Vehicle-mounted network security risk assessment method based on heterogeneous graph neural network

By constructing a heterogeneous graph neural network, extracting the attributes and structural characteristics of the on-board network nodes, the problem of failure to effectively evaluate the on-board network security situation in the existing technology is solved, and a comprehensive and accurate risk assessment of the on-board network is achieved.

CN120342675APending Publication Date: 2025-07-18CHONGQING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510450500.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing in-vehicle network security risk assessment methods fail to effectively consider network structure and real-time state, it is difficult to deal with a large amount of network traffic and attacks, and the lack of spatial structure information representation of situation characteristics, resulting in limited evaluation accuracy.

Method used

Using a heterogeneous graph neural network method, a heterogeneous graph data of device nodes, channel nodes and attack alarm information of the vehicle network are constructed, and a metapath sequence is generated using a predefined metapath template. The node attribute features are extracted in combination with a bidirectional long and short-term memory network and attention mechanism. The Metapath2Vec algorithm is used to randomly walk to learn structural features, and the risk assessment results are output through a multi-layer perceptron.

Benefits of technology

It can comprehensively and accurately evaluate the security situation of the on-board network, identify the context semantic information of specific attack patterns and attack chains, capture complex associations and spatial structure information between nodes, and improve the accuracy and comprehensiveness of the evaluation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342675A_ABST
    Figure CN120342675A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of artificial intelligence operation and maintenance, and particularly relates to a vehicle-mounted network security risk assessment method based on a heterogeneous graph neural network, which comprises the following steps: constructing equipment nodes, channel nodes and attack alarm information in a vehicle-mounted network in a certain time window and mutual relationships thereof into heterogeneous graph data; performing serialization processing based on meta-paths on the constructed data by utilizing a predefined meta-path template, and generating a plurality of meta-path sequences for each node; processing a meta-path sequence by adopting a bidirectional long-short-term memory network in combination with an attention mechanism, and extracting node attribute features; adopting a Metapath2Vec algorithm to carry out random walk based on a meta path, and learning generated sequence representation so as to extract structural features of nodes; fusing the attribute feature and the structure feature of each node to obtain a vector representation of each node; and fusing the vector representation of each equipment node by adopting an attention mechanism, inputting a representation result into the multi-layer perceptron, and outputting a vehicle-mounted network risk assessment result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of artificial intelligence security, and specifically relates to a vehicle-mounted network security risk assessment method based on heterogeneous graph neural networks. Background Art

[0002] In recent years, with the rapid increase in the number of cars, the importance of active safety, traffic efficiency and network protection has become increasingly prominent, and the research and development of the Internet of Vehicles has received extensive attention. The Internet of Vehicles has greatly improved traffic efficiency and driving safety by connecting vehicles, road infrastructure, pedestrians and other equipment. However, the high interconnectivity and complexity of the Internet of Vehicles also bring significant network security risks, such as malicious intrusion, data tampering and privacy leakage. Therefore, fully understanding the overall security status of vehicle networks is a hot issue that needs to be solved urgently.

[0003] Network security risk assessment is one of the most common and effective solutions. It monitors network security in real time, obtains the current security status, provides decision-making support for network security managers, discovers potential security risks in the network at the first time, and fully evaluates the impact of these hidden dangers, helping network security managers to understand the current network status and take containment and prevention measures against these threats before network attacks occur.

[0004] Research on network security risk assessment has made great progress, but so far, no systematic theoretical system has been formed. Traditional methods based on mathematical logic models and knowledge reasoning models can integrate the overall situation of the network to a certain extent and provide decision-making suggestions for network managers. However, as the network enters the era of big data, some traditional methods cannot meet the requirements of handling large amounts of network traffic and attacks. They usually rely too much on expert evaluation and logical reasoning. Although their accuracy is high, it is difficult to evaluate the situation based on the real-time status of the network; some machine learning-based models are more efficient, but they do not consider the correlation between various devices in the risk assessment process. The evaluation process lacks the representation and learning of spatial structure information in situation characteristics, which limits the accuracy of the model.

