VSOC platform and device based on adversarial neural network, and storage medium

Through the VSOC platform based on the adversarial neural network, multimodal data is collected and analyzed in real time, attack prediction and protection strategy settings are solved, and the traditional automobile security protection system is insufficiently identified by the new attack mode and improved the automobile's security protection capabilities.

CN120528628AInactive Publication Date: 2025-08-22SHANGHAI TONGSHI NETWORK INTELLIGENT TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510523616.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-08-22
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional automotive security protection systems are difficult to identify new attack modes in real time and cannot effectively deal with unknown attack threats.

Method used

A VSOC platform based on adversarial neural network is adopted to collect multimodal data through a predetermined sensing array, perform data preprocessing and feature alignment, use threat simulator to predict attacks, and set security protection strategies based on prediction results.

Benefits of technology

It realizes effective identification and defense of unknown attack patterns, and improves the car's security threat identification, detection and response capabilities during driving.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528628A_ABST
    Figure CN120528628A_ABST
Patent Text Reader

Abstract

The invention relates to a VSOC platform and device based on an adversarial neural network and a storage medium, and relates to the field of intelligent automobile safety protection, and the method comprises the steps: carrying out the preprocessing and feature alignment of multi-modal data, and obtaining standard monitoring data; inputting the standard monitoring data into a threat simulator for analysis, and outputting threat simulation data; performing attack prediction according to the threat simulation data to obtain a predicted attack mode and a predicted attack path; and according to the predicted attack mode and the predicted attack path, setting a security protection strategy to carry out automobile security protection. According to the invention, the technical problem that a traditional automobile safety protection method is difficult to identify a novel attack mode in real time and cannot effectively cope with unknown attack threats can be solved; through real-time acquisition of multi-modal data, threat simulation and attack prediction, the capability of identifying, detecting and responding to various potential security threats in the driving process of the automobile can be effectively improved, so that effective identification and defense of unknown attack modes are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of intelligent vehicle safety protection, and in particular to a VSOC platform, device and storage medium based on an adversarial neural network. Background Art

[0002] With the rapid development of smart cars and autonomous driving technology, vehicles are not only increasingly reliant on computer systems and network connectivity in terms of hardware, but their increasing number of intelligent features also presents them with increasingly complex and diverse security threats, while offering convenience and efficiency. These threats not only come from traditional physical attacks, but also from new attack vectors such as cyberattacks, remote manipulation, data tampering, and sensor spoofing. These attack vectors are often highly concealed and have diverse attack paths, leaving traditional automotive safety systems significantly deficient in the face of these new threats. Summary of the Invention

[0003] The present invention addresses the technical problem that traditional automobile safety protection methods are difficult to identify new attack patterns in real time and cannot effectively deal with unknown attack threats. It provides a VSOC platform, device and storage medium based on an adversarial neural network to solve the problem.

[0004] The technical solution of the present invention to solve the above technical problems is as follows:

[0005] In a first aspect, the present invention provides a VSOC platform based on an adversarial neural network, comprising: a data acquisition module, used to perform fixed-point acquisition during the driving process of a vehicle through a predetermined sensor array to obtain multimodal data; a data processing module, used to preprocess and align features of the multimodal data to obtain standard monitoring data; a threat simulation data acquisition module, used to input the standard monitoring data into a threat simulator for analysis and output threat simulation data, wherein the threat simulator is constructed based on an adversarial neural network; an attack prediction module, used to perform attack prediction based on the threat simulation data to obtain predicted attack features, wherein the predicted attack features include predicted attack patterns and predicted attack paths; and a vehicle safety protection module, used to set safety protection strategies based on the predicted attack patterns and predicted attack paths to perform vehicle safety protection.

[0006] Optionally, the VSOC platform based on the adversarial neural network also includes: a time alignment module, which is used to perform time synchronization alignment on the multimodal data based on the linear interpolation method to obtain the same-frequency multimodal data; a data denoising module, which is used to perform abnormal cleaning and smoothing filtering denoising on the same-frequency multimodal data to obtain standard multimodal data; a data fusion module, which is used to perform feature normalization processing and data fusion on the standard multimodal data to output the standard monitoring data.

