Risk defense method and device, storage medium and terminal
By monitoring and defending against vehicle application security incidents through a secure digital big model, the risks of network attacks and data leakage in the digital environment of automobiles are resolved, and real-time security monitoring and immediate defense of vehicles are achieved.
Patent Information
- Application Number
- CN202510805395.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-09-16
Smart Images

Figure CN120658459A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of vehicle digital security, and in particular to a risk defense method, device, storage medium, and terminal. Background Art
[0002] As cars evolve toward digitalization, connectivity, intelligence, and autonomous driving, they face numerous new risks and challenges. Digital safety has become the fourth most important safety issue facing cars, following active safety, passive safety, and functional safety. In this digital and connected world, cars interact increasingly frequently with the outside world, enhancing their functionality and convenience. However, this also makes them more vulnerable to digital security risks such as cyberattacks, data leaks, and malware infections, which can impact the normal operation of cars. Summary of the Invention
[0003] The present application provides a risk defense method, device, storage medium and terminal to solve the technical problem that the above-mentioned digital security issues increase driving risks.
[0004] In a first aspect, an embodiment of the present application provides a risk prevention method, the method comprising:
[0005] determining a safety digital big model in response to a risk monitoring request for the vehicle;
[0006] Monitor multiple application security events in the vehicle through a secure digital model;
[0007] If a target security risk for a target application security incident is detected, the control security digital model will execute defense measures corresponding to the target security risk.
[0008] In a second aspect, an embodiment of the present application provides a risk prevention device, which includes:
[0009] A model determination module, configured to determine a safety digital large model in response to a risk monitoring request for a vehicle;
[0010] An event monitoring module, used to monitor multiple application security events in the vehicle through a secure digital model;
[0011] The defense execution module is used to control the security digital model to execute the defense measures corresponding to the target security risk if a target security risk for a target application security event is detected.
[0012] In a third aspect, an embodiment of the present application provides a computer storage medium, wherein the computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the steps of the above method.
[0013] In a fourth aspect, an embodiment of the present application provides a terminal comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is suitable for being loaded by the processor and executing the steps of the above method.
[0014] The beneficial effects of the technical solutions provided by some embodiments of the present application include at least:
[0015] The present application provides a risk defense method, which determines a security digital big model in response to a risk monitoring request for a vehicle; monitors multiple application security events in the vehicle through the security digital big model; if a target security risk for the target application security event is monitored, controls the security digital big model to execute defense measures corresponding to the target security risk. When the vehicle receives a risk monitoring request, the on-board system will determine and start a security digital big model for risk analysis. This model can identify and evaluate various types of security threats, facilitating the subsequent effective monitoring of various security risks; after determining the security digital big model, the model is used to monitor multiple application security events in the vehicle in real time, which can comprehensively cover various security events inside the vehicle, timely capture any abnormal behavior or potential threats, and provide all-round security protection for the vehicle; when the security digital big model monitors the occurrence of a specific application security event, it will automatically trigger the corresponding defense mechanism to achieve immediate response and automated processing of the risk, thereby improving the vehicle's digital security protection capabilities. Through the method of this application, real-time monitoring and precise defense of vehicle application security incidents are achieved, and the active defense capability and response speed of the vehicle system to digital risks are improved. It can not only effectively prevent potential security threats, but also promptly deal with existing security risks, thereby ensuring the digital security of the vehicle. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.
[0017] Figure 1 An exemplary system architecture diagram of a risk prevention method provided in an embodiment of the present application;
[0018] Figure 2 A flow chart of a risk prevention method provided in an embodiment of the present application;
[0019] Figure 3 A flow chart of a risk prevention method provided in an embodiment of the present application;
[0020] Figure 4 A schematic diagram of a vehicle-mounted screen in a risk defense method provided in an embodiment of the present application;
[0021] Figure 5 A flow chart of a risk prevention method provided in an embodiment of the present application;
[0022] Figure 6 A schematic diagram of a vehicle-mounted screen in a risk defense method provided in an embodiment of the present application;
[0023] Figure 7 A schematic diagram of a vehicle-mounted screen in a risk defense method provided in an embodiment of the present application;
[0024] Figure 8 A flowchart of a model training method for a secure digital large model provided in an embodiment of the present application;
[0025] Figure 9 A structural block diagram of a risk prevention device provided in an embodiment of the present application;
[0026] Figure 10 A schematic diagram of the structure of a terminal provided in an embodiment of the present application. DETAILED DESCRIPTION
[0027] To make the features and advantages of this application more obvious and easy to understand, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this application.
[0028] When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. Instead, they are merely examples of devices and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0029] With the rapid advancement of technology, cars increasingly rely on digital technologies to enhance their functions and services, such as navigation systems and entertainment information systems. Vehicles' ability to interact with the external environment (e.g., communication between other vehicles and between vehicles and infrastructure) continues to improve. For example, by exchanging data with map service providers and traffic management systems, vehicles can provide real-time traffic information, intelligent route planning, and voice navigation to help drivers optimize their travel routes. With connected car technology, car owners can remotely control their vehicles (e.g., lock / unlock, start the air conditioning), monitor vehicle status (e.g., battery / fuel level, location), and receive safety alerts) through mobile phone apps. These digital technology services enhance vehicle functionality and convenience.
[0030] However, as a highly connected device, cars may be more vulnerable to malicious attacks from the Internet. For example, hackers may exploit software vulnerabilities to invade the vehicle system, steal user information and data, and violate user privacy; they may even tamper with vehicle control instructions, which will cause the vehicle to lose control or the system to crash, not only affecting the normal operation of the vehicle, but also posing a threat to the safety of the driver and other road users.