[0005] In view of the problems existing in the risk assessment model, such as not considering the network structure and relying on prior knowledge, the present invention proposes a vehicle network risk assessment method based on heterogeneous graph neural network. Summary of the invention

[0006] To solve the above problems, the present invention provides a vehicle network risk assessment method based on a heterogeneous graph neural network, comprising the following steps:

[0007] S1: The device nodes, channel nodes, and attack warning information in the vehicle network within a certain time window and their mutual relationships are constructed into heterogeneous graph data;

[0008] S2: Use the predefined metapath template to perform metapath serialization processing on the data, and generate multiple metapath sequences for each node;

[0009] S3: Adopt a bidirectional long short-term memory network combined with an attention mechanism to process the metapath sequences and extract node attribute features;

[0010] S4: Use the Metapath2Vec algorithm to perform metapath-based random walks, learn the generated sequence representations, and thus extract the structural features of the nodes;

[0011] S5: Fuse the attribute features and structural features of each node to obtain the node vector of each node;

[0012] S6: Use the attention mechanism to fuse the vector representations of each device node, input the representation result into a multi-layer perceptron, and output the vehicle network risk assessment result.

[0013] Further, step S2 uses the predefined metapath template to perform metapath serialization processing on the data, and generate multiple metapath sequences for each node, including:

[0014] S21: Define the metapath set MP = {MP1, MP2,..., MP n}, and each metapath MP i represents an ordered node type sequence MP i = (t i1 → t i2 →... → t ik ), where t ij represents the type of the j-th node in the path, and the node types include devices, attacks, or channels;

[0015] S22: For the heterogeneous graph G(V, E, T, X), given the starting node according to the starting type t i of the metapath MP i1 expand it to the terminal type t ik in turn according to the predefined expansion rules;

[0016] S23: During the expansion process, if the current node v i is connected to the node v j , that is, A[v i , v j = 1, and the type of v j meets the requirements of the next metapath, that is, T[v j = t i+1 , then v jAs the next expansion node, successively construct a complete node sequence S = {v1, v2, …, v k}, where , and (v i , v i+1 ) ∈ E;

[0017] S24: Repeat steps S22 and S23 until all nodes generate corresponding metapath sequences and form the final metapath sequence set

[0018] Furthermore, step S3 uses a bidirectional long short-term memory network combined with an attention mechanism to process the metapath sequences and extract node attribute features, including:

[0019] S31: Use the matrix projection method e v = W A · x v to linearly transform the node features so that the feature dimensions of all nodes are unified. Here, W A is a parameterized projection matrix, x v is the original feature of node v, and e v is the transformed feature vector;

[0020] S32: Use a bidirectional long short-term memory network to encode all metapath sequences, capture the semantic information of the node sequence from the front and back, and model the relationship in combination with the features of the nodes to obtain the encoded representation of each metapath instance;

[0021] S33: For the semantic representations of multiple path instances under the same metapath, use the attention mechanism to calculate the importance weights of each instance to obtain the semantic representation of the node under each type of metapath;

[0022] S34: Use the attention mechanism to fuse the semantic information of different metapaths to generate the final node representation A = {A1, A2,..., A n}, where n is the number of nodes.

[0023] Furthermore, step S4 uses the Metapath2Vec algorithm to perform a random walk based on the metapath and learn the generated sequence representation, thereby extracting the structural features of the nodes, including:

[0024] S41: Ignore the node features of the heterogeneous graph G(V, E, T, X) to obtain an attributeless graph G(V, E, T);

[0025] S42: Generate multiple node access sequences on the graph using a random walk strategy based on metapath constraints. During the random walk process, only jumps along edges that conform to the metapath are allowed to ensure that the generated node sequences can reflect the true relationships between device nodes and other nodes, thereby preserving the topological structure information of the vehicle-mounted network;