[0007] Optionally, the VSOC platform based on the adversarial neural network also includes: a threat simulator construction module, which is used to construct a threat simulator based on the adversarial neural network, wherein the threat simulator includes a simulation generator and a threat discriminator; a sample data acquisition module, which is used to query the automobile safety protection log and collect sample monitoring data sets and sample threat data sets; a model training module, which is used to perform adversarial training on the simulation generator and threat discriminator based on the adversarial loss function using the sample monitoring data sets and sample threat data sets until the loss function converges to obtain a trained threat simulator; a threat simulation data output module, which is used to input the standard monitoring data into the threat simulator for analysis and output the threat simulation data.

[0008] Optionally, the VSOC platform based on the adversarial neural network further includes: a generation loss function construction module, which means that the adversarial loss function includes a generation loss function and a discrimination loss function, wherein the expression of the generation loss function is: Among them, L G is the logarithm of the probability that the discriminator outputs the generated data as true, representing the generator loss, z is the input noise of the generator, G(z) is the false data output by the generator, D(G(z)) is the score of the discriminator on the generated data, E represents the expected value, p z (z) is the distribution of the latent variable.

[0009] Optionally, the VSOC platform based on the adversarial neural network further includes: a discriminant loss function construction module, which means that the expression of the discriminant loss function is: Among them, L D is the discriminator loss, x is the real data sample, p data (x) is the true data distribution, D(x) is the score of the discriminator on the true data, D(G(z)) is the score of the discriminator on the generated data, E represents the expected value, p z (z) is the distribution of the latent variable.

[0010] Optionally, the VSOC platform based on the adversarial neural network also includes: a sample feature acquisition module for collecting sample threat data, sample attack patterns and sample attack paths; a data selection module for taking the sample threat data, sample attack patterns and sample attack paths as sample data sets, and dividing the sample data sets into Q equal parts, selecting them Q times with replacement to construct a first training set, iteratively selecting them Q times to obtain Q data sets; an attack prediction plug-in generation module for using the Q data sets to perform supervised training on the BP neural network until convergence, and generating an attack prediction plug-in; a predicted attack feature output module for inputting the threat simulation data into the attack prediction plug-in for attack prediction, and outputting the predicted attack features, wherein the predicted attack features include predicted attack patterns and predicted attack paths.

[0011] Optionally, the VSOC platform based on the adversarial neural network also includes: an attack prediction branch acquisition module, used to use the Q data sets to supervise the BP neural network respectively until convergence, and obtain Q attack prediction branches; an attack prediction plug-in construction module, used to integrate and construct the attack prediction plug-in according to the Q attack prediction branches, wherein the output of the attack prediction plug-in is the mode of the outputs of the Q attack prediction branches.

[0012] Optionally, the VSOC platform based on the adversarial neural network further includes: an attack risk level determination module, configured to determine the attack risk level based on the predicted attack pattern analysis; a security protection strategy output module, configured to input the attack risk level, the predicted attack pattern, and the predicted attack path into a predetermined protection solution library for matching, and output the security protection strategy;

[0013] Among them, determining the attack danger level based on the predicted attack pattern analysis includes: collecting a sample attack pattern feature set based on historical attack logs, and counting the attack danger level mean under different sample attack pattern features, setting it as the sample attack danger level, and obtaining a sample attack danger level set; using the sample attack pattern feature set and the sample attack danger level set as training data, performing supervised training on the random forest until convergence, and obtaining an attack danger identification model; inputting the predicted attack pattern into the attack danger identification model for analysis, and outputting the attack danger level.

[0014] In a second aspect, the present invention further provides an electronic device, comprising:

[0015] At least one processor; a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor so as to enable the at least one processor to execute the platform described in any one of the first aspects above.

[0016] In a third aspect, a computer-readable storage medium stores a computer program, wherein the computer program implements the platform described in any one of the first aspects when executed.

[0017] The beneficial effects of the present invention are: through a predetermined sensor array, fixed-point collection is performed during the driving process of the car to obtain multimodal data; then the multimodal data is preprocessed and feature aligned to obtain standard monitoring data; then the standard monitoring data is input into a threat simulator for analysis, and threat simulation data is output, wherein the threat simulator is constructed based on an adversarial neural network; further attack prediction is performed based on the threat simulation data to obtain predicted attack features, wherein the predicted attack features include predicted attack patterns and predicted attack paths; finally, a safety protection strategy is set according to the predicted attack patterns and predicted attack paths to perform car safety protection; that is, through real-time collection of multimodal data, threat simulation and attack prediction, the car's ability to identify, detect and respond to various potential security threats during driving can be effectively improved, thereby achieving effective identification and defense of unknown attack patterns. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 A schematic diagram of the structure of the VSOC platform based on the adversarial neural network provided by the present invention;