[0031] Therefore, an embodiment of the present application provides a risk defense method to address the digital security risks faced by existing vehicles.
[0032] See also Figure 1 , Figure 1 An exemplary system architecture diagram of a risk defense method provided in an embodiment of the present application.
[0033] like Figure 1 As shown, the system architecture may include a terminal 101, a network 102, and a server 103. The network 102 is used to provide a medium for a communication link between the terminal 101 and the server 103. The network 102 may include various types of wired communication links or wireless communication links, for example, a wired communication link may include an optical fiber, a twisted pair, or a coaxial cable, and a wireless communication link may include a Bluetooth communication link, a Wireless-Fidelity (Wi-Fi) communication link, or a microwave communication link.
[0034] The terminal 101 can interact with the server 103 through the network 102 to receive messages from the server 103 or send messages to the server 103, or the terminal 101 can interact with the server 103 through the network 102 to receive messages or data sent to the server 103 by other users. The terminal 101 can be hardware or software. When the terminal 101 is hardware, it can be various electronic devices, including but not limited to vehicle-mounted computers, etc. When the terminal 101 is software, it can be installed in the electronic devices listed above, which can be implemented as multiple software or software modules (for example: used to provide distributed services), or it can be implemented as a single software or software module, which is not specifically limited here.
[0035] In an embodiment of the present application, the terminal 101 first responds to a risk monitoring request for the vehicle and determines a secure digital model; then the terminal 101 monitors multiple application security events in the vehicle through the secure digital model; finally, if a target security risk for a target application security event is detected, the terminal 101 controls the secure digital model to execute defense measures corresponding to the target security risk.
[0036] The server 103 may be a business server that provides various services. It should be noted that the server 103 may be hardware or software. When the server 103 is hardware, it may be implemented as a distributed server cluster consisting of multiple servers, or it may be implemented as a single server. When the server 103 is software, it may be implemented as multiple software or software modules (for example, for providing distributed services), or it may be implemented as a single software or software module, which is not specifically limited herein.
[0037] Alternatively, the system architecture may also not include the server 103. In other words, the server 103 may be an optional device in the embodiments of this specification, that is, the method provided in the embodiments of this specification may be applied to a system structure that only includes the terminal 101, and the embodiments of this application do not limit this.
[0038] It should be understood that Figure 1 The number of terminals, networks, and servers in the figure is only for illustration and any number of terminals, networks, and servers may be used according to implementation requirements.
[0039] See also Figure 2 , Figure 2 This is a flowchart of a risk defense method provided in an embodiment of the present application. The execution subject of an embodiment of the present application can be a terminal executing risk defense, a processor in a terminal executing the risk defense method, or a risk defense service in a terminal executing the risk defense method. For ease of description, the specific execution process of the risk defense method is described below using the example of a processor in a terminal as the execution subject.
[0040] like Figure 2 As shown, risk defense methods may include at least:
[0041] S202: In response to a risk monitoring request for a vehicle, determine a safety digital big model.
[0042] Optionally, in the method of an embodiment of the present application, the driver or passenger can manually activate the risk monitoring function through the vehicle's onboard screen or voice activation, or can also activate risk monitoring of the vehicle through a communication device bound to the vehicle. At the same time, the vehicle-mounted system can also be set to automatically trigger a risk monitoring request under specific circumstances, such as when binding to a new device, when detecting an abnormal data traffic pattern, or when accessing an unknown network; or the vehicle-mounted system can also set a timer task to automatically perform risk monitoring at preset time intervals.
[0043] Optionally, when the on-board system receives a risk monitoring request for the vehicle, it will initiate the process of determining the secure digital model. This includes checking the currently available secure digital model versions, evaluating their performance and applicability, and selecting the most appropriate secure digital model version for loading and initialization based on the vehicle's current status (such as network connection status, list of installed applications, etc.). To further improve the adaptability and accuracy of the secure digital model, the on-board system can dynamically adjust the parameters and risk monitoring strategies of the secure digital model based on historical security event data, vehicle usage habits, and external environmental factors (such as network environment, etc.).
[0044] S204: Monitor multiple application security events in the vehicle through the secure digital big model.
[0045] Optionally, in order to ensure that the secure digital model can fully and meticulously understand the digital security status inside the vehicle, the method of the embodiment of the present application performs multimodal analysis and processing on the applications and services of the vehicle-mounted system. Specifically, the secure digital model integrates a variety of sensors and interfaces to collect security event data of various applications and services inside the vehicle in real time. These data include but are not limited to network scanning, virus operation, account login, traffic surge, system logs, application installation, application behavior records, etc. Furthermore, the secure digital model monitors the collected multimodal data in real time to ensure that any abnormal behavior or potential risks can be discovered in a timely manner. In order to identify deep-seated risks and hidden dangers, the secure digital model introduces deep learning algorithms to conduct more in-depth mining and analysis of security event data. For example, the model can distinguish between normal application update requests and malware attacks disguised as legitimate updates.
[0046] S206: If a target security risk for a target application security event is detected, the security digital model is controlled to execute defense measures corresponding to the target security risk.
[0047] Optionally, if the Secure Digital Big Model detects a target security risk in a target application security event during monitoring, it will first automatically analyze and categorize the target security risk using the model's built-in risk classification algorithm. For example, it may distinguish between different types of security threats, such as malware attacks, unauthorized data access attempts, or system configuration errors. The model can also quantitatively assess the identified risks and determine their risk level, such as low risk, medium risk, or high risk. The Secure Digital Big Model also records detailed information such as the time of occurrence and scope of impact of the target security risk, providing a basis for subsequent risk assessment and the development of defensive measures.