[0026] S43: Using the generated node access sequences, perform unsupervised learning with the Skip-gram model. The goal of Skip-gram is to maximize the conditional probability of its neighbor node c given the central node v. The objective function is defined as follows: t The conditional probability of, the target function is defined as follows:

[0027]

[0028] where, N t (v) represents the set of neighbor nodes of type t, p(c t |v; θ) is the probability distribution obtained by softmax, and is the model training parameter. By optimizing the above objective function, the model can learn the low-dimensional vector representation of each device node, making the distances between structurally similar devices closer in the vector space, thereby capturing the structural features of device nodes and the topological features of different attack patterns;

[0029] S44: After training, the node embedding representation S generated by Metapath2Vec v is used as the structural feature of the device node, and finally the feature set of the device node is obtained: S = {S1, S2,..., S n}}.

[0030] Furthermore, step S5 fuses the attribute features and structural features of each node to obtain the node vector of each node, including:

[0031] S51: Based on the extracted attribute features and structural features of the device node, splice the different features of the node to obtain the initial comprehensive representation of the node, and its dimension is:

[0032] S52: To further optimize the node representation, use a learnable feature fusion matrix to perform dimensionality reduction mapping on the spliced features to obtain the final node representation F. The calculation process is as follows:

[0033] F = Concat(A, S)W

[0034] where, F = {F1, F2,..., F n} represents the feature set of device nodes. Concat(·) is the feature concatenation operation in step S51, which is used to fuse the attribute features and structural features of nodes.

[0035] 7. Further, in step S6, an attention mechanism is used to fuse the vector representations of each device node, and the representation result is input into a multi-layer perceptron to output the risk assessment result of the vehicle-mounted network, including:

[0036] S61: Use a feature aggregation method based on the attention mechanism to dynamically learn the correlation between nodes. For each node v, calculate its attention weight α v ;

[0037] S62: According to the attention scores, use global attention pooling to aggregate the hidden representations of all device nodes to obtain the overall feature representation R;

[0038] S63: Input the global feature representation R after the above feature aggregation into a multi-layer perceptron, and use multiple fully connected layers for non-linear transformation to output the risk assessment result of the vehicle-mounted network.

[0039] S64: Use the mean square error as the loss function to optimize the prediction effect of the model, and use the following formula to measure the error between the predicted value and the true value y:

[0040]

[0041] where, is the predicted value of the i-th sample, and y i is the true label value, and N is the number of training samples. By minimizing the loss function, the weight parameters of the MLP model are optimized so that it can accurately predict the security situation of the vehicle-mounted network.

[0042] By minimizing the loss function, the weight parameters of the MLP model are optimized so that it can accurately predict the security risks of the vehicle-mounted network.

[0043] The present invention has at least the following beneficial effects

[0044] This paper proposes a vehicle-mounted network risk assessment method based on a heterogeneous graph neural network. This model can effectively analyze and process complex attack information. By capturing the complex associations and spatial structure information between nodes, it can not only identify specific attack patterns but also extract the context semantic information of the attack chain, so as to comprehensively and accurately evaluate the security situation of the vehicle-mounted network.

[0045] In this paper, a bidirectional long short-term memory network is used to process the sequence data generated based on metapaths to extract the semantic features between nodes, and the attention mechanism is combined to dynamically assign weights to different nodes to highlight the role of key nodes. At the same time, Metapath2Vec is used to perform random walks on the heterogeneous graph to learn the structural features of each node. In addition, by combining the features obtained by the two methods, not only can the relationship patterns between different nodes in the vehicle network be fully mined, but also the structural differences of attack behaviors can be effectively captured, and the risk status of the vehicle network can be comprehensively considered. Description of the Drawings

[0046] Figure 1 It is a flowchart of a vehicle network security risk assessment method based on a heterogeneous graph neural network according to the present invention;

[0047] Figure 2 It is a block diagram of a vehicle network security risk assessment method based on a heterogeneous graph neural network according to the present invention;

[0048] Figure 3 It is a schematic diagram of the semantic information representation module of the present invention. Detailed Embodiment

[0049] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0050] The present invention provides a vehicle network security risk assessment method based on a heterogeneous graph neural network, as Figure 1 、 Figure 2 shown, including the following steps:

[0051] S1: Construct the device nodes, channel nodes, attack warning information and their mutual relationships in the vehicle network within a certain time window into heterogeneous graph data.