[0019] Figure 2 Another structural diagram of the VSOC platform based on the adversarial neural network provided by the present invention;

[0020] Figure 3 Another structural diagram of the VSOC platform based on the adversarial neural network provided by the present invention;

[0021] Figure 4 Another structural diagram of the VSOC platform based on the adversarial neural network provided by the present invention;

[0022] Figure 5 Another structural diagram of the VSOC platform based on the adversarial neural network provided by the present invention;

[0023] Figure 6 Another structural diagram of the VSOC platform based on the adversarial neural network provided by the present invention;

[0024] Figure 7 A schematic structural diagram of the electronic device provided by the present invention;

[0025] Figure 8 A schematic structural diagram of a computer-readable storage medium provided by the present invention. DETAILED DESCRIPTION

[0026] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making any creative efforts shall fall within the scope of protection of the present invention.

[0027] In the description of the present invention, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of the technical features indicated. Therefore, a feature specified as "first" or "second" may explicitly or implicitly include one or more of the specified features. In the description of the present invention, "plurality" means two or more, unless otherwise specifically defined.

[0028] In the description of the present invention, the term "for example" is used to mean "used as an example, illustration or illustration". Any embodiment of the present invention described as "for example" is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is given to enable any person skilled in the art to implement and use the present invention. In the following description, details are listed for the purpose of explanation. It should be understood that a person of ordinary skill in the art can recognize that the present invention can be implemented without using these specific details. In other examples, well-known structures and processes are not elaborated in detail to avoid obscuring the description of the present invention with unnecessary details. Therefore, the present invention is not intended to be limited to the embodiments shown, but is consistent with the widest scope consistent with the principles and features disclosed herein.

[0029] Example 1, as Figure 1 As shown, the embodiment of the present invention provides a VSOC platform based on a confrontation neural network, including:

[0030] The data acquisition module 01 is used to acquire multimodal data by performing fixed-point acquisition during the driving process of the vehicle through a predetermined sensor array.

[0031] Specifically, a predetermined sensor array is obtained. A sensor array refers to an array of sensors that are pre-arranged and coordinated based on the vehicle's functional needs and safety protection requirements. It is composed of different types of sensors and is designed to provide comprehensive data collection. Common sensors include cameras (used to capture road images to assist the vehicle in identifying obstacles, lane markings, traffic signals, etc.), radars (used to detect objects around the vehicle and provide information such as distance and speed, especially suitable for harsh environments such as rain and fog), lidars (which accurately construct three-dimensional maps of the surrounding environment through laser scanning, with high resolution and accuracy), and ultrasonic sensors (used for short-range obstacle detection, especially suitable for parking or automatic parking in low-speed driving environments). The sensor array is laid out based on the vehicle's functional needs and application scenarios. The sensor layout should take into account factors such as the vehicle's motion trajectory, changes in road conditions, and the range of environmental monitoring. Sensor layout typically covers the front, back, left, right, and top and bottom positions of the vehicle to provide comprehensive perception capabilities.

[0032] Next, a predefined sensor array is used to collect data at specific points while the vehicle is in motion. This refers to collecting data at predetermined points in time using specific sensors. Different sensors can collect data periodically or in real time, depending on their characteristics and needs. The goal of predefined data collection is to ensure data is captured at specific locations, times, and conditions, enabling more accurate analysis and decision support. Multimodal data is obtained, which refers to heterogeneous data from different sensor types. Data from each sensor has different characteristics, such as image data and lidar data.

[0033] The data processing module 02 is used to preprocess and align the features of the multimodal data to obtain standard monitoring data.

[0034] Further, if Figure 2 As shown, the data processing module 02 includes:

[0035] The time alignment module 021 is used to perform time synchronization alignment on the multimodal data based on the linear interpolation method to obtain the same-frequency multimodal data; the data denoising module 022 is used to perform abnormal cleaning and smoothing filtering denoising on the same-frequency multimodal data to obtain standard multimodal data; the data fusion module 023 is used to perform feature normalization processing and data fusion on the standard multimodal data to output the standard monitoring data.