[0048] Furthermore, based on the specific risk level and type identified, the Secure Digital Model matches appropriate defensive measures from a pre-defined library, dynamically generating and executing defensive instructions. These defensive measures may include, but are not limited to, isolating infected applications, blocking malicious traffic, updating firewall rules, remediating system vulnerabilities, or blocking malicious connections. For example, in the case of a high-risk virus attack, the Secure Digital Model will immediately isolate the infected application and initiate virus detection and removal. For privacy breach risks, the model may enhance relevant privacy protection settings and notify the user.
[0049] Optionally, with the emergence of new types of security risks and the development of technology, the secure digital big model has the ability to adaptively learn, and can continuously learn and optimize defense strategies based on historical defense data and real-time risk situations to ensure that it is always in the best protection state. And when facing multiple security risks, the model can also automatically adjust the priority and execution order of defense measures to improve the pertinence and effectiveness of defense. In addition, after the defense measures are executed, the secure digital big model will continue to monitor the defense effect to ensure that the risks are effectively controlled, and display the defense progress and results to the user through a dynamic visual interface, such as isolated applications, fixed vulnerabilities, enhanced privacy protection, etc. The method of the embodiment of the present application also introduces a user participation mechanism, allowing users to customize defense strategies according to their own needs and preferences, and set the defense level of specific applications, the method of receiving risk notifications, etc. through the communication device bound to the vehicle or the vehicle system interface, thereby enhancing the flexibility and personalization of risk defense.
[0050] In an embodiment of the present application, a risk defense method is provided, which determines a security digital big model in response to a risk monitoring request for a vehicle; monitors multiple application security events in the vehicle through the security digital big model; if a target security risk for a target application security event is monitored, controls the security digital big model to execute defense measures corresponding to the target security risk. When the vehicle receives a risk monitoring request, the on-board system will determine and start a security digital big model for risk analysis. This model can identify and evaluate various types of security threats, facilitating the subsequent effective monitoring of various security risks; after determining the security digital big model, the model is used to monitor multiple application security events in the vehicle in real time, which can comprehensively cover various security events inside the vehicle, timely capture any abnormal behavior or potential threats, and provide all-round security protection for the vehicle; when the security digital big model monitors the occurrence of a specific application security event, it will automatically trigger the corresponding defense mechanism to achieve immediate response and automated processing of the risk, thereby improving the digital security protection capability of the vehicle. Through the method of this application, real-time monitoring and precise defense of vehicle application security incidents are achieved, and the active defense capability and response speed of the vehicle system to digital risks are improved. It can not only effectively prevent potential security threats, but also promptly deal with existing security risks, thereby ensuring the digital security of the vehicle.
[0051] See also Figure 3 , Figure 3 A flowchart of a risk prevention method provided in an embodiment of the present application.
[0052] like Figure 3 As shown, risk defense methods may include at least:
[0053] S302: In response to a risk monitoring request for a vehicle, determine a safety digital big model.
[0054] Regarding step S302, please refer to the detailed description in step S202, which will not be repeated here.
[0055] S304: Determine at least one monitoring event type pre-selected by the user; and control the secure digital model to perform a risk scan on application security events corresponding to the monitoring event type according to a preset scanning frequency.
[0056] Optionally, during the initialization of the safety monitoring function or user configuration stage of the vehicle system, the user can select the specific monitoring event type that needs to be monitored by the safety digital model on the vehicle screen or the communication device bound to the vehicle according to their own needs. Figure 4 This is a schematic diagram of a vehicle screen in a risk defense method provided in an embodiment of the present application. When the user sets the safety monitoring function through the vehicle screen, the user can Figure 4The upper right area of the screen interface is used to select the monitoring event type.
[0057] Optionally, monitoring event types include, but are not limited to, traffic monitoring, file monitoring, sample monitoring, and application monitoring, each of which corresponds to different application security events. For example, traffic monitoring focuses on data transmission between the vehicle and the external network, including the volume, frequency, and source of uploaded and downloaded data. Corresponding application security events can include traffic surges and unauthorized data access. Application monitoring involves a comprehensive review of the behavior of in-vehicle applications, covering multiple stages such as installation, updating, and login. Corresponding application security events include application installation, account login, and password cracking.
[0058] The vehicle system optionally offers a variety of preset scanning frequency options, such as real-time, hourly, and daily, for users to choose based on vehicle usage and security requirements. After selecting a scanning frequency, the system associates it with the user-selected monitoring event type to create a personalized scanning plan. The Secure Digital Big Model then automatically scans for relevant application security events in the vehicle based on the user-defined monitoring event type and scanning frequency.
[0059] S306: If a target security risk for a target application security event is detected, defense information for the target security risk and defense measures are recorded.
[0060] Optionally, when the secure digital model detects a security risk in an application security incident and takes appropriate defensive measures, the vehicle system will automatically record relevant defense information about the incident. This information includes, but is not limited to: event timestamp, application security incident type, defense measure type (such as isolation, repair, blocking, etc.), and defense effectiveness evaluation (such as whether the attack was successfully blocked and whether the system was restored to normal state). The recorded defense information is stored in the vehicle's local storage device or cloud server to ensure data integrity and accessibility, and is encrypted when necessary to prevent unauthorized access and data leakage.
[0061] S308: When the user triggers a defense information viewing request for the vehicle, the defense information within a preset time period is displayed on the vehicle screen.
