CAN bus network intrusion detection method and system based on hybrid deep learning

The CAN bus data is processed through the UNET-Transformer model, sliding window, and a few supersampling methods, which solves the problems of data imbalance and high computing resource consumption, and realizes efficient and accurate CAN bus intrusion detection.

CN120389904AActive Publication Date: 2025-07-29COMPUTER INNOVATION TECH RES INST OF ZHEJIANG UNIV
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510765509.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-07-29
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

The existing CAN bus intrusion detection methods have deteriorated performance when processing complex data of modern vehicles, consumed a lot of computing resources, and data imbalanced problems lead to poor detection results.

Method used

The UNET-Transformer model is used to combine sliding windows and a few supersampling methods to extract the spatial and temporal characteristics of CAN bus data, and solve the data imbalance problem through data augmentation and missing value filling to build an efficient intrusion detection system.

Benefits of technology

It significantly improves the accuracy and efficiency of intrusion detection, is suitable for real-time operation of on-board systems with resource-constrained resources, reduces the false positive rate, and improves the ability to identify complex patterns.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389904A_ABST
    Figure CN120389904A_ABST
Patent Text Reader

Abstract

The invention discloses a CAN bus network intrusion detection method and system based on hybrid deep learning. According to the method, the UNET-Transform model is constructed, the spatial features in the CAN bus data are extracted through the encoder and the decoder, and the time and sequence dynamic states in the CAN bus data sequence are captured through the attention layer, so that the comprehensive analysis of the space and time characteristics of the message frame is realized. By means of the combined modeling, the recognition capacity of complex modes is remarkably enhanced. The method also aims at the problem of data imbalance, combines a sliding window method, not only expands training samples, but also keeps the distribution characteristics of original CAN data, so that a small number of types of data can be fully utilized, and adverse effects on detection of rare attack types are avoided. Therefore, the method provided by the invention avoids the limitation of limited sequence feature processing capability of the traditional CNN, is more efficient than BiLSTM processing, and is suitable for real-time intrusion detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a CAN bus network intrusion detection method, and specifically relates to a CAN bus network intrusion detection method and system based on hybrid deep learning. Background Art

[0002] Controller Area Network (CAN) is a communication protocol widely used in modern vehicles, mainly for data transmission between electronic control units (ECUs). Due to its low cost, high reliability, and real-time performance, CAN bus has become a key communication technology for traditional and autonomous vehicles. However, the CAN bus was not designed with security in mind and lacks built-in security mechanisms such as data encryption, authentication, and access control. This makes the CAN bus vulnerable to various network attacks, and attackers can send malicious packets through the CAN bus to control critical functions such as emergency braking, acceleration, and steering of the vehicle, seriously threatening the safety of the vehicle and passengers.

[0003] In recent years, with the rapid development of vehicle electrification and intelligence, the complexity of the CAN bus network has increased significantly. The CAN bus data in modern vehicles not only includes traditional CAN ID, data length code (DLC), and data payload fields, but also introduces extended identifiers, larger data fields (such as 64-byte data in CAN FD), high-resolution timestamps, and detailed sensor information (such as GPS and accelerometers). These new data fields make the CAN bus data more complex, and traditional intrusion detection systems (IDSs) are difficult to effectively cope with network attacks in modern vehicles.

[0004] Existing CAN bus intrusion detection methods are mainly divided into the following categories: 1. Fingerprint-based methods: These methods use the unique clock offset or signal characteristics of each ECU in the CAN bus to detect attacks. For example, by analyzing the clock offset of the ECU, forged CAN messages can be detected. However, these methods have certain limitations, such as being easily affected by environmental factors (such as temperature changes) and being unable to detect new types of attacks.

[0005] 2. Parameter monitoring-based methods: These methods detect abnormal behaviors by monitoring traffic parameters (such as message frequency, data payload distribution, etc.) in the CAN bus network. For example, when the message frequency sent by a certain ECU is detected to increase abnormally, it can be judged that the ECU may be under attack. However, these methods are computationally complex and highly sensitive to parameter settings, and are prone to false alarms.