[0036] Specifically, time synchronization is a key step in multimodal data processing. Data from different sensors usually have different sampling frequencies and timestamps. Therefore, these data need to be synchronized to ensure that they can be analyzed and processed within the same time window. First, the multimodal data is time-synchronized and aligned based on linear interpolation. Linear interpolation is a commonly used time synchronization method. It estimates the data values ​​at missing or mismatched timestamps through the linear relationship between known data points. After interpolation, the data from all sensors will be aligned at the same timestamp, forming multimodal data with the same frequency. Then, the same-frequency multimodal data is subjected to abnormality cleaning and smoothing filtering and denoising. During the multimodal data acquisition process, the data may contain outliers and noise due to sensor failure, environmental interference or noise influence. Therefore, abnormality cleaning and denoising processing are required. For example, abnormal data points can be detected and eliminated by setting a threshold or based on statistical methods (such as the 3σ rule). For the data of each sensor, the mean and standard deviation can be calculated to identify and remove data points that exceed the threshold range; smoothing filtering algorithms (such as moving average, weighted average, etc.) are used to filter and denoise the data to eliminate high-frequency noise and smooth data fluctuations; thus, standard multimodal data is obtained.

[0037] Because multimodal data comes from different sources, the dimensions and ranges of the data may vary significantly. Therefore, feature normalization is necessary to ensure that the data is analyzed at the same scale. Feature normalization and data fusion are then performed on the standard multimodal data. Normalization eliminates dimensional differences, making data from different sources comparable and facilitating subsequent processing and analysis. Data fusion combines data from multiple sensors to improve the accuracy and reliability of the information. For example, weighting can be applied to each sensor based on its reliability or importance. For example, radar data may be more reliable in rainy or snowy weather and therefore be given a higher weight. After the aforementioned time synchronization, anomaly cleaning, denoising, feature normalization, and data fusion processes, the resulting standard monitoring data is a high-quality, multimodal, unified data set. This data can serve as input for subsequent intelligent vehicle safety and protection systems, such as threat simulation, attack prediction, and anomaly detection.

[0038] The threat simulation data obtaining module 03 is used to input the standard monitoring data into a threat simulator for analysis and output threat simulation data, wherein the threat simulator is constructed based on an adversarial neural network.

[0039] Further, if Figure 3 As shown, the threat simulation data obtaining module 03 includes:

[0040] A threat simulator construction module 031 is used to construct a threat simulator based on an adversarial neural network, wherein the threat simulator includes a simulation generator and a threat discriminator; a sample data collection module 032 is used to query the automobile safety protection log and collect sample monitoring data sets and sample threat data sets; a model training module 033 is used to perform adversarial training on the simulation generator and threat discriminator based on an adversarial loss function using the sample monitoring data sets and the sample threat data sets until the loss function converges to obtain a trained threat simulator; a threat simulation data output module 034 is used to input the standard monitoring data into the threat simulator for analysis and output the threat simulation data.

[0041] Specifically, in the field of smart car security, vehicles face increasingly complex attack threats. Traditional security protection methods are often only able to identify known attack patterns and have limited detection capabilities for new or unknown attacks. Threat simulators based on generative adversarial neural networks (GANs) can help systems better predict and respond to potential attack threats by generating realistic attack simulation data. Composed of a simulation generator and a threat discriminator, the threat simulator continuously optimizes its generation and discrimination capabilities through adversarial training, improving the accuracy of attack predictions.

[0042] First, a threat simulator is constructed based on an adversarial neural network. The simulator consists of a simulation generator and a threat discriminator. The simulation generator generates simulated threat data, taking standard monitoring data as input and generating threat simulation data similar to real-world attacks. The threat discriminator determines the authenticity of the generated threat simulation data, distinguishing between real attack data and generated simulated threat data. To train the threat simulator, sample monitoring and threat datasets are collected, which serve as the training basis. Next, vehicle security logs are queried to collect sample monitoring and threat datasets. The sample monitoring data consists of real data collected from onboard sensors and communication networks, such as vehicle speed, sensor data, and environmental information. The sample threat data, generated from known attack patterns or simulated attacks, is used to train the generator to produce more realistic threat simulation data.