[0062] Optionally, when a user triggers a request to view defense information for the vehicle via the vehicle's screen or communication device, the vehicle system retrieves defense information from a preset period (e.g., the past week, month, etc.) from the storage device and filters and sorts it based on the user's needs. The retrieved defense information is then displayed on the vehicle's screen or communication device in a chart or other format, allowing the user to quickly understand the defense status. Furthermore, an export function for defense information is provided, allowing users to export the information to a file for further analysis and processing.
[0063] For example, Figure 4 The diagram of the in-vehicle screen shows the defense information query interface. In this interface, in addition to the types of monitoring events that have the security monitoring function currently enabled in the upper right area, the lower right area also lists the application security events for which defense measures have been taken, and records in detail the defense measures taken for each application security event and the defense effect. In the main part on the left side of the interface, a bar chart is also used to display the classification statistics of application security events that have occurred within the preset time period, such as the total number of application security events that occurred within the preset time period; the number of events is classified by application security event type or different dates, etc. At the same time, the top also summarizes the total number of events of "Resolving security risks for you in the past week" in text form, as well as the overall assessment of "Your car is safe, please drive with confidence". Defense information is recorded and displayed in an intuitive and easy-to-understand manner, allowing users to clearly understand the safety status of the vehicle.
[0064] Optionally, the in-vehicle system can intelligently analyze recorded defense information to identify frequently occurring security risk types, high-risk applications, or system components. Based on this analysis, the system can provide users with targeted security recommendations, such as software updates, enhanced access controls, and regular data backups, to help improve the overall safety of their vehicles. Furthermore, a historical defense information comparison function allows users to view defense status over different time periods, helping them identify changing risk trends and adjust security policies in a timely manner to address new security risks.
[0065] S310: Displaying a virtual image of the safety digital model on the vehicle screen, where the virtual image and the image of the cleaning robot meet a preset matching degree.
[0066] Optionally, in order to enhance the user's intuitive perception of the vehicle's safety status, the method of the embodiment of the present application further displays a virtual image of a large safety digital model on the vehicle screen to assist in displaying the operating status and safety information of the vehicle system. Figure 4The robot in the upper left corner of the in-car screen diagram is the avatar of the safety digital model. Designed to resemble a cleaning robot, this avatar is both approachable and technologically advanced. It also features dynamic performance, responding to various application security events or system status changes by embodying actions or expressions. For example, when a risk is detected, it can display alertness through changes in expression or color, emitting an alarm, or displaying a warning message. It can also celebrate after a successful security defense, enhancing user interactivity.
[0067] In an embodiment of the present application, a risk defense method is provided. By allowing the user to pre-select at least one monitoring event type and controlling the security digital large model to perform risk scanning according to a preset scanning frequency, personalized and more efficient security monitoring is achieved, and the targetedness and response speed of the vehicle system security monitoring are improved; by recording defense information for target security risks and defense measures, and displaying the defense information within a preset time period on the vehicle screen when the user triggers a viewing request, the transparency and traceability of the vehicle safety status are enhanced, which can help the user better understand the handling process and defense results of each application security event, and provide a basis for subsequent security analysis; through the dynamic display and interactive function of the virtual image of the security digital large model on the vehicle screen, the operating status and safety information of the vehicle system are intuitively displayed, which enhances the user's perception of the safety status and improves the user's interactive experience.
[0068] See also Figure 5 , Figure 5 A flowchart of a risk prevention method provided in an embodiment of the present application.
[0069] like Figure 5 As shown, risk defense methods may include at least:
[0070] S502 : In response to a Trojan application scanning operation triggered by the user, perform virus scanning on applications in the vehicle.
[0071] Optionally, in addition to allowing the secure digital model to automatically monitor the risks of the vehicle system according to preset rules, when the user suspects that certain applications have security issues or wants to maintain the system applications, the user can manually start the Trojan application scanning function through the vehicle system or communication device to perform a comprehensive virus scan on the vehicle applications.
[0072] Specifically, a comprehensive scan can be performed on all installed applications in the vehicle, including system-provided applications, third-party applications, and applications installed by users themselves; you can also choose to scan only newly installed or specific risky applications (such as applications involving user privacy information) to reduce scanning time and improve task processing efficiency. Multi-dimensional scanning technology is used to conduct in-depth scans of suspected risky applications, including file content, network communication behavior, permission usage, etc., to detect potential Trojans and viruses. For example, potential malicious code patterns can be identified through static analysis of the application's code structure, function call relationships, etc.; related applications can also be dynamically run in a simulated environment to monitor whether there is unauthorized data transmission or other suspicious behavior.
[0073] Optionally, during the scanning process, the scanning progress can be displayed in real time on the vehicle screen, including the number of scanned applications, remaining time, etc., so that the user can understand the scanning status. Figure 6 A schematic diagram of the vehicle screen in a risk defense method provided in an embodiment of the present application shows the user interface when scanning a vehicle application for viruses, in which a scan progress bar is displayed in real time to indicate the current scan progress and the percentage completed.
[0074] S504: Determine the target risk application according to the preset risk rules, and determine the risk label and risk level corresponding to the target risk application.
[0075] Optionally, a comprehensive risk rule library can be pre-established, encompassing, but not limited to, known Trojan virus signatures, malicious behavior patterns, and abnormal network communication patterns. The risk rules within this library are regularly updated to reflect the latest security threats and vulnerabilities. When performing virus scans on in-vehicle applications, the application's operating status or characteristics are compared with the various patterns in the risk rule library to identify target risk applications that may pose security risks.
[0076] Optionally, in order to facilitate users to quickly understand the risk type and severity of target risk applications, the in-vehicle system will generate a list of all target risk applications and match each application with a corresponding risk label, such as "Trojan virus", "malicious advertising", "privacy leakage risk", etc. At the same time, according to factors such as the severity of the risk, the scope of spread, and the difficulty of repair, the risks will be divided into different levels, such as "high risk", "medium risk", and "low risk".