[0006] 3. Information - theory - based methods: These methods utilize concepts in information theory (such as entropy, mutual information, etc.) to analyze the characteristics of CAN - bus data and detect potential intrusion behaviors. For example, by calculating the entropy value of CAN messages, it is possible to determine whether there is abnormal traffic. However, these methods have high requirements for data quality and limited effectiveness in dealing with complex data.

[0007] 4. Machine - learning - based methods: These methods use machine - learning algorithms (such as support vector machines, random forests, etc.) to detect abnormal behaviors in the CAN bus. For example, by training a classifier, CAN messages can be classified into normal and abnormal categories. However, these methods usually rely on manually designed features and have poor performance in dealing with imbalanced datasets.

[0008] Although the above - mentioned methods can effectively detect attacks in the CAN bus in specific scenarios, they generally have the following problems: Insufficient feature extraction: Most of the existing IDS methods are based on vehicle datasets before 2020. These datasets have fewer features and cannot effectively handle the complex CAN - bus data in modern vehicles. The CAN - bus data in modern vehicles contains more fields and features, and the performance of traditional IDS methods significantly degrades when dealing with this data.

[0009] High computational resource consumption: Many existing IDS methods rely on complex feature engineering and model training, resulting in high computational resource consumption and being difficult to run in real - time in resource - constrained in - vehicle systems.

[0010] Data imbalance problem: The attack data in the CAN bus is usually much less than the normal data, resulting in an imbalanced dataset. Traditional machine - learning methods have poor performance in dealing with imbalanced datasets.

[0011] Therefore, it is necessary to propose a more effective CAN - bus network intrusion - detection method. Summary of the Invention

[0012] To address the requirements and problems in the background art, the present invention provides a CAN - bus network intrusion - detection method and system based on hybrid deep learning. By introducing the UNET - Transformer model, the present invention can simultaneously capture the spatial features (such as CAN ID and data - payload fields) and temporal features (such as the transmission order and time - dependence of messages) of CAN - bus data, thereby significantly improving the accuracy and efficiency of intrusion detection. In addition, the present invention also combines the minority oversampling method (SMOTE) and the sliding - window method to effectively solve the data - imbalance problem and further enhance the detection ability of the model.

[0013] The technical solution of the present invention is as follows: 1. A CAN bus network intrusion detection method based on hybrid deep learning Step 1: Preprocess the collected real-time CAN bus data to obtain a training dataset; the real-time CAN bus data includes injected data frames; Step 2: Build a UNET-Transformer model and train the UNET-Transformer model using the training dataset to obtain a CAN bus network intrusion detection model; Step 3: Preprocess the CAN bus data to be tested and then input it into the CAN bus network intrusion detection model, and the model outputs the intrusion detection result.

[0014] The specific content of Step 1 is as follows: First, perform data cleaning, label One-hot processing, and normalization on the collected real-time CAN bus data in sequence to obtain the normalized CAN bus data; then, use the minority oversampling method to perform data augmentation on the normalized CAN bus data to obtain the data-augmented CAN bus data, and the number of samples with different labels in the data-augmented CAN bus data is balanced; finally, fill in the missing values in the data-augmented CAN bus data to obtain a training dataset, and each training sample in the training dataset is a CAN bus message sequence composed of continuous K frames of CAN bus data.

[0015] The filling of the missing values in the data-augmented CAN bus data specifically includes: Use a sliding window to select the same feature of continuous K frames, calculate the average value of the non-missing values in the sliding window and use it as the filling feature of the missing values in the sliding window. After traversing and processing the missing values in the data-augmented CAN bus data, the filling of all missing values is completed.

[0016] In Step 2, the UNET-Transformer model includes an encoder, a decoder, a bottleneck unit, and a classifier. The input of the UNET-Transformer model is used as the input of the encoder. The encoder is connected to the decoder through the bottleneck unit, the decoder is connected to the classifier, and the output of the classifier is used as the output of the UNET-Transformer model; the encoder includes N sequentially connected convolutional units, the decoder includes N sequentially connected upsampling units, and the nth convolutional unit is also connected to the (N - n + 1)th upsampling unit, where n = 1, …, N.