[0043] An adversarial loss function is obtained. This adversarial loss function is key to optimizing the performance of the generator and discriminator during training. By maximizing the fidelity of the generator's generated data and minimizing the discriminator's discriminant error, the generator gradually generates more realistic threat simulation data, while the discriminator improves its ability to discriminate attack data. Based on the adversarial loss function, the simulation generator and the threat discriminator are then trained adversarially using the sample monitoring dataset and the sample threat dataset. The collected sample monitoring dataset and the sample threat dataset are input to the generator and discriminator. The generator generates threat simulation data based on the monitoring data and potential noise. The discriminator distinguishes between the generated threat simulation data and real threat data. The discriminator determines whether each piece of data is a real sample or fake data generated by the generator. By continuously adjusting the parameters of the generator and discriminator, the authenticity of the generator's output is maximized while the discriminator's misjudgment is minimized until the loss function converges. Through continuous adversarial training, the generator can generate increasingly realistic threat simulation data, and the discriminator can accurately identify this data, thus achieving ideal training results. The result is a trained threat simulator. Finally, the standard monitoring data is input into the threat simulator for analysis, and the threat simulation data is output. This threat simulation technology based on adversarial training provides an efficient and flexible solution for intelligent vehicle safety protection systems, especially for constantly changing and complex attack patterns.

[0044] Furthermore, the threat simulation data obtaining module 03 includes:

[0045] The generation loss function construction module 0331 refers to the adversarial loss function including the generation loss function and the discrimination loss function, wherein the expression of the generation loss function is: Among them, L G is the logarithm of the probability that the discriminator outputs the generated data as true, representing the generator loss, z is the input noise of the generator, G(z) is the false data output by the generator, D(G(z)) is the score of the discriminator on the generated data, E represents the expected value, p z (z) is the distribution of the latent variable.

[0046] Specifically, the adversarial loss function includes a generation loss function and a discrimination loss function, wherein the expression of the generation loss function is: In the generative loss function, L G is the logarithm of the probability that the discriminator outputs the generated data as true, representing the generator loss, z is the input noise of the generator, G(z) is the false data output by the generator, D(G(z)) is the score of the discriminator on the generated data, E represents the expected value, p z(z) is the distribution of the latent variable. The generative loss function measures the difference between the fake data output by the generator and the real data. The goal of the generator is to generate data that is as realistic as possible, making it impossible for the discriminator to distinguish it from real data. Therefore, the generator aims to maximize the probability that the discriminator will mistakenly classify its output as real data.

[0047] Furthermore, the threat simulation data obtaining module 03 includes:

[0048] The discriminant loss function construction module 0332 refers to the expression of the discriminant loss function:

[0049] Among them, L D is the discriminator loss, x is the real data sample, p data (x) is the true data distribution, D(x) is the score of the discriminator on the true data, D(G(z)) is the score of the discriminator on the generated data, E represents the expected value, p z (z) is the distribution of the latent variable.

[0050] Specifically, the expression of the discriminant loss function is:

[0051] Among them, L D is the discriminator loss, x is the real data sample, p data (x) is the true data distribution, D(x) is the score of the discriminator on the true data, D(G(z)) is the score of the discriminator on the generated data, E represents the expected value, p z (z) is the distribution of the latent variable. The goal of the discriminant loss function is to minimize this value. That is, the discriminator hopes to correctly judge the real data as 1 and the generated data as 0. By minimizing this loss function, the discriminator can continuously improve the accuracy of distinguishing true and false data.

[0052] The attack prediction module 04 is configured to perform attack prediction based on the threat simulation data to obtain predicted attack features, wherein the predicted attack features include a predicted attack mode and a predicted attack path.

[0053] Further, if Figure 4 As shown, the attack prediction module 04 includes:

[0054] The sample feature collection module 041 is used to collect sample threat data, sample attack patterns and sample attack paths; the data selection module 042 is used to use the sample threat data, sample attack patterns and sample attack paths as a sample data set, and divide the sample data set into Q equal parts, select them Q times with replacement to construct a first training set, and iterate the selection Q times to obtain Q data sets.

[0055] Specifically, first, sample threat data (specific data that records and reflects different types of known threats, which may include network attacks, physical intrusions, signal interference, and other forms), sample attack patterns (describes the specific methods of how the attack is implemented, such as the path of network intrusion, software tampering methods, etc.) and sample attack paths (identifies the propagation path and impact level of the attack, for example, the attack propagates from the external network to the on-board network, and ultimately affects the vehicle's control system) are collected; then the sample threat data, sample attack patterns, and sample attack paths are used as sample data sets, and the sample data sets are divided into Q equal parts, and are selected Q times with replacement to construct the first training set; the same method is used to iteratively select Q times to obtain Q data sets.