[0077] S506 : Display the target risk application on the vehicle screen, and display the risk label corresponding to the target risk application according to the display color corresponding to the risk level.
[0078] Optionally, after the scan is complete, the vehicle system will visually display the detected risky applications, their corresponding risk labels, and risk levels on the vehicle screen using charts and color coding. Specifically, a dedicated risk overview page will be provided on the vehicle screen, showcasing all detected risky applications. Each application will display basic information such as its name, icon, and installation date, helping users quickly identify problematic applications. These risky applications will be sorted from high to low risk, and risk labels of different risk levels will be coded with different colors, allowing users to quickly understand the overall security status of the system. For example, a striking red color will be used for "high risk" risk labels to ensure that users are immediately aware of these high-risk applications; yellow will be used for "medium risk" risk labels to remind users to pay close attention to these risky applications; and green will be used for "low risk" risk labels to encourage users to regularly review these applications. Users can also click on a risk label to view more detailed risk information, including a description of the risk, the time of detection, the scope of impact, and recommended remediation measures.
[0079] For example, Figure 7 A schematic diagram of the vehicle screen in a risk defense method provided in an embodiment of the present application shows the user interface after virus scanning of vehicle applications, which lists three target risk applications with security risks, and matches relevant risk labels after each risk application. The colors are differentiated and displayed according to different risk levels, providing users with a clearer and more intuitive risk scanning result.
[0080] S508 : In response to the user's uninstallation operation on the target risk application, uninstall the target risk application from the vehicle.
[0081] Optionally, the system provides an "Uninstall" button on the risk overview screen on the in-vehicle screen. Clicking this button immediately triggers the uninstall process for the specific target risk app. To facilitate users to quickly process multiple target risk apps, the system also supports batch selection of target risk apps for uninstallation and provides a "Batch Uninstall" option to uninstall the selected apps in a preset or user-defined order.
[0082] Specifically, before the uninstall operation is triggered, the system will pop up a confirmation prompt box to inform the user of the name of the application to be uninstalled, the risk level and the consequences of the uninstallation, to ensure that the user is clear about the operation intention; during the uninstallation process, the uninstallation progress bar or percentage will be displayed on the car screen to let the user know the uninstallation status in real time; after the uninstallation is completed, the user will be informed of the uninstallation result through a pop-up window on the car screen or a voice prompt, and the residual files of the target risk application will be automatically scanned and cleaned to prevent the residual files from posing a potential threat to the vehicle system. If an abnormality occurs during the uninstallation process (such as the application cannot be uninstalled, the uninstallation is interrupted, etc.), a prompt box will pop up immediately to inform the user of the reason for the uninstallation failure, and provide the option of re-uninstalling or contacting customer service; for uninstallation failures not caused by user reasons (such as system busy, file occupied, etc.), an automatic retry mechanism can be set to automatically try to re-uninstall after a period of time to increase the uninstallation success rate. In addition, the system will also record detailed information for each uninstallation operation, including uninstallation time, application name, risk level, etc., for subsequent user inquiries or system maintenance.
[0083] In an embodiment of the present application, a risk defense method is provided, which performs virus scanning on applications in the vehicle through a Trojan application scanning operation triggered by the user, and determines target risk applications according to preset risk rules, thereby improving the management efficiency of automobile digital security; at the same time, by intuitively displaying the detected target risk applications on the vehicle screen and displaying risk labels in different colors according to the risk level, the user can quickly understand the security status of the vehicle application, promptly discover and deal with potential security threats, thereby improving the overall security of the vehicle system; further responding to the user's uninstall operation for the target risk application, the risk application is directly uninstalled from the vehicle, effectively preventing further infringement of the vehicle system by malicious software, and providing users with a safer and more reliable driving environment.
[0084] See also Figure 8 , Figure 8 A flowchart of a model training method for a secure digital large model provided in an embodiment of the present application.
[0085] like Figure 8 As shown, the model training method of the secure digital large model may at least include:
[0086] S802: Construct an initial security digital big model for risk monitoring scenarios based on the basic multimodal security big model and the preset big language model.
[0087] Optionally, because the secure digital big model needs to be able to simultaneously process security data from different sources (such as on-board sensors, network traffic, user behavior, etc.), a multimodal fusion architecture is needed to construct the initial secure digital big model. This allows the model to more comprehensively understand the vehicle's safety status and improve the accuracy of risk monitoring. Based on this, an existing, verified basic multimodal secure big model is selected as a starting point. This model has the ability to output prediction results for the predicted object based on its various different types of features. Based on this, an initial secure digital big model for risk monitoring scenarios is constructed.
[0088] Optionally, in order to enhance the model's understanding ability and response speed, a preset large language model (such as DeepSeek) is integrated into the initial secure digital large model to process and analyze tasks related to natural language through its own powerful text understanding and generation capabilities, such as parsing user commands or understanding complex log files. Based on this, the basic multimodal secure large model is fused with the preset large language model. During the fusion process, it is necessary to ensure that the interfaces between the two models are compatible and can collaborate efficiently under a unified framework, which involves adjusting the model architecture, sharing intermediate layer feature representations, etc. The parameters of the initial secure digital large model are then customized according to specific risk monitoring needs, so that it is more focused on detecting and evaluating security threats in the vehicle environment. This not only retains the advantages of each model, but also improves the overall performance of the initial secure digital large model through collaborative work.
[0089] S804: Acquire multiple sample risk data, where the multiple sample risk data are all sample data with standard risk labels.