[0052] S2: Use a predefined metapath template to perform metapath serialization processing on the data to generate multiple metapath sequences for each node.

[0053] In the vehicle network, there are various attack patterns and they involve different and complex attack links. Metapaths guide neighbor node selection by predefined complex relationships between nodes, construct the semantic context information of nodes, help the model capture the semantic information of the heterogeneous graph, and focus on specific attack patterns to improve the performance of the regression task.

[0054] Specifically, in step S2, the data is processed based on meta-path serialization using a predefined meta-path template to generate multiple meta-path sequences for each node, including:

[0055] S21: Define a set of meta-paths MP = {MP1, MP2, …, MP n}, and each meta-path MP i represents an ordered sequence of node types MP i = (t i1 → t i2 → … → t ik ), where t ij represents the type of the j-th node in the path, and the node types include devices, attacks, or channels;

[0056] S22: For the heterogeneous graph G(V, E, T, X), given the starting node According to the starting type t i of the meta-path MP i1 extend it to the terminal type t ik in turn according to the predefined extension rules;

[0057] S23: During the extension process, if the current node v i is connected to the node v j , that is, A[v i , v j = 1, and the type of v j meets the requirements of the next meta-path, that is, T[v j = t i+1 , then take v j as the next extension node, and sequentially construct a complete node sequence S = {v1, v2, …, v k}, where and (v i , v i+1 ) ∈ E;

[0058] S24: Repeat steps S22 and S23 until meta-path sequences are generated for all nodes and a final set of meta-path sequences is formed

[0059] S3: Use a bidirectional long short-term memory network combined with an attention mechanism to process the meta-path sequences and extract node attribute features.

[0060] Vehicular networks contain various types of nodes and edges, representing entities such as vehicles and sensors and their diverse interaction patterns, with high dynamics and complex sequential dependencies. To effectively capture these characteristics, a bidirectional long short-term memory network is used to process the metapath sequence, as it is good at learning sequential dependencies in the sequence, understanding the interactions between different entities over time, and comprehensively analyzing the roles and interactions of each node through bidirectional information flow. Combining the attention mechanism, the model can focus on key parts of the sequence, enhance the learning of important features, and thus more accurately extract the node attribute features. The computational process of the model is as Figure 3 shown:

[0061] Specifically, step S3 uses a bidirectional long short-term memory network combined with the attention mechanism to process the metapath sequence and extract node attribute features, including:

[0062] S31: Use the matrix projection method e v = W A ·x v to perform a linear transformation on the node features, so that the feature dimensions of all nodes are unified. Here, W A is the parameterized projection matrix, x v is the original feature of node v, and e v is the transformed feature vector;

[0063] S32: Use a bidirectional long short-term memory network to encode all metapath sequences, capture the semantic information of the node sequence from the forward and backward directions, and model the relationship by combining the features of the nodes to obtain the encoded representation of each metapath instance;

[0064] S33: For the semantic representations of multiple path instances under the same metapath, use the attention mechanism to calculate the importance weights of each instance to obtain the semantic representation of the node under each type of metapath;

[0065] S34: Use the attention mechanism to fuse the semantic information of different metapaths to generate the final node representation A = {A1, A2,..., A n}, where n is the number of nodes.

[0066] S4: Use the Metapath2Vec algorithm to perform random walks based on metapaths and learn the generated sequence representations to extract the structural features of the nodes.

[0067] In a vehicle network, attacks against each node have specific attack structures, such as man-in-the-middle attacks, denial-of-service attacks, etc., which rely on specific network topology positions and connection relationships. These attacks usually follow specific structural paths or utilize specific relationships between nodes to spread. Metapath2Vec can calculate the structural similarity between device nodes by learning the structural features of nodes in the graph (including different relationships defined by metapaths), enabling topological information to be better incorporated into the risk assessment task.

