A network attack defense method and device for an autonomous driving system

By introducing random defense strategies and asymptotic normality analysis in the autonomous driving system, the problem that traditional protection methods are difficult to cope with complex network attacks is solved, the stability and robustness of the system are improved, and a more adaptable and reliable security protection mechanism is built.

CN120434645BActive Publication Date: 2025-08-29NANJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510927060.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-07
Publication Date
2025-08-29
Estimated Expiration
2045-07-07

AI Technical Summary

Technical Problem

Traditional autonomous driving system security protection methods are difficult to effectively deal with increasingly complex and diverse cyber attacks, resulting in unsatisfactory security and robustness.

Method used

The random defense strategy is adopted to design the optimal defense strategy by establishing a network attack model and asymptotic normality analysis, and deploying it between the sensor and the Internet of Vehicles to enhance the stability and robustness of the system.

Benefits of technology

Effectively reduce the security risks brought by cyber attacks, enhance the stability and robustness of autonomous driving systems in complex attack environments, and build a more adaptable and reliable security protection mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120434645B_ABST
    Figure CN120434645B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and device for defending an autonomous driving system against cyberattacks. This method relates to the field of autonomous driving technology. In an autonomous driving system, sensors acquire sensor data and transmit it to a decision-making system via a connected vehicle network. The method for defending against cyberattacks occurring at the connected vehicle network includes: establishing a cyberattack model and partitioning the sensor data based on model parameters of the cyberattack model and system parameters of the autonomous driving system; designing a randomized defense strategy and performing defensive operations on the partitioned sensor data based on the defense strategy; estimating system parameters based on the sensor data after the defense operation, performing asymptotic normality analysis on the estimated errors of the system parameters, and solving for the strategy parameters of the defense strategy; and deploying the solved defense strategy between the sensors and the connected vehicle network to implement cyberattack defense. This invention can enhance the stability and robustness of autonomous driving systems in complex attack environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of autonomous driving technology, and in particular to a method and device for defending against network attacks on an autonomous driving system. Background Art

[0002] With the continuous advancement of autonomous driving technology, autonomous driving systems are becoming an integral part of intelligent transportation. Compared to traditional driving methods, autonomous driving systems enable more precise perception, judgment, and decision-making, resulting in higher safety and efficiency. However, with the development of technology, autonomous driving systems face increasingly complex security threats, particularly the risk of cyberattacks. Autonomous driving systems not only require efficient environmental perception and path planning capabilities, but also need to mitigate potential external attacks such as data tampering, malicious signal interference, and remote control of control systems.

[0003] Traditional approaches to protecting autonomous driving systems typically rely on encryption, authentication mechanisms, and rule-based defense strategies. However, these approaches often focus on fixed threat models and defense strategies, making them inadequate for rapidly evolving attack vectors. As cyberattacks become increasingly complex and diverse, the limitations of traditional defenses are becoming increasingly apparent, posing serious challenges to the security of autonomous driving systems. Summary of the Invention

[0004] The purpose of the present invention is to overcome the deficiencies in the prior art and provide a network attack defense method and device for an autonomous driving system, so as to solve the technical problem that traditional protection methods are difficult to effectively deal with increasingly complex and diverse network attacks, resulting in unsatisfactory security and robustness of autonomous driving systems.

[0005] To achieve the above object, the present invention is implemented by adopting the following technical solutions:

[0006] In a first aspect, the present invention provides a method for defending against cyberattacks on an autonomous driving system, wherein sensors in the autonomous driving system acquire sensor data and transmit the data to a decision-making system via an Internet of Vehicles. The method for defending against cyberattacks occurring in the Internet of Vehicles includes:

[0007] Establishing a network attack model, and dividing the sensor data based on model parameters of the network attack model and system parameters of the autonomous driving system;

[0008] designing a randomized defense strategy, and performing a defense operation on the divided sensor data based on the defense strategy;

[0009] estimating system parameters based on the sensor data after the defense operation, performing asymptotic normality analysis on the estimation errors of the system parameters, and solving the strategy parameters of the defense strategy;

[0010] The solved defense strategy is deployed between sensors and the Internet of Vehicles to achieve network attack defense.

