Internet of vehicles malicious node detection method based on multilevel reputation evaluation model
Through the multi-level reputation evaluation model and dynamic entropy weight fusion algorithm, the computational overhead and adaptability problems of traditional Internet of Vehicles malicious vehicle detection in dynamic communication scenarios are solved, and the accurate identification of malicious vehicles and the improvement of system robustness are achieved.
Patent Information
- Application Number
- CN202510922204.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-04
- Publication Date
- 2025-09-30
AI Technical Summary
Traditional methods for detecting malicious vehicles and behaviors in the Internet of Vehicles have high computational overhead, poor real-time performance, and are difficult to adapt to complex dynamic attacks in dynamic communication scenarios. Existing reputation management mechanisms lack adaptability and robustness in the face of diverse and dynamic attacks, making it difficult to effectively identify new variant attacks.
Based on a multi-level reputation evaluation model, the multi-dimensional trust indicators of vehicles are probabilistically normalized, a dynamic entropy weight fusion algorithm is introduced, and a reputation collaborative evaluation algorithm based on the behavioral correlation between vehicles is established to achieve group consensus decision-making and accurate identification of malicious vehicles, including rapid initial screening, direct reputation value update, indirect reputation value update and comprehensive reputation value update.
It improves the accuracy of malicious vehicle detection and the security of the system, effectively suppresses false identity disguise and reputation manipulation attacks in Sybil attacks, improves the robustness and adaptability of the system, and can dynamically respond to changes in the network environment.
Smart Images

Figure CN120729591A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of vehicle networking security technology, and in particular to a vehicle networking malicious node detection method based on a multi-level reputation evaluation model. Background Art
[0002] The Internet of Vehicles (IoV), as the core vehicle of intelligent transportation systems, builds a collaborative vehicle-road-cloud network through wireless vehicular communication technology, supporting real-time data exchange between vehicles and road infrastructure, other vehicles, and cloud services. This data-driven intelligent traffic control model plays a key role in scenarios such as dynamic route planning, autonomous driving decision-making, and traffic flow optimization, significantly improving the resource utilization of autonomous vehicle networks and traffic safety. However, the dynamic topology and openness of IoV channels also provide opportunities for malicious nodes to exploit. Attackers can forge vehicle identities, tamper with driving data (such as speed and location), or broadcast false road conditions, undermining the network's trust foundation, rendering traffic decisions ineffective and potentially causing serious incidents. Research indicates that by 2024, malicious vehicle interference will account for 15% of global traffic accidents, with forged information attacks accounting for as much as 67%. Therefore, effectively detecting and isolating malicious vehicles and their behaviors to ensure the trustworthiness of all communicating entities is the foundation of secure IoV communication.
[0003] The detection of malicious vehicles and behaviors in traditional Internet of Vehicles mainly relies on encryption authentication and static rule base matching, but it has many defects in scenarios where Internet of Vehicles resources are limited and communication is dynamic. For example, in the document “Distributed anonymous authentication scheme based on blockchain in VANET”, a distributed anonymous authentication scheme based on blockchain is proposed. This scheme realizes efficient anonymous authentication and batch verification of vehicle identities in vehicular ad hoc networks (VANET) by introducing zero-knowledge proof and nonlinear pair aggregation signature mechanism. However, while this scheme improves security, it also leads to an increase in the computing overhead of on-board equipment, and the delay caused by the blockchain consensus mechanism affects the scalability and practicality of the system in dynamic scenarios. In the document
[0004] The paper "QKBAKA: A Quantum-Key-Based Authentication and Key Agreement Scheme for the Internet of Vehicles" proposes a quantum-key-based authentication and key agreement scheme for the Internet of Vehicles. By introducing role-driven data access control, it achieves secure authentication and controlled access to sensitive data, improving system security and communication performance. However, this scheme suffers from complex multi-level key management and long delays in key agreement initialization, resulting in limitations in resource consumption and real-time performance, hindering its practical application in dynamic and open scenarios. Furthermore, defense detection methods based on static rule bases lack adaptability and robustness in the face of diverse and dynamic attack behaviors. For example, the paper "Cybersecurity in automotive: An intrusion detection system in connected vehicles" proposes an embedded bus intrusion detection system based on two-step detection. This system first screens suspicious messages through spatiotemporal analysis, and then uses a Bayesian network to assess attack probability. Experimental results show that it is effective for identifying conventional attacks such as distributed denial of service attacks (DDoS). However, for dynamic threats such as free-state attacks, detection performance degrades and the false negative rate increases. While this system maintains real-time performance and high detection accuracy, it still requires optimization to adapt to complex dynamic attack scenarios. The paper "MTH-IDS: A multitiered hybrid intrusion detection system for internet of vehicles" proposes a multi-layered hybrid intrusion detection system that combines signature-based and anomaly-based detection methods to achieve efficient identification and real-time defense against external network attacks. However, it lacks adaptability to rapidly evolving dynamic attack patterns and struggles to promptly identify new attack variants. Therefore, given the highly dynamic and complex interactive nature of the connected vehicle environment, traditional detection mechanisms struggle to effectively address the evolving malicious behavior and coordinated attacks.