[0090] Alternatively, when the basic multimodal security big model is directly applied in a specific scenario, the unadjusted big model is difficult to adapt to the new scenario. Based on this, after constructing the initial risk monitoring big model for the risk monitoring scenario, the initial risk monitoring big model needs to be trained in a targeted manner.
[0091] Optionally, first determine the type and quantity of sample data required based on project requirements and goals, and collect diverse sample risk data. For example, we need to cover common in-vehicle application security incidents, including but not limited to virus execution, malware samples, network attack records, and account login anomalies. This sample risk data covers different risk types and scenarios, providing sufficient and accurate training material for the model. Furthermore, data augmentation techniques such as random noise addition, feature transformation, and data synthesis can be used to expand the original sample risk data, increase the model's generalization capabilities, and reduce the risk of overfitting.
[0092] Specifically, the ways to obtain sample risk data include but are not limited to the following aspects: historical data collection, that is, screening out representative risk event cases from past vehicle system logs, security event records, user feedback and other channels, including different types of attack methods, security vulnerabilities and system responses; simulated attack generation, that is, using professional security testing tools or customized attack scripts to simulate various attack scenarios against vehicle systems, and record the system behavior, security response and final results during the attack to form simulated attack samples; public data set utilization, drawing on industry-recognized security data sets, which usually contain a large amount of network traffic data and attack samples, which can be used for model pre-training. In addition, a dynamic update mechanism for sample risk data can be established to regularly extract new samples from new attack cases, security vulnerability reports and user feedback, and update the training data set in a timely manner to ensure that the model can keep up with the latest security threat situation.
[0093] Optionally, the collected sample risk data can be annotated with standard risk labels to ensure that each sample risk data has a clear risk label and risk level. After the standard risk labeling is completed, a random sample of sample risk data can be reviewed to ensure the accuracy and consistency of the labeling. Statistical methods can also be used to assess the overall quality of the sample risk dataset, such as whether the proportion of various risks is reasonable and whether there are significant deviations from the standard risk labels. If any problems are found, the affected data can be corrected and re-annotated in a timely manner.
[0094] S806: Input multiple sample risk data into the initial safety digital model to train the initial safety digital model.
[0095] Optionally, the pre-processed sample risk data is input into the initial safety digital big model in an appropriate format, and the initial safety digital big model is controlled to automatically extract key information and perform risk assessment based on the characteristics of the input data.
[0096] S808. During the training process of the initial safety digital large model, the initial safety digital large model is controlled to output predicted risk labels for multiple sample risk data, and the parameters of the initial safety digital large model are adjusted according to the predicted risk labels and the standard risk labels of the multiple sample risk data until the initial safety digital large model converges to obtain the trained safety digital large model.
[0097] Optionally, during the training process of the initial secure digital model, the model outputs predicted risk labels based on the input sample risk data. These predicted risk labels represent the risk prediction results of the initial secure digital model for the multiple sample risk data. These predicted risk labels are then compared with the standard risk labels included with the sample risk data. The difference between the predicted risk labels and the standard risk labels represents the difference between the current state of the initial secure digital model and the expected performance.
[0098] Furthermore, a loss function is calculated based on the difference between the predicted risk label and the standard risk label, and the parameters of the initial secure digital model are adjusted based on the loss value until the initial secure digital model converges to obtain the trained secure digital model. For example, the learning rate is dynamically adjusted based on the changes in the model's loss function. When the loss function decreases slowly, the learning rate is appropriately reduced to prevent the model from falling into a local optimum; when the loss function decreases rapidly, the learning rate is appropriately increased to accelerate convergence.
[0099] Optionally, the model training process can be repeated multiple times, with each iteration utilizing all or part of the sample risk data. Based on the training results, the model architecture can be adjusted, training data can be added, and training strategies can be optimized, gradually improving the model's ability to identify vehicle system safety risks. Furthermore, distributed training techniques can be employed to distribute model training tasks across multiple computing nodes for parallel execution. This not only shortens training time but also allows for greater utilization of computing resources to process larger training datasets.
[0100] In an embodiment of the present application, a risk defense method is provided, which includes a method for training a large security digital model. By combining a basic multimodal security model with a preset large language model to construct an initial large security digital model, combined with multimodal data processing capabilities and powerful natural language understanding capabilities, not only the risk detection performance of the system is enhanced, but also the robustness and adaptability of the model are improved. Furthermore, the large model is trained using a large amount of sample risk data with standard risk labels, enabling the model to automatically learn and accurately identify various security risks in the vehicle system, effectively improving the accuracy and efficiency of risk monitoring and providing a solid guarantee for vehicle safety.
[0101] See also Figure 9 , Figure 9 This is a structural block diagram of a risk prevention device provided in an embodiment of the present application.
[0102] like Figure 9 As shown, the risk prevention device 900 includes:
[0103] A model determination module 910 is configured to determine a safety digital model in response to a risk monitoring request for a vehicle;
[0104] An event monitoring module 920 is used to monitor multiple application security events in the vehicle through a secure digital model;
[0105] The defense execution module 930 is used to control the security digital model to execute defense measures corresponding to the target security risk if a target security risk for a target application security event is detected.
[0106] In some possible embodiments, the event monitoring module 920 is further configured to determine at least one monitoring event type pre-selected by a user; and control the secure digital model to perform risk scanning on application security events corresponding to the monitoring event type according to a preset scanning frequency.
[0107] In some possible embodiments, the risk defense device 900 further includes: a defense information recording module, which is used to record defense information for target security risks and defense measures after the defense execution module 930 controls the security digital model to execute defense measures corresponding to the target security risks; the risk defense device 900 further includes: a defense information viewing module, which is used to display defense information within a preset time period on the vehicle's on-board screen when the user triggers a defense information viewing request for the vehicle.