[0011] Optionally, the network attack model is:

[0012]

[0013] Where, is the probability of a random event occurring, Sensor data transmitted to the Internet of Vehicles, Sensor data received from the Internet of Vehicles for the decision-making system; are model parameters.

[0014] Optionally, dividing the sensor data based on the network attack model includes:

[0015] Set up two random variables that follow a Poisson distribution Divide the index values ​​of the sensor data into sets ;

[0016] gather The first period subset in for:

[0017]

[0018]

[0019]

[0020] The index values ​​of all sensor data are divided periodically, where the set Used to estimate model parameters ,gather To estimate system parameters , , is a constant term.

[0021] Optionally, performing a defense operation on the divided sensor data based on the defense strategy includes:

[0022]

[0023] Where, For the The sensor data before and after the defense operation corresponding to the index value.

[0024] Optionally, estimating system parameters based on sensor data after the defense operation includes:

[0025]

[0026]

[0027]

[0028]

[0029]

[0030] Where, Set The number of elements in , is the model parameter The estimated value of For collection The average characteristics of the sensor data, is the maximum value of the index value of the sensor data, For collection The state value of the sensor data, System parameters The estimated value of is a circulant matrix The inverse matrix of is the system output threshold, is the Gaussian distribution function.

[0031] Optionally, performing asymptotic normality analysis on the estimation error of the system parameter includes:

[0032]

[0033] Where, To converge on the distribution, is the normalized form of the system parameter estimation error, The asymptotic covariance matrix is The asymptotically normal distribution of

[0034]

[0035] Where, are the diagonal elements of the asymptotic covariance matrix;

[0036]

[0037]

[0038]

[0039]

[0040]

[0041] Where, is the probability density function, Set The corresponding feature weights and system characteristic values, All are intermediate variables;

[0042] is the asymptotic covariance matrix No. Rank The element value of the column;

[0043]

[0044] Where, is the standardized coefficient, For collection Corresponding system characteristic values;

[0045] For the time When it approaches infinity, the proportional coefficient corresponding to the defense strategy modification data is:

[0046]

[0047] Where, It is the policy parameter of the defense policy.

[0048] Optionally, the strategy parameters for solving the defense strategy include:

[0049] With strategy parameters For variables, with asymptotic covariance matrix The goal is to minimize the trace of , and construct a constrained objective function:

[0050]

[0051] Where, is the trace of the matrix;

[0052] The objective function is optimized and solved by the optimization algorithm to obtain the optimal strategy parameters for:

[0053]

[0054]

[0055]

[0056]

[0057] Where, The circulant matrices are Middle Row and Row No. Column element values, circulant matrix .

[0058] In a second aspect, the present invention provides a network attack defense device for an autonomous driving system, wherein a sensor in the autonomous driving system acquires sensor data and transmits the data to a decision-making system via an Internet of Vehicles. The network attack defense device comprises:

[0059] a data partitioning module configured to establish a network attack model and partition the sensor data based on model parameters of the network attack model and system parameters of the autonomous driving system;

[0060] a defense operation module configured to design a random defense strategy and perform a defense operation on the divided sensor data based on the defense strategy;

[0061] a strategy solving module configured to estimate system parameters based on the sensor data after the defense operation, perform asymptotic normality analysis on the estimation errors of the system parameters, and solve the strategy parameters of the defense strategy;

[0062] The defense application module is configured to deploy the solved defense strategy between the sensor and the Internet of Vehicles to implement network attack defense.

[0063] In a third aspect, the present invention provides an electronic device, including a processor and a storage medium;

[0064] The storage medium is used to store instructions;

[0065] The processor is configured to operate according to the instructions to execute the steps of the above method.

[0066] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the above method when executed by a processor.