[0017] The convolutional unit includes a first convolutional layer, a first batch normalization layer, a first max pooling layer, and a first dropout layer connected in sequence.

[0018] The upsampling unit includes a second convolutional layer, a second batch normalization layer, and a second dropout layer that are connected in sequence.

[0019] The bottleneck unit includes an attention layer, a normalization layer, a third batch normalization layer, and a third dropout layer. The output of the encoder is used as the input of the attention layer. After the output of the attention layer is added to its input, it is input into the normalization layer. After passing through the third batch normalization layer, the normalization layer is connected to the third dropout layer, and the output of the third dropout layer is used as the output of the bottleneck unit.

[0020] II. A CAN bus network intrusion detection system based on hybrid deep learning A preprocessing unit for preprocessing the collected real-time CAN bus data; A training dataset generation unit for batch processing CAN bus data using the preprocessing unit to generate a training dataset; A model storage unit for storing the UNET-Transformer model and training the UNET-Transformer model using the training dataset to obtain a CAN bus network intrusion detection model; An intrusion detection unit for preprocessing the CAN bus data to be measured and then inputting it into the CAN bus network intrusion detection model to obtain an intrusion detection result.

[0021] The preprocessing unit specifically includes: A data cleaning unit for cleaning the CAN bus data; A label One-hot processing unit for performing One-hot processing on the labels in the CAN bus data; A normalization unit for normalizing the CAN bus data after data cleaning; A data augmentation unit for augmenting the CAN bus data after normalization using a few oversampling methods; A missing value filling unit for filling the missing values in the CAN bus data after data augmentation.

[0022] III. A computer device The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the method for a CAN bus network intrusion detection method based on hybrid deep learning are implemented.

[0023] Compared with the existing method, the method proposed by the present invention has the following beneficial effects: 1. The present invention realizes the comprehensive analysis of the spatial and temporal characteristics of message frames by extracting spatial features (such as CAN ID and data payload fields) through an encoder and a decoder and capturing temporal and sequential dynamics through an attention layer. This joint modeling significantly enhances the ability to recognize complex patterns.

[0024] 2. The method proposed by the present invention avoids the limitation of the traditional CNN in processing sequence features, and is more efficient than BiLSTM in processing, making it suitable for real-time intrusion detection.

[0025] 3. Aiming at the problem of data imbalance, the present invention combines a sliding window and a minority oversampling method (SMOTE), which not only expands the training samples but also maintains the characteristics of the original CAN data distribution, so as to make full use of the minority class data and avoid adverse effects on detecting rare attack classes. Description of the Drawings

[0026] Figure 1 It is a flowchart of the method of the present invention.

[0027] Figure 2 It is a schematic diagram of samples of an imbalanced data set.

[0028] Figure 3 It is a schematic diagram of the network structure of the UNET-Transformer model.

[0029] Figure 4 It is a flowchart of data preprocessing. Detailed Embodiments

[0030] The present invention will be further described in detail below with reference to the drawings and specific embodiments. It should be understood that the specific embodiments described herein are only for explaining and illustrating the present invention, and are not used to limit the present invention.

[0031] As Figure 1 shown, the present invention proposes a CAN bus network intrusion detection method based on hybrid deep learning, including the following steps: Step 1: Perform data preprocessing on the collected real-time CAN bus data to obtain a training data set; the real-time CAN bus data includes injected data frames (i.e., abnormal data frames); As Figure 4 shown, Step 1 is specifically as follows: First, the CAN bus data is collected in real time through the in-vehicle OBD-II interface. Specifically, the data of two vehicle models, Tesla Model 3 (2022) and LeapMotor C10 (2024), is collected, including normal data frames and injected abnormal data frames. The abnormal data frames include various typical attack types such as Denial of Service (DoS) attacks, Spoofing attacks, and Fuzzy attacks. These attack types will seriously affect the safety of the vehicle in the actual driving environment, so strict requirements are put forward for data preprocessing.

