - to - end optimization training on the student model LADNet. As Figure 3 shown, the specific training process is as follows:

[0089] 1) Input the GAF image data (converted from S2) into three groups of already trained teacher models and the lightweight student model LAD Net respectively, and output the multi - source prediction probability distributions. Among them, the prediction probability distribution calculation formula is expressed as: where t ∈ {T1, T2, T3} represents different teacher models, i represents the i - th input sample, represents the logits vector output by the teacher model. The prediction probability distribution output by each teacher model is used as a "soft label" to participate in the distillation training.

[0090] 2) To address the severe class imbalance problem in vehicle networking attack data and the characteristic that minority-class attack samples are easily overlooked near the decision boundary, a boundary-aware dynamic feature enhancement mechanism is proposed to significantly improve the model's recognition ability for boundary-blurred samples and sparse attack types. That is, using the boundary-aware dynamic feature enhancement mechanism, the attention weights of the CBAM convolutional attention module in the lightweight student model LAD Net are adjusted. The specific process is as follows:

[0091] First, calculate the entropy value of the prediction output of the lightweight student model LAD Net to measure the classification uncertainty of the model for the current sample. The higher the prediction entropy value, the more uncertain the model's judgment of the sample, usually indicating that the sample is near the class decision boundary or belongs to a minority class or an easily overlooked attack sample. The calculation formula of the entropy value is expressed as:

[0092]

[0093] where is the prediction probability of the student model for the k-th class, and K is the total number of classes.

[0094] Next, dynamically adjust the feature enhancement intensity of the CBAM convolutional attention module in the lightweight student model LAD Net according to the entropy value. For fuzzy boundary samples and rare attack samples with higher entropy values, the model can adaptively increase the feature weights of the corresponding regions in the CBAM attention module to strengthen the expression of these key but easily overlooked attack features. The specific feature adjustment formula is expressed as:

[0095]

[0096] where A is the attention weight calculated by the original CBAM convolutional attention module, A′ is the dynamically adjusted attention weight, and λ is the weight scaling factor that controls the influence degree of the model on feature enhancement.

[0097] In this way, through the above boundary-aware dynamic feature enhancement mechanism, this application can effectively enhance the attention of the student model to minority-class attacks and boundary-blurred samples, further improve the classification performance and generalization ability of the model, and significantly alleviate the negative impact brought by data imbalance.

[0098] 3) To improve the flexibility and expression ability of the student model in the process of learning complex samples, the present invention further proposes an adaptive distillation temperature adjustment mechanism based on the student prediction entropy value. That is, according to the student prediction entropy value The distillation temperature is dynamically adjusted using an adaptive distillation temperature adjustment mechanism. The higher the predicted entropy value, the greater the uncertainty of the model for this sample. At this time, the distillation temperature should be lowered to enhance the ability to capture the features of this complex sample. When the entropy value is low, the temperature is increased to make the distillation signal smoother. The temperature adjustment function is as follows:

[0099]

[0100] Among them, T min and T max are the set minimum and maximum temperature values respectively, is the entropy of the predicted distribution of the student model, and K is the total number of categories;

[0101] 4), During the training process, the overall loss function of the student model consists of three parts: one is the prediction error for the true label (the cross-entropy loss L ST ) between the student model and the true label, which is used to ensure the basic classification performance; the second is the distillation error (knowledge distillation loss L KD ) with multiple teacher models, which is used to inherit the deep attack features extracted by the teacher models; the third is the consistency error of the intermediate layer features between the student and teacher models (intermediate layer feature alignment loss L inter ), which is used to align the deep expressions. That is, in the embodiments of this application, through the knowledge distillation loss L Kd , the intermediate layer feature alignment loss L inter and the cross-entropy loss L ST between the student model and the true label, these three loss functions are used to construct the total loss function L for training the student model. The specific construction of the distillation total loss function is as follows:

[0102] Knowledge distillation loss L KD :

[0103]

[0104] Among them, represents the softmax output probability of the k-th teacher model in the c-th class, represents the soft logits of the predicted distribution of the student model after temperature smoothing; the teacher weight is calculated using a dynamic confidence weighting method, and the specific formula is as follows:

[0105]

[0106] At the same time, the intermediate layer feature alignment loss L inter is introduced to improve the learning ability of the student model for the deep features of the teacher. Its calculation formula is as follows:

[0107]

[0108] Among them, is the intermediate feature extracted by the k-th teacher model, F s is the intermediate feature of the student model, and r(·) is the alignment mapping function. is the dynamic weighting coefficient of the intermediate layer supervision;

[0109] The total loss function for training the student model is:

[0110] L = L ST + αL KD + βL inter

[0111] Among them, L ST is the cross-entropy loss between the student model and the true label, and α and β are the weight hyperparameters of the loss terms.

[0112] Finally, the trained student model LAD Net is optimized and converted into a lightweight model format suitable for edge deployment (such as ONNX or TensorRT) by parameter freezing. This model can be deployed on in-vehicle computing platforms or vehicle network edge nodes to perform intrusion detection tasks on real-time traffic data in the vehicle network, achieving efficient and robust attack behavior recognition and warning response.

[0113] In the embodiment of this application, in S6, the trained lightweight student model LAD Net is used to predict and evaluate the performance of the test set of vehicle network traffic data. It should be understood that, to evaluate the actual performance of the lightweight vehicle network intrusion detection method that fuses channel attention and adaptive multi-teacher knowledge distillation mechanism proposed in this application, this application uses the trained and deployed student model LAD Net, and uses the independent test set of vehicle network traffic data divided in step S1 for performance verification. The test data set covers in-vehicle CAN bus traffic data (Car-Hacking data set and CICIoV2024 data set) and out-of-vehicle network traffic data (CICIDS2017 data set), which can comprehensively evaluate the generalization performance and actual detection ability of the model of the present invention.

[0114] Specifically, during the performance evaluation of S6, three typical and important performance evaluation indicators were selected, namely Accuracy, F1_score, and Inference Time, to comprehensively evaluate the performance of the model in identifying normal traffic and attack traffic. Among them, Accuracy can intuitively reflect the overall prediction accuracy of the model, the F1 score is especially suitable for evaluating the model's performance in identifying attack traffic, especially minority-class attacks, in the case of data imbalance, while the average single-sample inference time (Inference Time) can effectively measure the response speed of the model during actual operation and is an important reference basis for evaluating whether it has real-time detection capabilities in resource-constrained environments such as in-vehicle terminals and edge nodes. The calculation methods for the three performance indicators are as follows:

[0115]

[0116] Among them, TP represents true positive, TN represents true negative, FP represents false positive, and FN represents false negative.

[0117]

[0118] Among them, T total represents the total time (in milliseconds) consumed by the model to complete inference on the entire test set, and N is the total number of test samples. The detailed model performance evaluation results for different test data sets are shown in Table 4:

[0119]

[0120] Table 4 Model Performance Test Results

[0121] In summary, the lightweight vehicle network intrusion detection method integrating multi-teacher distillation and boundary-aware enhancement according to the embodiments of the present application is clarified. It first obtains in-vehicle CAN bus traffic data and out-of-vehicle network traffic data, divides them into training sets, test sets, and validation sets, and uses the Gramian Angular Field technology to convert the traffic data into two-dimensional image data. Then, a lightweight student model LAD Net is constructed, adopting a multi-path feature extraction structure, a CBAM convolutional attention module, and a temporal convolutional network TCN module. At the same time, a multi-teacher fusion model is constructed based on the ResNet32 network, and LAD Net is optimized and trained through a boundary-aware dynamic feature enhancement mechanism and an adaptive distillation temperature adjustment mechanism. Finally, the trained LAD Net is used to predict and evaluate the performance of the test set, effectively solving the problems of high model complexity, data imbalance, and insufficient generalization ability in the prior art.