[0067] Compared with the prior art, the present invention has the following beneficial effects:

[0068] The present invention provides a network attack defense method for an autonomous driving system. Starting from the defender's perspective, random variables are used to introduce a defense strategy. By analyzing the asymptotic normality of the defense strategy, an optimal defense strategy optimization model is established, and ultimately the optimal defense strategy is obtained. This method can effectively reduce the security risks brought by network attacks and enhance the stability and robustness of the autonomous driving system in complex attack environments, thereby constructing a more adaptable and reliable autonomous driving system security protection mechanism. BRIEF DESCRIPTION OF THE DRAWINGS

[0069] Figure 1 This is a schematic diagram of a network attack on an autonomous driving system provided by an embodiment of the present invention;

[0070] Figure 2 The figure is a flow chart of a network attack defense method provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0071] The present invention will be further described below in conjunction with the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention and are not intended to limit the scope of protection of the present invention.

[0072] Example 1:

[0073] The embodiment of the present invention provides a network attack defense method for an autonomous driving system, such as Figure 1 As shown, is the system input, is the system noise, is the real output of the system. The target of network attack is the output of the sensor. .

[0074] like Figure 2 As shown, the defense method for network attacks occurring in the Internet of Vehicles includes the following steps:

[0075] Step S1: Establish a network attack model and divide the sensor data based on the model parameters of the network attack model and the system parameters of the autonomous driving system.

[0076] (1) The network attack model is:

[0077]

[0078] Where, is the probability of a random event occurring, Sensor data transmitted to the Internet of Vehicles, Sensor data received from the Internet of Vehicles for the decision-making system; is the model parameter, that is, the tampering probability.

[0079] (2) Classification of sensor data based on network attack models includes:

[0080] Set up two random variables that follow a Poisson distribution Divide the index values ​​of the sensor data into sets ;

[0081] gather The first period subset in for:

[0082]

[0083]

[0084]

[0085] The index values ​​of all sensor data are divided periodically, where the set Used to estimate model parameters ,gather To estimate system parameters , , is a constant term.

[0086] Through random variables Control Set The size of the defense is to prevent attackers from predicting the defense pattern.

[0087] Step S2: design a random defense strategy, and perform defense operations on the divided sensor data based on the defense strategy.

[0088] Through random distribution, attackers cannot predict the defense patterns. Defense operations based on defense strategies on the divided sensor data include:

[0089]

[0090] Where, For the The sensor data before and after the defense operation corresponding to the index value.

[0091] Step S3: Estimate system parameters based on the sensor data after the defense operation, perform asymptotic normality analysis on the estimation error of the system parameters, and solve the strategy parameters of the defense strategy.

[0092] (1) Estimation of system parameters based on sensor data after defense operations includes:

[0093]

[0094]

[0095]

[0096]

[0097]

[0098] Where, Set The number of elements in , is the model parameter The estimated value of For collection The average characteristics of the sensor data, is the maximum value of the index value of the sensor data, For collection The state value of the sensor data, System parameters The estimated value of is a circulant matrix The inverse matrix of is the system output threshold, is the Gaussian distribution function.

[0099] (2) Asymptotic normality analysis of the estimation error of system parameters includes:

[0100]

[0101] Where, To converge on the distribution, is the normalized form of the system parameter estimation error, The asymptotic covariance matrix is The asymptotically normal distribution of

[0102]

[0103] Where, are the diagonal elements of the asymptotic covariance matrix;

[0104]

[0105]

[0106]

[0107]

[0108]

[0109] Where, is the probability density function, Set The corresponding feature weights and system characteristic values, All are intermediate variables;

[0110] is the asymptotic covariance matrix No. Rank The element values ​​of the column reflect the coupling effect of parameter estimation;

[0111]

[0112] Where, is the standardized coefficient, For collection Corresponding system characteristic values;

[0113] For the time When it approaches infinity, the proportional coefficient corresponding to the defense strategy modification data is:

[0114]

[0115] Where, It is the policy parameter of the defense policy.