[0032] The real-time CAN bus data contains multiple feature fields, including the CAN ID field, Data Length Code (DLC), data payload (DATA[0]-DATA[7]), and a label field (used to mark whether it is an attack frame). Among them, the CAN ID is used to identify the message source and type, the DLC represents the data length of the message, and the data payload contains specific control information. The correctness of this information is directly related to the running safety of the vehicle.

[0033] After the collected real-time CAN bus data is sequentially subjected to data cleaning, label One-hot processing, and normalization, the normalized CAN bus data is obtained.

[0034] Next, considering that the number of normal data frames is much larger than that of abnormal data frames in the actual environment and the data imbalance problem is serious, the Synthetic Minority Over-sampling Technique (SMOTE) is used to perform data augmentation on the normalized CAN bus data to obtain the data-augmented CAN bus data. The SMOTE method synthesizes new data points by analyzing the feature similarities and differences between minority-class data points, solving the problem of dataset imbalance. This method not only significantly increases the scale of training data but also ensures the authenticity of the original feature distribution of the data, thus effectively improving the model's ability to identify minority-class attack data. The sample structure of the dataset imbalance is as Figure 2 shown. Therefore, the number of samples with different labels in the data-augmented CAN bus data is balanced.

[0035] Finally, after filling in the missing values in the data-augmented CAN bus data, a training dataset is obtained. Each training sample in the training dataset is a CAN bus message sequence composed of consecutive K frames of CAN bus data.

[0036] Among them, during the data cleaning process, noise information and redundant fields that may exist in the original data, such as timestamps, index numbers, check bits, etc., are removed, and only core features such as CAN ID, DLC, and payload are retained. The purpose is to reduce the data dimension and improve the data quality, thereby making the training process of the subsequent model more efficient. When collecting data, one-hot processing is performed on the label field, that is, normal data frames are marked as 0, and abnormal data frames are marked as 1. This label processing method clearly defines the classification boundary and can effectively improve the classification accuracy of the deep learning model during the training process.

[0037] Since the numerical ranges of the various features of CAN bus data vary greatly, it may cause problems of unstable numerical calculations during the training of the model. Therefore, in the embodiments of the present invention, the MinMaxScaler method is used to uniformly normalize all features to between 0 and 1. This normalization method not only ensures the consistency of data processing but also improves the sensitivity of the model to different data features, ensuring that the model is more stable and effective.

[0038] Fill in the missing values in the CAN bus data after data augmentation, specifically including: Use a sliding window to select the same feature of consecutive K frames, calculate the average value of the non-missing values within the sliding window and use it as the filling feature for the missing values within the sliding window. After traversing and processing the missing values in the CAN bus data after data augmentation, all missing values are filled. This method effectively ensures the integrity and coherence of the training data and avoids the negative impact of data missing on the model performance.

[0039] In summary, through the above strict and detailed steps in the data preprocessing stage of the present invention, it is ensured that the data input into the deep learning network not only has high quality, rich features but also is evenly distributed, so as to improve the accuracy and real-time performance of the model.