[0122] It is obvious to those skilled in the art that the present invention is not limited to the details of the above-described exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0123] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit of the technical solutions of the present invention.

Claims

1. A lightweight vehicle network intrusion detection method integrating multi-teacher distillation and boundary perception enhancement, characterized in that: include: S1, obtaining in-vehicle CAN bus traffic data and out-vehicle network traffic data as an Internet of Vehicles traffic data set, and dividing the Internet of Vehicles traffic data set into a training set, a test set, and a verification set; S2, using a time series data to image technology based on Gramian Angular Field to convert the IoV traffic data set into two-dimensional image data to obtain GAF image data; S3, using the multi-path feature extraction structure, CBAM convolutional attention module and temporal convolutional network TCN module to build a lightweight student model LAD Net; S4, build and train the multi-teacher fusion model based on ResNet32 network; S5, optimize the training of the lightweight student model LAD Net through a multi-teacher fusion model, a dynamic feature enhancement mechanism based on boundary perception, and an adaptive distillation temperature adjustment mechanism based on the student prediction entropy value; S6. Use the trained lightweight student model LAD Net to predict and evaluate the performance of the test set of IoV traffic data. The S5 comprises: S51, input GAF image data into three sets of trained teacher models and lightweight student model LADNet respectively, and output multi-source prediction probability distribution; Among them, the predicted probability distribution output by each teacher model is The calculation formula is expressed as: Among them, t∈{T1,T2,T3} represents different teacher models, i represents the i-th sample of the input, The logits vector representing the output of the teacher model; S52. Use the boundary-aware dynamic feature enhancement mechanism to adjust the attention weight of the CBAM convolutional attention module in the lightweight student model LAD Net; S53, based on students' predicted entropy value The distillation temperature is dynamically adjusted using an adaptive distillation temperature regulation mechanism; S54, through knowledge distillation loss L KD , intermediate layer feature alignment loss L inter And the cross entropy loss L between the student model and the true label ST Construct the total loss function for student model training; S55. The lightweight student model LAD Net that has been trained and optimized is solidified through parameters and converted into a lightweight model format suitable for edge deployment.

2. The lightweight vehicle network intrusion detection method integrating multi-teacher distillation and boundary perception enhancement according to claim 1 is characterized in that: The S2 comprises: S21. Perform minimum-maximum normalization on the Internet of Vehicles traffic data, and uniformly map the original data values ​​to the interval [-1,1]. The normalization formula is expressed as: in, is the normalized data value, min(X) and max(X) are the minimum and maximum values ​​in the time series data sequence, respectively, X={x1,x2,…,x n } represents the traffic data of Internet of Vehicles; S22, the normalized data Mapped to the polar coordinate system through angle transformation to obtain the angle value φ of each data point i , where the angle value φ i Calculated by the following formula: in S23. Construct the Gramian Angular Field matrix. The specific formula is: S24. Perform a size adjustment operation on the Gramian Angular Field matrix to obtain GAF image data.

3. The lightweight vehicle network intrusion detection method integrating multi-teacher distillation and boundary perception enhancement according to claim 2 is characterized in that: The S3 includes: S31, performing multi-scale feature extraction on the GAF image data using a multi-path feature extraction structure to obtain a multi-scale feature map; S32, performing key area feature enhancement on the multi-scale feature map through a CBAM convolutional attention module; wherein the CBAM convolutional attention module includes channel attention and spatial attention; S33, inputting the enhanced feature map into the temporal convolutional network (TCN) module for temporal modeling; S34. The feature map output by the temporal convolutional network (TCN) module is processed by global average pooling and converted into a fixed-length vector, and the fixed-length vector is input into the Softmax classifier for attack type prediction.