[0005] Currently, dynamic reputation management mechanisms with greater adaptability and collaborative capabilities have become a focus of scholarly attention. In the detection of malicious vehicles and behaviors in connected vehicles, dynamic trust management mechanisms dynamically quantify the trustworthiness of node behaviors, transcending the traditional binary (legal / illegal) judgment logic. These mechanisms offer dynamic adaptability and detailed behavioral characterization. Furthermore, they effectively integrate feedback from roadside units and neighboring vehicles, achieving multi-source information fusion. By combining vehicle history with the dynamic assessment of node trustworthiness based on current behavior, they enable precise identification and countermeasures against spoofing and collusion attacks. Summary of the Invention
[0006] To address the aforementioned technical issues, the present invention provides a method for detecting malicious nodes in the Internet of Vehicles (IoV) based on a multi-level reputation evaluation model. First, a probabilistic normalization process is performed on the multidimensional trust indicators of vehicles, allowing for rapid differentiation between normal and malicious vehicles through quantitative analysis. Second, a dynamic entropy weight fusion algorithm is introduced to establish a collaborative reputation evaluation algorithm based on behavioral correlations between vehicles. This enables group consensus decision-making and precise identification of malicious vehicles, effectively avoiding the limitations of single-point judgment. Finally, experimental analysis verifies the accuracy of malicious vehicle detection in this method and compares it with other reputation systems.
[0007] The inventive concept of the present invention is: in order to improve the accuracy of malicious vehicle detection in the Internet of Vehicles environment, a method for detecting malicious nodes in the Internet of Vehicles based on a multi-level reputation evaluation model is proposed. First, the multi-dimensional trust indicators of vehicles are probabilistically normalized, and normal vehicles and malicious vehicles are quickly distinguished through quantitative analysis. Secondly, a dynamic entropy weight fusion algorithm is introduced to establish a reputation collaborative evaluation algorithm based on the behavioral association between vehicles, so as to achieve group consensus decision-making and accurate identification of malicious vehicles, effectively avoiding the limitations of single-point judgment. Simulation analysis shows that the scheme can effectively suppress false identity disguise in Sybil attacks and malicious recommendation behaviors in reputation manipulation attacks while taking into account screening efficiency and detection accuracy. The specific implementation steps are given below.
[0008] The present invention is achieved through the following measures: a method for detecting malicious nodes in an Internet of Vehicles environment based on a multi-level reputation evaluation model, comprising the following steps:
[0009] S1. Rapid initial screening of vehicle identity based on multi-dimensional reputation indicators;
[0010] S2. Vehicle direct credit value update;
[0011] S3, vehicle indirect reputation value update;
[0012] S4. Update the comprehensive reputation value of the vehicle;
[0013] S5. Accurately determine the identity of suspicious vehicles based on comprehensive credibility.