[0108] In some possible embodiments, the risk defense device 900 also includes: a Trojan application scanning module, which is used to perform virus scanning on applications in the vehicle in response to a Trojan application scanning operation triggered by the user; determine the target risk application based on preset risk rules, and determine the risk label and risk level corresponding to the target risk application; display the target risk application on the vehicle's on-board screen, and display the risk label corresponding to the target risk application according to the display color corresponding to the risk level.
[0109] In some possible embodiments, the risk defense device 900 further includes: a Trojan application uninstallation module, configured to uninstall the target risk application from the vehicle in response to a user's uninstallation operation on the target risk application.
[0110] In some possible embodiments, the risk defense device 900 further includes: a model image display module, which is used to display a virtual image of the large safety digital model on the vehicle's onboard screen, and the virtual image and the image of the cleaning robot meet a preset matching degree.
[0111] In some possible embodiments, the risk defense device 900 also includes: a model training module, which is used to construct an initial security digital big model for risk monitoring scenarios based on a basic multimodal security big model and a preset big language model; obtain multiple sample risk data, and the multiple sample risk data are all sample data with standard risk labels; input the multiple sample risk data into the initial security digital big model to train the initial security digital big model; during the training process of the initial security digital big model, control the initial security digital big model to output predicted risk labels for the multiple sample risk data, and adjust the parameters of the initial security digital big model according to the predicted risk labels and the standard risk labels of the multiple sample risk data until the initial security digital big model converges to obtain the trained security digital big model.
[0112] In an embodiment of the present application, a risk defense device is provided, wherein a model determination module is used to determine a security digital model in response to a risk monitoring request for a vehicle; an event monitoring module is used to monitor multiple application security events in the vehicle through the security digital model; and a defense execution module is used to control the security digital model to execute defense measures corresponding to the target security risk if a target security risk for the target application security event is detected. When the vehicle receives a risk monitoring request, the model determination module of the vehicle system will determine and activate the security digital model for risk analysis. This model can identify and evaluate various types of security threats, facilitating the subsequent effective monitoring of various security risks. After determining the security digital model, the event monitoring module uses the model to monitor multiple application security events in the vehicle in real time, which can comprehensively cover various security events within the vehicle, promptly capture any abnormal behavior or potential threat, and provide comprehensive security protection for the vehicle. When the security digital model monitors the occurrence of a specific application security event, the defense execution module automatically triggers the corresponding defense mechanism to achieve immediate response and automated processing of the risk, thereby improving the vehicle's security protection capabilities. Through the device of this application, real-time monitoring and precise defense of vehicle application security incidents are achieved, and the active defense capability and response speed of the vehicle system to digital risks are improved. It can not only effectively prevent potential security threats, but also promptly deal with existing security risks, thereby ensuring the digital security of the vehicle.
[0113] An embodiment of the present application further provides a computer storage medium, which can store multiple instructions, and the instructions are suitable for being loaded by a processor and executing the steps of any method in the above embodiments.
[0114] See Figure 10 , Figure 10 This is a schematic diagram of the structure of a terminal provided in an embodiment of the present application. Figure 10As shown, the terminal 1000 may include: at least one terminal processor 1001 , at least one network interface 1004 , a user interface 1003 , a memory 1005 , and at least one communication bus 1002 .
[0115] The communication bus 1002 is used to implement the connection and communication between these components.
[0116] The user interface 1003 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 1003 may also include a standard wired interface and a wireless interface.
[0117] The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a WI-FI interface).
[0118] The terminal processor 1001 may include one or more processing cores. The terminal processor 1001 utilizes various interfaces and circuits to connect various components within the terminal 1000. It executes instructions, programs, code sets, or instruction sets stored in the memory 1005, and accesses data stored in the memory 1005 to perform various functions and process data for the terminal 1000. Optionally, the terminal processor 1001 may be implemented using at least one hardware form factor selected from the group consisting of a digital signal processing (DSP), a field-programmable gate array (FPGA), and a programmable logic array (PLA). The terminal processor 1001 may integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing the content displayed on the display screen; and the modem handles wireless communications. It is understood that the modem may not be integrated into the terminal processor 1001 and may be implemented as a separate chip.
[0119] Among them, the memory 1005 may include a random access memory (RAM) or a read-only memory (ROM). Optionally, the memory 1005 includes a non-transitory computer-readable storage medium. The memory 1005 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 1005 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory 1005 may also be optionally at least one storage device located away from the aforementioned terminal processor 1001. As Figure 10 As shown, the memory 1005 as a computer storage medium may include an operating system, a network communication module, a user interface module, and a risk defense program.
[0120] exist Figure 10 In the terminal 1000 shown, the user interface 1003 is mainly used to provide an input interface for the user and obtain the data input by the user; and the terminal processor 1001 can be used to call the risk prevention program stored in the memory 1005 and perform the following operations:
[0121] determining a safety digital big model in response to a risk monitoring request for the vehicle;
[0122] Monitor multiple application security events in the vehicle through a secure digital model;
[0123] If a target security risk for a target application security incident is detected, the control security digital model will execute defense measures corresponding to the target security risk.
[0124] In some possible embodiments, when the terminal processor 1001 monitors multiple application security events in the vehicle through a secure digital big model, it specifically performs the following steps: determining at least one monitoring event type pre-selected by the user; controlling the secure digital big model to perform risk scanning on the application security events corresponding to the monitoring event type according to a preset scanning frequency.