[0040] Step 2: Construct a UNET-Transformer model and use the training data set to train the UNET-Transformer model to obtain a CAN bus network intrusion detection model; The present invention has carried out in-depth optimization design for the characteristics of complex CAN bus data features and tightly coupled space-time features, and proposed a UNET-Transformer model. The schematic diagram of the network structure of the UNET-Transformer model is as Figure 3As shown. The UNET-Transformer model includes an encoder, a decoder, a bottleneck unit, and a classifier. The input of the UNET-Transformer model serves as the input of the encoder. After passing through the bottleneck unit, the encoder is connected to the decoder, the decoder is connected to the classifier, and the output of the classifier serves as the output of the UNET-Transformer model. The encoder aims to gradually extract rich spatial feature information from the CAN bus data. The decoder is responsible for gradually reconstructing the high-level features extracted by the bottleneck unit into the spatial resolution of the original input data for final intrusion detection classification. The encoder includes N consecutively connected convolutional units, the decoder includes N consecutively connected upsampling units, and the nth convolutional unit is also connected to the (N - n + 1)th upsampling unit, where n = 1, …, N, that is, a Unet-Transformer network structure is adopted; The convolutional unit includes a first one-dimensional convolutional layer, a first batch normalization layer, a first max pooling layer, and a first dropout layer connected in sequence. The output of the first dropout layer serves as the output of each convolutional unit. Specifically, the one-dimensional convolutional layer effectively extracts fine-grained spatial local features in the CAN data by setting the number of filters and the kernel size, such as the complex interaction information between the CAN ID field, DLC field, and data payload field (DATA[0] - DATA[7]); the batch normalization layer normalizes the feature map output by the convolution, effectively alleviating the problems of gradient disappearance and gradient explosion during network training, and significantly improving the network training speed and stability; the max pooling layer is used to compress the feature dimension and highlight important local spatial features, thereby reducing the number of network parameters and the computational burden; the dropout layer randomly masks the outputs of some neurons, effectively reducing the overfitting phenomenon of the network and improving the network generalization performance.

[0041] The bottleneck unit includes an attention layer, a normalization layer, a third batch normalization layer, and a third dropout layer. The output of the encoder serves as the input to the attention layer. After the output of the attention layer is added to its input, it is then input into the normalization layer, thus implementing a residual connection. The normalization layer is connected to the third batch normalization layer and then to the third dropout layer. The output of the third dropout layer serves as the output of the bottleneck unit. The bottleneck unit adopts an attention mechanism with strong sequence feature modeling capabilities to efficiently capture the dynamic time features in the CAN message sequence. Specifically, the spatial features output by the encoder are first input into the attention mechanism layer. Through the attention mechanism, a weight analysis is performed on the temporal relationships within the sequence data, thereby automatically learning the importance distribution features in the data sequence. This attention mechanism enables the network to sensitively identify key time features when processing continuous message sequences by dynamically weighting and combining spatial features. Subsequently, these features enhanced by weighting through the attention layer continue to be input into the normalization layer for feature standardization processing, and then sequentially pass through the batch normalization layer and the dropout layer, finally outputting a rich spatio-temporal feature representation. Through the effective combination of multiple levels above, the bottleneck unit comprehensively improves the network's ability to express complex sequence relationships in CAN bus data.

[0042] The upsampling unit includes a second one-dimensional convolutional layer, a second batch normalization layer, and a second dropout layer connected in sequence. The output of the corresponding convolutional unit serves as the input to the second convolutional layer. The one-dimensional convolutional layer effectively extracts and restores the feature details in the spatial dimension. The batch normalization layer ensures the stability of the feature restoration process. The dropout layer prevents overfitting during the feature reconstruction process. The skip connection mechanism between the encoder and the decoder directly connects the spatial features extracted by each layer of the encoder to the corresponding feature reconstruction layer of the decoder. This design not only effectively prevents the loss of spatial information in the bottleneck unit but also makes the feature reconstruction more accurate, ensuring the overall performance of the network.

[0043] The Unet-Transformer network structure proposed in the present invention effectively solves the limitation problem of traditional networks when separately processing spatial and temporal features through the organic cooperation and linkage among the encoder, the bottleneck unit, and the decoder. It automatically and efficiently extracts the complex spatio-temporal feature relationships in CAN bus data without relying on manual feature engineering, eliminating the need for manual feature engineering. This not only significantly improves the network's recognition accuracy for different attack types but also remarkably enhances the model's real-time inference ability in vehicle-mounted resource-constrained environments, greatly enhancing its practical application value.