[0014] Furthermore, the S1 step includes:
[0015] S11, the roadside unit RSU collects multi-dimensional trust indicators of vehicles;
[0016] S111, evaluate the credibility of the car owner's identity, the method is: set the credibility score of the car owner's identity to S cert, assessing the reliability of the vehicle user or owner based on the vehicle owner's identity attributes. The assessment is based on the vehicle owner's social role and occupational attributes, and converted into a numerical reputation score. High-risk occupations (such as online ride-hailing drivers) score 0.2, ordinary occupations score 0.4, and privileged occupations (such as ambulance drivers) score 0.6;
[0017] S112, evaluate the credibility of the vehicle's historical behavior record, the method is: set the credibility score of the vehicle's historical behavior record to S history , which reflects the credibility and compliance of the vehicle in its past behavior. Calculated based on the vehicle's historical violation record, a vehicle with no violation record scores 0.8, with 0.2 points deducted for each violation, down to a minimum of 0.1;
[0018] S1121. Introduce a time decay factor into the historical reputation score. The method is as follows: Since historical reputation is affected by time, a time decay factor λ is added therein. The formula is as follows: Among them S history is the historical reputation after time decay, S' history is the initial historical reputation, Δt is the time difference, that is, the difference between the current time and the time when the historical event occurred, It is a natural exponential decay factor, which is used to simulate the natural decay process of reputation value decreasing rapidly over time;
[0019] S113, conduct credibility assessment on the vehicle hardware security level, the method is: set the credibility score of the hardware security level to S hardware It is a core indicator used to quantify the security of vehicle hardware devices in the Internet of Vehicles system, reflecting the ability of vehicle hardware to resist physical attacks, data tampering and malicious intrusion. hardware The value range is usually [0, 1], and different hardware security technologies are graded using a standardized evaluation system. If the vehicle hardware is TEE-certified, it is set to 1.0 points; if the hardware is a standard device, it is set to 0.5 points; if the hardware is an uncertified device, it is set to 0 points.
[0020] S12, the roadside unit RSU converts the vehicle's multi-dimensional trust index into a corresponding feature vector;
[0021] S121. Convert the three-dimensional behavior characteristic index into a three-dimensional characteristic vector x i , and sent to the trusted agency TA, where the subscript i represents the i-th vehicle. The specific formula is:
[0022]
[0023] S13. The trusted agency TA performs an initial classification on all vehicles;
[0024] S131, the trusted agency TA calculates the original score of the vehicle in different categories. The method is as follows: the trusted agency TA receives the feature vector x i Then, the preset weight matrix W and the bias term b are used for linear transformation to calculate the original score z of the vehicle in three categories (trustworthy, suspicious, and malicious) i , the specific formula is:
[0025] z i =W·x i +b.
[0026] Among them, x i Represents the vehicle's behavioral feature vector, x i ∈R 3 ,R represents the real number domain; the weight matrix W represents the classification weight parameter set by the system, W∈R 3×3 ; The bias term b introduces an offset for each category, b∈R 3 ;
[0027] S132, the trusted institution TA sends the vehicle's original score z i Converted into probability distribution P i (k) , the method is: the trusted agency TA uses the Softmax function to classify the original vehicle classification score z i Normalization is performed. The Softmax function can convert a real number vector into a probability distribution and is often used to output the probability of each category in multi-classification tasks. The specific formula is:
[0028]
[0029] Among them, j is a traversal index, represents the original score of vehicle i in the jth category (trust / suspect / malicious); k represents the probability of which category is currently being calculated. Indicates the original score of vehicle i belonging to the kth category,
[0030] S133, the trusted institution TA uses the maximum probability principle to calculate the probability distribution P i (k) The classification method is as follows: if the highest probability corresponds to the trustworthy class, the vehicle is judged to be trustworthy and normal communication is allowed; if it corresponds to the malicious class, the vehicle is considered malicious and its communication is prohibited; if it is a suspicious class, it enters the second stage of the collaborative identification process, undergoing fine-grained reputation evaluation and group judgment. The judgment formula is as follows:
[0031]
[0032] Among them, Label irepresents the final classification label of vehicle i, Denotes the probability of choosing i (k) The largest category k is taken as the classification result;
[0033] Furthermore, the S2 step includes:
[0034] S21. Calculate the vehicle's direct reputation. Direct reputation calculation is a quantitative assessment of a vehicle's credibility based on the system's direct interaction history with the infrastructure and between vehicles. The specific formula is as follows:
[0035]
[0036] Among them, C d,v (t) represents the direct reputation value of vehicle v at the current time t. d,v (t+1) represents the direct reputation value of vehicle v at the next moment after the update. c is a weight parameter used to control the rate of reputation value update. Medium S v represents the number of data packets successfully transmitted by vehicle v, F v The formula represents the number of data packets that failed to be transmitted by vehicle v. This formula represents the interaction success rate, reflecting the reliability of data transmission of vehicle v in past interactions. The parameter d is the delay impact coefficient, which is usually negative and is used to control the impact of delay on reputation value. v Indicates the actual transmission delay of the vehicle in a certain interaction. Threshold is the preset delay threshold, which indicates the maximum delay range that the system can tolerate.