[0056] The attack prediction plug-in generation module 043 is used to use the Q data sets to perform supervised training on the BP neural network until convergence, and generate an attack prediction plug-in.

[0057] Further, if Figure 5 As shown, the attack prediction plug-in generation module 043 includes:

[0058] The attack prediction branch obtaining module 0431 is used to use the Q data sets to supervise the BP neural network until convergence, thereby obtaining Q attack prediction branches; the attack prediction plug-in construction module 0432 is used to integrate and construct the attack prediction plug-in based on the Q attack prediction branches, wherein the output of the attack prediction plug-in is the mode of the outputs of the Q attack prediction branches.

[0059] Specifically, the BP neural network is a commonly used feedforward neural network trained using a backpropagation algorithm. The BP neural network primarily adjusts the neural network weights by minimizing the loss function, enabling the model to effectively learn the relationship between input data and target outputs. Each dataset (i.e., each training set) is trained using the BP neural network until the network converges (i.e., the loss function approaches a minimum value). Each training set corresponds to a trained BP neural network, forming Q attack prediction branches, each of which can predict an attack pattern or path based on the input data.

[0060] The attack prediction plug-in is then constructed based on the integration of the Q attack prediction branches, where the output of the attack prediction plug-in is the mode of the outputs of the Q attack prediction branches. By integrating the Q trained BP neural network branches, the attack prediction plug-in is constructed, which can synthesize the output results of multiple prediction branches, thereby improving the accuracy and stability of predictions.

[0061] The predicted attack feature output module 044 is configured to input the threat simulation data into the attack prediction plug-in to perform attack prediction and output the predicted attack features, wherein the predicted attack features include a predicted attack mode and a predicted attack path.

[0062] Specifically, the threat simulation data is finally input into the attack prediction plug-in for attack prediction, and the predicted attack features are output, wherein the predicted attack features include a predicted attack mode and a predicted attack path.

[0063] The automobile safety protection module 05 is used to set a safety protection strategy according to the predicted attack mode and predicted attack path to perform automobile safety protection.

[0064] Further, if Figure 6 As shown, the automobile safety protection module 05 is also used for:

[0065] An attack danger level determination module 051 is used to determine the attack danger level based on the predicted attack pattern analysis; a security protection strategy output module 052 is used to input the attack danger level, predicted attack pattern and predicted attack path into a predetermined protection solution library for matching, and output the security protection strategy; wherein, determining the attack danger level based on the predicted attack pattern analysis includes: collecting a sample attack pattern feature set based on historical attack logs, and counting the attack danger level mean under different sample attack pattern features, setting it as the sample attack danger level, and obtaining a sample attack danger level set; using the sample attack pattern feature set and the sample attack danger level set as training data, performing supervised training on the random forest until convergence, and obtaining an attack danger identification model; inputting the predicted attack pattern into the attack danger identification model for analysis, and outputting the attack danger level.

[0066] Specifically,

[0067] First, we collect a set of sample attack pattern features based on historical attack logs. Each attack pattern has specific characteristics that reflect the nature and behavior of the attack. Historical attack logs record relevant information about various attacks, such as attack type, attack source, affected system module, attack time, and attack frequency. Next, we calculate the mean attack risk level for each sample attack pattern feature. Each attack pattern has a different risk. For example, some attacks may only cause minor disruptions to the system, while others may directly threaten the vehicle control system or passenger safety. Based on the impact of the attack, attacks can be classified into multiple risk levels, such as low, medium, and high. For each sample attack pattern feature (e.g., a specific attack type), we calculate the mean of the corresponding attack risk levels across all historical logs as the sample's attack risk level. The risk level here is assessed based on actual conditions and can be manually calibrated or based on an assessment of the attack's consequences.