[0044] Each frame of CAN bus data includes priority (CAN ID), payload length (DLC), data payload (recorded as 8 features), and a label (1 for anomaly injection frames and 0 for normal in-vehicle frames), totaling 11 features. The encoder and decoder extract spatial features from each frame of CAN bus data, such as CAN ID, DLC, and data payload (a total of 8 bytes, 64 bits, divided into 8 features), providing the necessary context information to enable the model to distinguish normal operation from potential anomalies. The attention layer captures the time and order of message transmission within a specified window in terms of time, contributing to pattern recognition, anomaly detection, and the evaluation of message reception order, and is responsible for extracting time dependencies. This comprehensive attention to spatial and temporal dynamics allows for a more advanced data representation, improving the model's ability to accurately identify benign traffic and potential intrusions. By examining the message sequence rather than relying solely on absolute time, the model significantly reduces the false positive rate, thereby improving the reliability of intrusion detection in the automotive environment.

[0045] Step 3: Preprocess the CAN bus data to be tested (i.e., data cleaning and normalization) and then input it into the CAN bus network intrusion detection model. The model outputs a binary classification intrusion detection result, that is, to determine whether each data frame sequence is abnormal attack data or normal data. Specifically, the data to be tested is input into the model after undergoing strict preprocessing consistent with the training data. The model first extracts the spatial features of the data through the encoder. Next, the attention mechanism in the bottleneck unit dynamically evaluates and strengthens the time feature information in the data sequence. Subsequently, the decoder reconstructs and classifies the comprehensive features to ensure that each frame in the data sequence can be accurately classified as a normal or abnormal category.

[0046] To evaluate the actual performance of the model proposed in the present invention, the present invention has conducted a large number of experimental verifications on two vehicle type datasets of Tesla Model 3 (2022) and LeapMotor C10 (2024) as well as the public bus intrusion dataset. The model has shown excellent performance, and the specific performance indicators are shown in Table 1. As can be seen from the table, the method proposed in the present invention has reached an extremely high level in key indicators such as accuracy, precision, recall rate, and F1-score, showing obvious performance advantages. As can be seen from the confusion matrix, the model has extremely high recognition accuracy for DoS attacks and extremely low misjudgment rates, especially excellent performance in the performance of undetected cases. All attack scenarios have been detected, and it also maintains superior performance for the two types of forgery attacks.

[0047] In summary, through detailed data preprocessing steps, a carefully designed network model structure, and comprehensively analyzed model output results, the present invention effectively realizes the efficient identification and classification of CAN bus intrusion data, significantly improves the real-time detection ability and accuracy of automotive network security, and is particularly suitable for the high-performance requirements of real-time intrusion detection in modern complex vehicle environments.

[0048] Table 1 shows the performance metrics of the method proposed by the present invention.

[0049] The present invention also proposes a CAN bus network intrusion detection system based on hybrid deep learning, including: A preprocessing unit for preprocessing the collected real-time CAN bus data.

[0050] A training dataset generation unit for batch processing CAN bus data using the preprocessing unit to generate a training dataset.

[0051] A model storage unit for storing the UNET-Transformer model and training the UNET-Transformer model using the training dataset to obtain a CAN bus network intrusion detection model. An intrusion detection unit for preprocessing the CAN bus data to be tested and then inputting it into the CAN bus network intrusion detection model to obtain an intrusion detection result.

[0052] The preprocessing unit specifically includes: A data cleaning unit for cleaning the CAN bus data.

[0053] A label One-hot processing unit for performing One-hot processing on the labels in the CAN bus data.

[0054] A normalization unit for normalizing the CAN bus data after data cleaning.

[0055] A data augmentation unit for augmenting the normalized CAN bus data using a minority oversampling method.

[0056] A missing value filling unit for filling the missing values in the CAN bus data after data augmentation.

[0057] Finally, it should be noted that the above embodiments and descriptions are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the disclosure of the technical solutions of the present invention, and they should all be covered by the protection scope of the claims of the present invention.

Claims

1. A CAN bus network intrusion detection method based on hybrid deep learning, characterized in that, It includes the following steps: Step 1: Preprocess the collected real-time CAN bus data to obtain a training dataset; The real-time CAN bus data contains injected data frames; Step 2: Build a UNET-Transformer model and use the training dataset to train the UNET-Transformer model to obtain a CAN bus network intrusion detection model; Step 3: Preprocess the CAN bus data to be tested and then input it into the CAN bus network intrusion detection model, and the model outputs the intrusion detection result.