[0068] Specifically, step S4 uses the Metapath2Vec algorithm to perform random walks based on metapaths and learn the generated sequence representations, thereby extracting the structural features of nodes, including:

[0069] S41: Ignore the node features of the heterogeneous graph G(V, E, T, X) to obtain an attribute-free graph G(V, E, T);

[0070] S42: Use a random walk strategy based on metapath constraints to generate multiple node access sequences on the graph. During the random walk process, only allow jumps along the edges that conform to the metapath to ensure that the generated node sequences can reflect the true relationships between device nodes and other nodes, thereby retaining the topological structure information of the vehicle network;

[0071] S43: Use the generated node access sequences to perform unsupervised learning using the Skip-gram model. The goal of Skip-gram is to maximize the conditional probability of its neighbor node c given the central node v t The objective function is defined as follows:

[0072]

[0073] where, N t (v) represents the set of neighbor nodes of type t, and p(c t |v; θ) is the probability distribution obtained by softmax, which are the model training parameters. By optimizing the above objective function, the model can learn the low-dimensional vector representation of each device node, making the distance between structurally similar devices closer in the vector space, thereby capturing the structural features of device nodes and the topological features of different attack patterns;

[0074] S44: After training, the node embedding representation S generated by Metapath2Vec v is used as the structural feature of the device node, and finally the feature set of the device node is obtained: S = {S1, S2, …, S n}.

[0075] S5: Fuse the attribute features and structural features of each node to obtain the node vector of each node.

[0076] Due to the complexity of in - vehicle network structures, a single feature will not be able to accurately reflect the situation of in - vehicle networks. To more comprehensively understand the risk status of in - vehicle networks, we need to consider multiple features and analyze them comprehensively. The present invention uses a method for fusing in - vehicle network features based on in - vehicle device nodes, which fuses the semantic features and structural features of each in - vehicle device node to obtain a fused service vector for each in - vehicle device node's one - time request.

[0077] Specifically, in step S5, the attribute features and structural features of each node are fused to obtain a node vector for each node, including:

[0078] S51: Based on the extracted device node attribute features and structural features the different features of the node are concatenated to obtain an initial comprehensive representation of the node, and its dimension is:

[0079] S52: In order to further optimize the node representation, a learnable feature fusion matrix is used to perform dimensionality reduction mapping on the concatenated features to obtain the final node representation F. The calculation process is as follows:

[0080] F = Concat(A, S)W

[0081] where F = {F1, F2, …, F n} represents the feature set of the device nodes, and Concat(·) is the feature concatenation operation in step S51, which is used to fuse the attribute features and structural features of the nodes.

[0082] S6: An attention mechanism is used to fuse the vector representations of each device node, and the representation result is input into a multi - layer perceptron to output the in - vehicle network risk assessment result.

[0083] In in - vehicle networks, the security states and interactions of different device nodes are crucial for the risk assessment of the overall network. The state changes of some key nodes may have a significant impact on network security. By using the attention mechanism, the model can automatically focus on those nodes and their features that are most critical for risk assessment, thereby improving the accuracy and reliability of the assessment.

[0084] Specifically, an attention mechanism is used to fuse the vector representations of each device node, and the representation result is input into a multi - layer perceptron to output the in - vehicle network risk assessment result, including:

[0085] S61: A feature aggregation method based on the attention mechanism is used to dynamically learn the correlation between nodes. For each node v, its attention weight α is calculated v ;

[0086] S62: According to the attention scores, use global attention pooling to aggregate the hidden representations of all device nodes to obtain an overall feature representation R;

[0087] S63: Input the globally feature-represented R after the above feature aggregation into a multi-layer perceptron, and use multiple fully connected layers for non-linear transformation to output the risk assessment result of the vehicle-mounted network.