4. The lightweight vehicle network intrusion detection method integrating multi-teacher distillation and boundary perception enhancement according to claim 3 is characterized in that: The S4 comprises: First training: Using GAF image data as input, the ResNet32 network is trained using the standard cross entropy loss function to obtain the weights W of the basic teacher model T1. T1 , where the training objective function is defined as: Second training: weight W of the basic teacher model T1 obtained from the first training T1 , introduce random data enhancement strategy to perturb the GAF image data and obtain the weight W of the data enhancement teacher model T2 T2 ; Third training: Based on the second training, change the optimization algorithm or optimize the hyperparameters, use the enhanced GAF ​​image data for training, and obtain the weight W of the generalized enhanced teacher model T3 T3 .

5. The lightweight vehicle network intrusion detection method integrating multi-teacher distillation and boundary perception enhancement according to claim 4 is characterized in that: In S4, the ResNet32 network includes several residual modules, and the calculation process of each residual module is shown in the following formula: y=F(x,W)+x Among them, F is the residual mapping function, W is the convolutional network parameter, x is the input feature, and y is the residual module output.

6. The lightweight vehicle network intrusion detection method integrating multi-teacher distillation and boundary perception enhancement according to claim 5 is characterized in that: The S52 includes: The entropy value of the predicted output of the lightweight student model LAD Net is calculated, and the entropy value calculation formula is expressed as: in, is the predicted probability of the student model on the kth category, K is the total number of categories; The feature enhancement strength of the CBAM convolutional attention module in the lightweight student model LAD Net is dynamically adjusted according to the entropy value. The feature adjustment formula is expressed as: Among them, A is the attention weight calculated by the original CBAM convolutional attention module, A′ is the dynamically adjusted attention weight, and λ is the weight scaling factor.

7. The lightweight vehicle network intrusion detection method integrating multi-teacher distillation and boundary perception enhancement according to claim 6 is characterized in that: The S53 includes: the temperature adjustment function is as follows: Among them, T min and T max are the minimum and maximum temperature values ​​set respectively, is the entropy of the student model prediction distribution, and K is the total number of categories.

8. The lightweight vehicle network intrusion detection method integrating multi-teacher distillation and boundary perception enhancement according to claim 7 is characterized in that: The S54 comprises: Knowledge distillation loss L KD : in, represents the softmax output probability of the k-th teacher model in the c-th category, The soft logits representing the predicted distribution of the student model after temperature smoothing; the teacher weight The dynamic confidence weighting method is used for calculation. The specific formula is as follows: Intermediate layer feature alignment loss L inter : in, is the intermediate feature extracted by the kth teacher model, F S is the intermediate feature of the student model, r(·) is the alignment mapping function, is the dynamic weight coefficient of the intermediate layer supervision; The total loss function for student model training is: L=L ST +αL KD +βL inter Among them, L ST is the cross entropy loss between the student model and the true label, and α and β are the weight hyperparameters of the loss term.

9. The lightweight vehicle network intrusion detection method integrating multi-teacher distillation and boundary perception enhancement according to claim 8 is characterized in that: In S6, the performance of the trained lightweight student model LAD Net is evaluated by accuracy, F1 score F1_score and average inference time Inference Time. The performance index calculation method is as follows: Where TP stands for true positive, TN stands for true negative, FP stands for false positive, and FN stands for false negative; Among them, T total It represents the total time taken by the model to complete reasoning on the entire test set, and N is the total number of test samples.

Citation Information

Cited By

  • Knowledge distillation double-teacher model-based Internet of Things malicious traffic detection method and system

    CN120750644A

  • Airport runway intrusion identification method based on ESNB algorithm

    CN121121672A

  • Airport runway intrusion identification method based on esnb algorithm

    CN121121672B

  • Light-weight man-machine interaction model system for industrial scene application

    CN121213892A

  • Intelligent retrieval method and system for CAD design features based on knowledge graph

    CN121255870A