[0068] The sample attack pattern feature set and sample attack risk level set are then used as training data for supervised training of a random forest. Random forest is a common ensemble learning method that trains multiple decision trees and generates a final prediction result through voting or averaging. Each decision tree is trained on a random subset of the training data. This effectively reduces overfitting and improves the model's generalization ability. During training, the model learns how to predict the corresponding risk level based on the features. In each iteration, the random forest model builds a decision tree, gradually adjusting the tree structure until the model converges to a state capable of accurate classification. The training process continues until the model stops improving significantly, indicating that it has learned how to accurately infer the risk level from the input attack pattern features and has achieved the desired prediction accuracy. After training is complete, the random forest model becomes an "attack risk identification model" that can accept new attack pattern features as input and predict the risk level of the attack. Finally, the predicted attack pattern is input into the attack risk identification model for analysis, outputting the attack risk level. A training dataset is constructed by converting historical attack log data into a feature set of attack patterns and calculating the mean danger level corresponding to each attack pattern. Using random forests for supervised learning, the model learns to predict the attack danger level based on the attack pattern characteristics. Ultimately, the trained model can be used to monitor new attack patterns in real time and output their danger levels, providing intelligent decision-making support for the protection system. This approach helps the system proactively identify potential high-risk attacks and implement timely protective measures, thereby improving vehicle safety. Next, the attack danger level, predicted attack pattern, and predicted attack path are input into a predefined protection solution library for matching. Specifically, the attack danger level, predicted attack pattern, and predicted attack path are entered into the protection solution library. Based on the input attack features, the most appropriate protection strategy is matched. The protection solution library contains predefined response strategies for different scenarios. Based on a machine learning model or rule library, the appropriate strategy is automatically matched and output as the security protection strategy.

[0069] The VSOC platform based on the adversarial neural network provided by the embodiment of the present invention has at least the following technical effects:

[0070] Through a predetermined sensor array, fixed-point collection is performed during the driving process of the car to obtain multimodal data; then the multimodal data is preprocessed and feature aligned to obtain standard monitoring data; then the standard monitoring data is input into a threat simulator for analysis, and threat simulation data is output, wherein the threat simulator is constructed based on an adversarial neural network; further, attack prediction is performed based on the threat simulation data to obtain predicted attack features, wherein the predicted attack features include predicted attack patterns and predicted attack paths; finally, a security protection strategy is set according to the predicted attack patterns and predicted attack paths to perform car safety protection; that is, through real-time collection of multimodal data, threat simulation and attack prediction, the car's ability to identify, detect and respond to various potential security threats during driving can be effectively improved, thereby achieving effective identification and defense against unknown attack patterns.

[0071] For example 2, please refer to Figure 7 , Figure 7 Schematic diagram of an embodiment of an electronic device provided by an embodiment of the present invention. Figure 7 As shown, an embodiment of the present invention provides an electronic device 500, including a memory 510, a processor 520, and a first computer program 511 stored in the memory 510 and executable on the processor 520. When the processor 520 executes the first computer program 511, a VSOC platform based on an adversarial neural network as described in Example 1 is implemented.

[0072] For example three, please refer to Figure 8 , Figure 8 Schematic diagram of an embodiment of a computer-readable storage medium provided in an embodiment of the present invention. Figure 8 As shown, this embodiment provides a computer-readable storage medium 600 on which a second computer program 611 is stored. When the second computer program 611 is executed by a processor, the VSOC platform based on the adversarial neural network as described in the first embodiment is implemented.

[0073] It should be noted that, in the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.

[0074] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0075] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded computer, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0076] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0077] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.

[0078] Although preferred embodiments of the present invention have been described, additional changes and modifications to these embodiments may occur to those skilled in the art once the basic inventive concepts become known.

[0079] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the present invention and its equivalents, the present invention is also intended to include these modifications and variations.

Claims

1. The VSOC platform based on adversarial neural network is characterized by: The platform includes: The data acquisition module is used to acquire multimodal data by performing fixed-point acquisition during the driving process of the vehicle through a predetermined sensor array; A data processing module, configured to perform preprocessing and feature alignment on the multimodal data to obtain standard monitoring data; a threat simulation data acquisition module, configured to input the standard monitoring data into a threat simulator for analysis and output threat simulation data, wherein the threat simulator is constructed based on an adversarial neural network; an attack prediction module, configured to perform attack prediction based on the threat simulation data and obtain predicted attack features, wherein the predicted attack features include a predicted attack mode and a predicted attack path; The automobile safety protection module is used to set a safety protection strategy according to the predicted attack mode and predicted attack path to perform automobile safety protection.