[0116] (3) The strategic parameters for solving the defense strategy include:

[0117] According to the asymptotic covariance matrix It can be seen that the strategy parameters The size of determines the asymptotic variance of the algorithm error. In order to make the algorithm converge faster, a reasonable design is required. , to implement optimal defense.

[0118] With strategy parameters For variables, with asymptotic covariance matrix The goal is to minimize the trace of , and construct a constrained objective function:

[0119]

[0120] Where, is the trace of the matrix;

[0121] Optimize the objective function through the optimization algorithm to obtain the optimal strategy parameters for:

[0122]

[0123]

[0124]

[0125]

[0126] Where, The circulant matrices are Middle Row and Row No. Column element values, circulant matrix .

[0127] Step S4: Deploy the solved defense strategy between the sensor and the Internet of Vehicles to implement network attack defense.

[0128] A stochastic defense strategy is an optimization method that improves system security by introducing random variables. Specifically, this method accurately models the dynamic characteristics of autonomous driving systems based on system identification techniques. Incorporating the characteristics of cyber attacks, it constructs a probabilistic cyberattack model for autonomous driving systems. From the defender's perspective, a stochastic defense strategy is designed by introducing random variables, and a consensus algorithm is proposed to counter potential attacks. Furthermore, through in-depth analysis of the asymptotic normality of the defense algorithm, an optimal defense strategy optimization model is established. The optimal defense strategy is derived by minimizing the trace of the asymptotic normal matrix.

[0129] The embodiments of the present invention, by adopting a random defense strategy, can effectively reduce the security risks brought by network attacks, enhance the stability and robustness of the autonomous driving system in complex attack environments, and thus build a more adaptable and reliable autonomous driving system security protection mechanism.

[0130] Example 2:

[0131] An embodiment of the present invention provides a network attack defense device for an autonomous driving system. In the autonomous driving system, sensors acquire sensor data and transmit it to a decision-making system via an Internet of Vehicles. The defense device for network attacks occurring in the Internet of Vehicles includes:

[0132] a data partitioning module configured to establish a network attack model and partition the sensor data based on model parameters of the network attack model and system parameters of the autonomous driving system;

[0133] a defense operation module configured to design a random defense strategy and perform a defense operation on the divided sensor data based on the defense strategy;

[0134] a strategy solving module configured to estimate system parameters based on the sensor data after the defense operation, perform asymptotic normality analysis on the estimation errors of the system parameters, and solve the strategy parameters of the defense strategy;

[0135] The defense application module is configured to deploy the solved defense strategy between the sensor and the Internet of Vehicles to realize network attack defense.

[0136] Example 3:

[0137] An embodiment of the present invention provides an electronic device, including a processor and a storage medium;

[0138] The storage medium is used to store instructions;

[0139] The processor is configured to operate according to the instructions to execute the steps of the above method.

[0140] Example 4:

[0141] An embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the above method when executed by a processor.

[0142] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0143] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0144] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0145] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0146] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A network attack defense method for an autonomous driving system, characterized in that: In the autonomous driving system, sensors acquire sensor data and transmit it to the decision-making system through the Internet of Vehicles. Methods for defending against network attacks occurring in the Internet of Vehicles include: Establishing a network attack model, and dividing the sensor data based on model parameters of the network attack model and system parameters of the autonomous driving system; designing a randomized defense strategy, and performing a defense operation on the divided sensor data based on the defense strategy; estimating system parameters based on the sensor data after the defense operation, performing asymptotic normality analysis on the estimation errors of the system parameters, and solving the strategy parameters of the defense strategy; Deploy the solved defense strategy between sensors and the Internet of Vehicles to achieve network attack defense; Wherein, the network attack model is: ; Where, is the probability of a random event occurring, Sensor data transmitted to the Internet of Vehicles, Sensor data received from the Internet of Vehicles for the decision-making system; are model parameters; The dividing of the sensor data based on the network attack model includes: Set up two random variables that follow a Poisson distribution Divide the index values ​​of the sensor data into sets ; gather The first period subset in for: ; ; ; The index values ​​of all sensor data are divided periodically, where the set Used to estimate model parameters ,gather To estimate system parameters , , is a constant term.