[0088] S64: Use the mean squared error as the loss function to optimize the model prediction effect, and measure the error between the predicted value and the true value y using the following formula:

[0089]

[0090] where, is the predicted value of the i-th sample, y i is the true label value, and N is the number of training samples. By minimizing the loss function, optimize the weight parameters of the MLP model so that it can accurately predict the security situation of the vehicle-mounted network.

[0091] By minimizing the loss function, optimize the weight parameters of the MLP model so that it can accurately predict the security risks of the vehicle-mounted network.

[0092] When conducting risk assessment, the evaluation result outputs a real number y ∈ [0, 1], and this value represents the degree of security risk in the vehicle-mounted network. When the output is close to 0, it means that almost no security threats are detected and no additional security measures are required; while when the output is close to 1, it means that there is a high security risk, indicating that the vehicle-mounted network may have suffered a serious attack or there are significant security hazards, and at this time, a detailed threat analysis and response mechanism needs to be further enabled.

[0093]

[0094] Among them, the attached drawings are only for illustrative purposes, showing only schematic diagrams, not physical diagrams, and should not be construed as a limitation of the present invention; for better illustration of the embodiments of the present invention, some components in the attached drawings will be omitted, enlarged or reduced, which do not represent the dimensions of actual products; for those skilled in the art, it is understandable that some well-known structures and their descriptions in the attached drawings may be omitted.

[0095] It should be noted that those of ordinary skill in the art can understand that all or part of the processes in the above method embodiments can be completed by instructing relevant software and hardware through a computer program, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above method embodiments. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory, etc.

[0096] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

[0097] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the purpose and scope of the present technical solution, and they should all be covered within the scope of the claims of the present invention.

Claims

1. A vehicle network security risk assessment method based on heterogeneous graph neural network, characterized in that, It includes the following steps: S1: Construct the device nodes, channel nodes, attack warning information and their mutual relationships in the vehicle-mounted network within a certain time window into heterogeneous graph data; S2: Use the predefined metapath templates to perform metapath-based serialization processing on the data, generating multiple metapath sequences for each node; S3: Adopt a bidirectional long short-term memory network combined with an attention mechanism to process the metapath sequences and extract node attribute features; S4: Use the Metapath2Vec algorithm to perform metapath-based random walks, learn the generated sequence representations, and thus extract the structural features of the nodes; S5: Fuse the attribute features and structural features of each node to obtain the node vector of each node; S6: Use the attention mechanism to fuse the vector representations of each device node, input the representation result into a multi-layer perceptron, and output the risk assessment result of the vehicle-mounted network.

2. The on-vehicle network security risk assessment method based on heterogeneous graph neural network according to claim 1, wherein Step S2 uses the predefined metapath templates to perform metapath-based serialization processing on the data, generating multiple metapath sequences for each node, including: S21: Define the meta-path set MP = {MP1, MP2, …, MP n}, and each meta-path MP i represents an ordered sequence of node types MP i = (t i1 → t i2 → … → t ik ), where t ij represents the type of the j-th node in the path, and the node types include devices, attacks, or channels; S22: For the heterogeneous graph G(V, E, T, X), given the starting node According to the meta-path MP i with the starting type t i1 successively expand to the terminal type t according to the predefined expansion rules ik ; S23: During the expansion process, if the current node v i is connected to node v j , that is, A[v i , v j = 1, and the type of v j meets the requirements of the next meta-path, that is, T[v j = t i+1 , then v j is used as the next expansion node, and a complete node sequence S = {v1, v2,..., v k} is constructed in sequence, where and (v i , v i+1 ) ∈ E; S24: Repeat steps S22 and S23 until all nodes generate corresponding meta-path sequences and form a final set of meta-path sequences 3. The on-vehicle network security risk assessment method based on heterogeneous graph neural network according to claim 1, wherein, Step S3 adopts a bidirectional long short-term memory network combined with an attention mechanism to process the metapath sequences and extract node attribute features, including: S31: Adopt the matrix projection method e v = W A ·x v Perform a linear transformation on the node features to unify the feature dimensions of all nodes, where W A is a parameterized projection matrix, and x v is the original feature of node v, and e v is the transformed feature vector; S32: Use the bidirectional long short-term memory network to encode all metapath sequences, capture the semantic information of the node sequences from the forward and backward directions, and model the relationships in combination with the features of the nodes to obtain the encoded representation of each metapath instance; S33: For the semantic representations of multiple path instances under the same metapath, use the attention mechanism to calculate the importance weights of each instance, and obtain the semantic representation of the node under each type of metapath; S34: The attention mechanism is adopted to fuse the semantic information of different meta-paths, and the final node representation A = {A1, A2,..., A n}, where n is the number of nodes.