2. The VSOC platform based on adversarial neural network according to claim 1, characterized in that: The data processing module includes: A time alignment module, configured to perform time synchronization alignment on the multimodal data based on a linear interpolation method to obtain multimodal data with the same frequency; A data denoising module is used to perform abnormal cleaning and smoothing filtering on the same-frequency multimodal data to obtain standard multimodal data; The data fusion module is used to perform feature normalization processing and data fusion on the standard multimodal data and output the standard monitoring data.

3. The VSOC platform based on adversarial neural network according to claim 1, characterized in that: The threat simulation data acquisition module includes: A threat simulator construction module, configured to construct a threat simulator based on an adversarial neural network, wherein the threat simulator includes a simulation generator and a threat discriminator; The sample data collection module is used to query the vehicle safety protection log and collect sample monitoring data sets and sample threat data sets; A model training module is used to perform adversarial training on the simulation generator and the threat discriminator using the sample monitoring data set and the sample threat data set based on the adversarial loss function until the loss function converges to obtain a trained threat simulator; The threat simulation data output module is used to input the standard monitoring data into the threat simulator for analysis and output the threat simulation data.

4. The VSOC platform based on adversarial neural network according to claim 3, characterized in that: The model training module includes: The generation loss function construction module refers to the adversarial loss function including the generation loss function and the discrimination loss function, wherein the expression of the generation loss function is: Among them, L G is the logarithm of the probability that the discriminator outputs the generated data as true, representing the generator loss, z is the input noise of the generator, G(z) is the false data output by the generator, D(G(z)) is the score of the discriminator on the generated data, E represents the expected value, p z (z) is the distribution of the latent variable.

5. The VSOC platform based on adversarial neural network according to claim 4, characterized in that: The model training module includes: The discriminant loss function construction module refers to the expression of the discriminant loss function: Among them, L D is the discriminator loss, x is the real data sample, p data (x) is the true data distribution, D(x) is the score of the discriminator on the true data, D(G(z)) is the score of the discriminator on the generated data, E represents the expected value, p z (z) is the distribution of the latent variable.

6. The VSOC platform based on adversarial neural network according to claim 1, characterized in that: The attack prediction module includes: Sample feature collection module, used to collect sample threat data, sample attack patterns, and sample attack paths; a data selection module, configured to take the sample threat data, sample attack patterns, and sample attack paths as a sample data set, divide the sample data set into Q equal parts, select the data set Q times with replacement to construct a first training set, and iterate the selection process Q times to obtain Q data sets; An attack prediction plug-in generation module, configured to perform supervised training on the BP neural network using the Q data sets until convergence, and generate an attack prediction plug-in; The predicted attack feature output module is used to input the threat simulation data into the attack prediction plug-in to perform attack prediction and output the predicted attack features, wherein the predicted attack features include predicted attack modes and predicted attack paths.

7. The VSOC platform based on adversarial neural network according to claim 6, characterized in that: The attack prediction plug-in generation module includes: An attack prediction branch obtaining module is used to supervise the BP neural network using the Q data sets until convergence, thereby obtaining Q attack prediction branches; An attack prediction plug-in construction module is used to construct the attack prediction plug-in based on the Q attack prediction branches, wherein the output of the attack prediction plug-in is the mode of the outputs of the Q attack prediction branches.

8. The VSOC platform based on adversarial neural network according to claim 1, characterized in that: The automobile safety protection module includes: an attack risk level determination module, configured to determine the attack risk level based on the predicted attack pattern analysis; A security protection strategy output module is used to input the attack risk level, predicted attack mode and predicted attack path into a predetermined protection solution library for matching and output the security protection strategy; The step of determining the attack risk level based on the predicted attack pattern analysis includes: According to historical attack logs, a sample attack pattern feature set is collected, and the mean attack risk level under different sample attack pattern features is calculated and set as the sample attack risk level to obtain the sample attack risk level set; Using the sample attack pattern feature set and the sample attack risk level set as training data, the random forest is supervised trained until convergence, thereby obtaining an attack risk identification model; The predicted attack pattern is input into the attack risk identification model for analysis, and the attack risk level is output.

9. An electronic device, characterized in that: include: Memory for storing computer software programs; A processor, configured to read and execute the computer software program, thereby implementing the VSOC platform based on the adversarial neural network as described in any one of claims 1 to 8.

10. A non-transitory computer-readable storage medium, characterized in that The storage medium stores a computer software program, which, when executed by a processor, implements the VSOC platform based on the adversarial neural network as described in any one of claims 1 to 8.