2. The CAN bus network intrusion detection method based on hybrid deep learning according to claim 1, characterized in that, The specific content of Step 1 is as follows: First, perform data cleaning, label One-hot processing, and normalization on the collected real-time CAN bus data in sequence to obtain the normalized CAN bus data; then, use the minority oversampling method to perform data augmentation on the normalized CAN bus data to obtain the data-augmented CAN bus data, and the number of samples with different labels in the data-augmented CAN bus data is balanced; Finally, fill in the missing values in the data-augmented CAN bus data to obtain a training dataset, and each training sample of the training dataset is a CAN bus message sequence composed of continuous K frames of CAN bus data.

3. The CAN bus network intrusion detection method based on hybrid deep learning according to claim 2, characterized in that, The filling of the missing values in the data-augmented CAN bus data specifically includes: Use a sliding window to select the same feature of continuous K frames, calculate the average value of the non-missing values in the sliding window and use it as the filling feature of the missing values in the sliding window, and complete the filling of all missing values after traversing and processing the missing values in the data-augmented CAN bus data.

4. A CAN bus network intrusion detection method based on hybrid deep learning according to claim 1, characterized in that In Step 2, the UNET-Transformer model includes an encoder, a decoder, a bottleneck unit, and a classifier. The input of the UNET-Transformer model is used as the input of the encoder. The encoder is connected to the decoder through the bottleneck unit, the decoder is connected to the classifier, and the output of the classifier is used as the output of the UNET-Transformer model; the encoder includes N sequentially connected convolutional units, the decoder includes N sequentially connected upsampling units, and the nth convolutional unit is also connected to the (N - n + 1)th upsampling unit, where n = 1, …, N.

5. The CAN bus network intrusion detection method based on hybrid deep learning according to claim 4, characterized in that, The convolutional unit includes a first convolutional layer, a first batch normalization layer, a first max pooling layer, and a first dropout layer connected in sequence.

6. A CAN bus network intrusion detection method based on hybrid deep learning according to claim 4, characterized in that, The upsampling unit includes a second convolutional layer, a second batch normalization layer, and a second dropout layer connected in sequence.

7. A CAN bus network intrusion detection method based on hybrid deep learning according to claim 4, characterized in that The bottleneck unit includes an attention layer, a normalization layer, a third batch normalization layer, and a third dropout layer. The output of the encoder is used as the input of the attention layer. The output of the attention layer and its input are added and then input into the normalization layer. The normalization layer is connected to the third batch normalization layer and then to the third dropout layer, and the output of the third dropout layer is used as the output of the bottleneck unit.

8. A CAN bus network intrusion detection system based on hybrid deep learning, characterized in that, It includes: A preprocessing unit for preprocessing the collected real-time CAN bus data; A training dataset generation unit for using the preprocessing unit to batch process the CAN bus data to generate a training dataset; A model storage unit for storing the UNET-Transformer model and training the UNET-Transformer model using a training data set to obtain a CAN bus network intrusion detection model; An intrusion detection unit for preprocessing the to-be-detected CAN bus data and then inputting it into the CAN bus network intrusion detection model to obtain an intrusion detection result.

9. The CAN bus network intrusion detection system based on hybrid deep learning according to claim 8, characterized in that, The preprocessing unit specifically includes: A data cleaning unit for cleaning the CAN bus data; A label One-hot processing unit for performing One-hot processing on the labels in the CAN bus data; A normalization unit for normalizing the CAN bus data after data cleaning; A data augmentation unit for augmenting the normalized CAN bus data using a minority oversampling method; A missing value filling unit for filling the missing values in the CAN bus data after data augmentation.

10. A computer device, characterized in that, The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the steps of the method for CAN bus network intrusion detection based on hybrid deep learning according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Data enhancement model and method suitable for power grid information attack detection

    CN116522326A

  • Vehicle-mounted CAN network intrusion detection method based on generative adversarial network

    CN118368137A

  • Method and apparatus for detecting attack in can bus

    US20220407874A1