4. The vehicle network security risk assessment method based on heterogeneous graph neural network according to claim 1, characterized in that, Step S4 uses the Metapath2Vec algorithm to perform metapath-based random walks, learn the generated sequence representations, and thus extract the structural features of the nodes, including: S41: Ignore the node features of the heterogeneous graph G(V, E, T, X) to obtain an attribute-free graph G(V, E, T); S42: Use a metapath-constrained random walk strategy to generate multiple node access sequences on the graph. During the random walk process, only allow jumps along the edges that conform to the metapath to ensure that the generated node sequences can reflect the real relationships between device nodes and other nodes, thereby retaining the topological structure information of the vehicle-mounted network; S43: Using the generated node access sequence, perform unsupervised learning with the Skip-gram model. The goal of Skip-gram is to maximize the conditional probability of its neighbor node c given the central node v. The objective function is defined as follows: t The conditional probability, the objective function is defined as follows: Among them, N t (v) represents the set of neighbor nodes belonging to type t, p(c t |v; θ) is the probability distribution obtained by softmax calculation, which are the model training parameters. By optimizing the above objective function, the model can learn the low-dimensional vector representation of each device node, making the distance between structurally similar devices closer in the vector space, so as to capture the structural features of device nodes and the topological features of different attack patterns; S44: After training, the node embedding representation S generated by Metapath2Vec v As the structural features of the device nodes, the feature set of the device nodes is finally obtained: S = {S1, S2, …, S n}.

5. The vehicle network security risk assessment method based on heterogeneous graph neural network according to claim 1, characterized in that Step S5 fuses the attribute features and structural features of each node to obtain the node vector of each node, including: S51: Based on the extracted device node attribute features and structural features concatenate different features of the node to obtain an initial comprehensive representation of the node, whose dimension is: S52: To further optimize the node representation, a learnable feature fusion matrix is adopted Perform dimensionality reduction mapping on the concatenated features to obtain the final node representation F. The calculation process is as follows: F = Concat(A, S)W Among them, F = {F1, F2, …, F n} represents the feature set of device nodes, and Concat(·) is the feature concatenation operation in step S51, which is used to fuse the attribute features and structural features of nodes.

6. The vehicle network security risk assessment method based on heterogeneous graph neural network according to claim 1, characterized in that, Step S6 uses the attention mechanism to fuse the vector representations of each device node, input the representation result into a multi-layer perceptron, and output the risk assessment result of the vehicle-mounted network, including: S61: Adopt a feature aggregation method based on the attention mechanism to dynamically learn the correlation between nodes. For each node v, calculate its attention weight α v ; S62: According to the attention scores, use global attention pooling to aggregate the hidden representations of all device nodes to obtain the overall feature representation R; S63: Input the globally feature-aggregated global feature representation R into a multi-layer perceptron, use multiple fully connected layers for non-linear transformation, and output the risk assessment result of the vehicle-mounted network. S64: The mean squared error is used as the loss function to optimize the model prediction effect, and the following formula is used to measure the error between the predicted value and the true value y: Among them, is the predicted value of the i-th sample, and y i is the true label value, and N is the number of training samples. By minimizing the loss function, the weight parameters of the MLP model are optimized to enable it to accurately predict the security situation of the vehicle-mounted network. By minimizing the loss function, optimize the weight parameters of the MLP model so that it can accurately predict the security risks of the vehicle-mounted network.