[0125] In some possible embodiments, after controlling the security digital model to execute defense measures corresponding to the target security risk, the terminal processor 1001 further specifically performs the following steps: recording defense information for the target security risk and defense measures; when the user triggers a defense information viewing request for the vehicle, the terminal processor 1001 further specifically performs the following steps: displaying the defense information within a preset time period on the vehicle's on-board screen.
[0126] In some possible embodiments, the terminal processor 1001 further specifically performs the following steps: in response to a Trojan application scanning operation triggered by a user, performing a virus scan on the applications in the vehicle; determining the target risk application based on preset risk rules, and determining the risk label and risk level corresponding to the target risk application; displaying the target risk application on the vehicle's on-board screen, and displaying the risk label corresponding to the target risk application based on the display color corresponding to the risk level.
[0127] In some possible embodiments, the terminal processor 1001 further specifically performs the following steps: in response to a user's uninstall operation on the target risk application, uninstall the target risk application from the vehicle.
[0128] In some possible embodiments, the terminal processor 1001 further specifically performs the following steps: displaying a virtual image of the safety digital model on the vehicle's onboard screen, where the virtual image and the image of the cleaning robot meet a preset matching degree.
[0129] In some possible embodiments, the terminal processor 1001 further specifically performs the following steps: constructing an initial security digital big model for a risk monitoring scenario based on a basic multimodal security big model and a preset big language model; obtaining multiple sample risk data, where the multiple sample risk data are all sample data with standard risk labels; inputting the multiple sample risk data into the initial security digital big model to train the initial security digital big model; during the training process of the initial security digital big model, controlling the initial security digital big model to output predicted risk labels for the multiple sample risk data, and adjusting the parameters of the initial security digital big model according to the predicted risk labels and the standard risk labels of the multiple sample risk data until the initial security digital big model converges, thereby obtaining a trained security digital big model.
[0130] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.
[0131] Modules described as separate components may or may not be physically separate, and components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of these modules may be selected to achieve the purpose of this embodiment based on actual needs.
[0132] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The above-mentioned computer program product includes one or more computer instructions. When the above-mentioned computer program instructions are loaded and executed on a computer, the above-mentioned process or function according to the embodiment of this specification is generated in whole or in part. The above-mentioned computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The above-mentioned computer instructions can be stored in a computer-readable storage medium or transmitted by the above-mentioned computer-readable storage medium. The above-mentioned computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center by wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The above-mentioned computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The above-mentioned available media can be magnetic media (for example, floppy disks, hard disks, tapes), optical media (for example, digital versatile discs (DVDs)), or semiconductor media (for example, solid state disks (SSDs)).
[0133] It should be noted that for the aforementioned method embodiments, for ease of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.
[0134] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0135] The above is a description of a risk defense method, device, storage medium, and terminal provided in this application. For those skilled in the art, based on the ideas of the embodiments of this application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on this application.
Claims
1. A risk defense method, characterized in that: Applied to a vehicle, the method comprises: determining a safety digital model in response to a risk monitoring request for the vehicle; monitoring a plurality of application security events in the vehicle through the secure digital macro model; If a target security risk for a target application security event is detected, the secure digital model is controlled to execute defense measures corresponding to the target security risk.
2. The method according to claim 1, characterized in that The monitoring of multiple application security events in the vehicle by using the secure digital model includes: determining at least one monitoring event type pre-selected by a user; The secure digital model is controlled to perform risk scanning on application security events corresponding to the monitoring event type according to a preset scanning frequency.
3. The method according to claim 1, characterized in that After controlling the secure digital model to execute the defense measures corresponding to the target security risk, the method further includes: Recording defense information against the target security risks and the defense measures; When the user triggers a defense information viewing request for the vehicle, the method further includes: The defense information is displayed on the vehicle screen for a preset time period.
4. The method according to claim 1, wherein The method further comprises: In response to a Trojan application scanning operation triggered by a user, performing a virus scan on applications in the vehicle; Determine the target risk application based on the preset risk rules, and determine the risk label and risk level corresponding to the target risk application; The target risk application is displayed on an on-board screen of the vehicle, and a risk label corresponding to the target risk application is displayed according to a display color corresponding to the risk level.
5. The method according to claim 4, characterized in that The method further comprises: In response to an uninstallation operation by the user on the target risk application, the target risk application is uninstalled from the vehicle.
6. The method according to claim 1, wherein The method further comprises: The virtual image of the safety digital model is displayed on the vehicle-mounted screen of the vehicle, and the virtual image and the image of the cleaning robot meet the preset matching degree.
7. The method according to claim 1, characterized in that The method further comprises: Build an initial security digital model for risk monitoring scenarios based on the basic multimodal security model and the preset large language model; Acquire multiple sample risk data, where the multiple sample risk data are all sample data with standard risk labels; Inputting the plurality of sample risk data into the initial secure digital model to train the initial secure digital model; During the training process of the initial security digital large model, the initial security digital large model is controlled to output predicted risk labels for the multiple sample risk data, and the parameters of the initial security digital large model are adjusted according to the predicted risk labels and the standard risk labels of the multiple sample risk data until the initial security digital large model converges, thereby obtaining a trained security digital large model.
8. A risk prevention device, characterized in that: The device comprises: a model determination module, configured to determine a safety digital large model in response to a risk monitoring request for the vehicle; an event monitoring module, configured to monitor a plurality of application security events in the vehicle through the secure digital macromodel; The defense execution module is used to control the secure digital model to execute defense measures corresponding to the target security risk if a target security risk for a target application security event is detected.
9. A computer storage medium, characterized in that The computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the steps of the method according to any one of claims 1 to 7.
10. A terminal, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method according to any one of claims 1 to 7 when executing the program.