2. The network attack defense method for an autonomous driving system according to claim 1, characterized in that: The performing of a defense operation on the divided sensor data based on the defense strategy includes: ; Where, For the The sensor data before and after the defense operation corresponding to the index value, That is, the sensor data transmitted by the Internet of Vehicles.

3. The network attack defense method for an autonomous driving system according to claim 2, characterized in that: The estimating of system parameters according to the sensor data after the defense operation includes: ; ; ; ; ; Where, Set The number of elements in , is the model parameter The estimated value of For collection The average characteristics of the sensor data, is the maximum value of the index value of the sensor data, For collection The state value of the sensor data, System parameters The estimated value of is a circulant matrix The inverse matrix of is the system output threshold, is the Gaussian distribution function.

4. The network attack defense method for an autonomous driving system according to claim 3, characterized in that: The performing asymptotic normality analysis on the estimation error of the system parameter comprises: ; Where, To converge on the distribution, is the normalized form of the system parameter estimation error, The asymptotic covariance matrix is The asymptotically normal distribution of ; Where, are the diagonal elements of the asymptotic covariance matrix; ; ; ; ; ; Where, is the probability density function, Set The corresponding feature weights and system characteristic values, All are intermediate variables; is the asymptotic covariance matrix No. Rank The element value of the column; ; Where, is the standardized coefficient, For collection Corresponding system characteristic values; For the time When it approaches infinity, the proportional coefficient corresponding to the defense strategy modification data is: ; Where, It is the policy parameter of the defense policy.

5. The network attack defense method for an autonomous driving system according to claim 4, characterized in that: The strategy parameters for solving the defense strategy include: With strategy parameters For variables, with asymptotic covariance matrix The goal is to minimize the trace of , and construct a constrained objective function: ; Where, is the trace of the matrix; The objective function is optimized and solved by the optimization algorithm to obtain the optimal strategy parameters for: ; ; ; ; Where, The circulant matrices are Middle Row and Row No. Column element values, circulant matrix .

6. A network attack defense device for an autonomous driving system, characterized in that: In the autonomous driving system, sensors acquire sensor data and transmit it to the decision-making system through the Internet of Vehicles. The defense device for network attacks occurring in the Internet of Vehicles includes: a data partitioning module configured to establish a network attack model and partition the sensor data based on model parameters of the network attack model and system parameters of the autonomous driving system; a defense operation module configured to design a random defense strategy and perform a defense operation on the divided sensor data based on the defense strategy; a strategy solving module configured to estimate system parameters based on the sensor data after the defense operation, perform asymptotic normality analysis on the estimation errors of the system parameters, and solve the strategy parameters of the defense strategy; A defense application module is configured to deploy the solved defense strategy between the sensor and the Internet of Vehicles to implement network attack defense; Wherein, the network attack model is: ; Where, is the probability of a random event occurring, Sensor data transmitted to the Internet of Vehicles, Sensor data received from the Internet of Vehicles for the decision-making system; are model parameters; The dividing of the sensor data based on the network attack model includes: Set up two random variables that follow a Poisson distribution Divide the index values ​​of the sensor data into sets ; gather The first period subset in for: ; ; ; The index values ​​of all sensor data are divided periodically, where the set Used to estimate model parameters ,gather To estimate system parameters , , is a constant term.

7. An electronic device, characterized in that: including processors and storage media; The storage medium is used to store instructions; The processor is configured to operate according to the instructions to execute the steps of the method according to any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • A method for estimating vehicle networking actuator attacks and sensor attacks

    CN109241736A

  • Black box aggressive defense system and method based on neural network interlayer regularization

    CN112464230A