[0037] S22. Introduce a reputation degradation function in direct reputation calculation. The method is as follows: In order to prevent the vehicle from not participating in network activities for a long time, which leads to the vehicle v becoming untrustworthy, the system further introduces a reputation degradation function D(C d,v (t)) to adjust the reputation value of the vehicle. The specific formula is as follows:
[0038]
[0039] S221. Calculate the reputation degradation function:
[0040]
[0041] Among them, δ is the reputation degradation coefficient, which controls the speed of degradation of low-reputation nodes. τ is the reputation threshold. When C d,v When (t) < τ, the downgrade takes effect;
[0042] Furthermore, the S3 step includes:
[0043] S31. Differentiate and process the positive and negative recommendations of neighboring vehicles;
[0044] S311. Calculate the weighted contributions of all positive and negative recommended vehicles:
[0045]
[0046] Among them, M positive (t) represents the weighted contribution of all positively recommended vehicles at time t, M negative (t) represents the weighted contribution of all negatively recommended vehicles at time t, R i,v (t) is the recommended value of vehicle i to vehicle v, R i,v (t)>0 indicates positive recommendation, R i,v (t)<0 indicates negative recommendation, Actively recommend vehicle collection, Negatively recommended vehicle collection;
[0047] S312. Calculate the recommendation weight of vehicle i by setting the recommendation weight of vehicle i to reflect the degree of influence of the recommendation of vehicle i on the reputation score of vehicle v when updating the indirect reputation of vehicle v. The calculation formula is:
[0048]
[0049] Among them, the total number of vehicles is n, the recommendation weight of vehicle i and its reputation value C i (t) is proportional to the value of the vehicle, ensuring that the recommendation of high-reputation vehicles is more influential. j is the traversal index of all vehicles;
[0050] S32. Calculate the vehicle's indirect reputation score. Indirect reputation refers to evaluating the credibility of a vehicle (recommended) based on recommendations from neighboring vehicles (recommenders). Vehicle v obtains recommendation information from other vehicle nodes passing through the road section to determine whether vehicle v has engaged in unreliable or malicious behavior. The specific formula is as follows:
[0051] C in,v (t+1)=C in,v (t)+β positive ×M positive (t)-β negative ×M negative (t)
[0052] Among them, C in,v (t) represents the indirect reputation value of vehicle v at the current time t; C in,v (t+1) represents the indirect reputation value of vehicle v at the next moment after the update; β positive and β negative Represents the weight factors of positive and negative recommendations, satisfying β positive >0,β negative >0;
[0053] Furthermore, the S4 step includes:
[0054] S41. Calculate the weights of the vehicle's direct reputation and indirect reputation using a dynamic entropy weight method;
[0055] S411. Calculate the entropy values of direct reputation and indirect reputation using the following method: In the comprehensive evaluation system, information entropy is used to measure the degree of data dispersion of reputation indicators. The entropy formula for each indicator is as follows:
[0056]
[0057] Among them, m is the total number of vehicles, X1 and X2 represent direct reputation and indirect reputation respectively, p1(x i ) represents the relative proportion of vehicle i’s direct reputation among all vehicles, p2(x i ) represents the relative proportion of indirect reputation of vehicle i among all vehicles;
[0058] S412. Calculate the total information entropy value H total :H total =H(X1)+H(X2);
[0059] S413. Calculate weights θ1 and θ2 based on the entropy value. The specific formula is as follows:
[0060]
[0061] Among them, θ1 and θ2 satisfy θ1+θ2=1, and the weight of each factor is proportional to its entropy value;
[0062] S42. Calculate the vehicle's comprehensive reputation score by combining the vehicle's direct and indirect reputation scores according to weights to generate a dynamically updated comprehensive reputation score. The formula is as follows:
[0063] C v (t+1)=θ1·C d,v (t+1)+θ2·C in,v (t+1)
[0064] Among them, C v (t+1) represents the comprehensive reputation value of vehicle v at the next moment after the update;
[0065] Furthermore, the step S5 includes:
[0066] S51. Calculate a dynamic threshold value of the vehicle's comprehensive reputation value;
[0067] S511, calculate the average value of the comprehensive reputation value of all vehicles, the method is: set μ is the comprehensive reputation value C of all vehicles vThe average value reflects the central trend of the overall credibility level. N is the total number of suspicious vehicles. The specific calculation process of μ is as follows:
[0068]
[0069] S512. Calculate the standard deviation of the comprehensive reputation values of all vehicles by setting σ as the standard deviation, which is used to measure the dispersion of the comprehensive reputation values and reflect the volatility of the data distribution. The specific calculation formula is as follows:
[0070]
[0071] S513, calculate the dynamic threshold, the method is: set Th T is a dynamic threshold, which is used to distinguish between credible and malicious vehicles among suspicious vehicles by the mean and standard deviation method. The specific calculation formula is as follows: Th T =μ-k·σ. Where k is the sensitivity adjustment parameter, set k=2;
[0072] S52. Accurately judge suspicious vehicles based on the comprehensive reputation value and dynamic threshold;
[0073] S521. Consider the comprehensive reputation C of vehicle v v and threshold Th T The specific formula for the impact on this classification is as follows:
[0074]
[0075] If the comprehensive reputation value of a suspicious vehicle is greater than the dynamic threshold, it is considered a trustworthy vehicle; otherwise, it is considered a malicious vehicle and its communication is prohibited.
[0076] Compared with the prior art, the present invention has the following beneficial effects:
[0077] (1) The present invention proposes a method for detecting malicious nodes in the Internet of Vehicles based on a multi-level reputation evaluation model. First, the multi-dimensional trust indicators of vehicles are probabilistically normalized, and normal vehicles and malicious vehicles are quickly distinguished through quantitative analysis. Secondly, a dynamic entropy weight fusion algorithm is introduced to establish a reputation collaborative evaluation algorithm based on the behavioral association between vehicles, thereby achieving group consensus decision-making and accurate identification of malicious vehicles, effectively avoiding the limitations of single-point judgment. Simulation analysis shows that the scheme can effectively suppress false identity disguise in Sybil attacks and malicious recommendation behaviors in reputation manipulation attacks while taking into account screening efficiency and detection accuracy.
[0078] (2) The present invention proposes a method for detecting malicious nodes in the Internet of Vehicles (IoV) based on a multi-level reputation evaluation model. During the reputation calculation process, the method adaptively calculates the optimal weighted combination of direct and indirect reputations, overcoming the inherent objectivity and adaptability deficiencies of traditional fixed-weight methods. This mechanism not only improves the accuracy of trust assessments but also enables the system to dynamically respond to changes in the network environment, enabling it to effectively address complex security threats such as coordinated attacks.
[0079] (3) The present invention proposes a method for detecting malicious nodes in the Internet of Vehicles based on a multi-level reputation evaluation model. It introduces a reputation decay function and a penalty factor. By exponentially decaying the reputation value of long-term inactive nodes and applying penalty weights to malicious recommendations, it effectively suppresses false identity disguise in Sybil attacks and malicious recommendation behaviors in reputation manipulation attacks, significantly improving the security and robustness of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0080] The accompanying drawings are used to provide further understanding of the present invention and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention and do not constitute a limitation of the present invention.
[0081] Figure 1 This is an overall flow chart of the method for detecting malicious nodes in the Internet of Vehicles based on a multi-level reputation evaluation model provided by the present invention.
[0082] Figure 2 This is a framework diagram of the reputation evaluation system in the present invention.
[0083] Figure 3 This is a diagram of the vehicle rapid screening and collaborative identification framework provided by the present invention.
[0084] Figure 4 This is a simulated traffic environment map provided by the present invention.
[0085] Figure 5 This is a curve chart showing changes in vehicle credit value provided by the present invention.
[0086] Figure 6 This is a comparison chart of detection accuracy under different ratios of malicious vehicles provided by the present invention.
[0087] Figure 7 This is a comparison chart of the detection recall rates under different proportions of malicious vehicles provided by the present invention.
[0088] Figure 8 This is a comparison chart of F values under different ratios of malicious vehicles provided by the present invention.
[0089] Figure 9 This is a comparison chart of the detection accuracy of the three methods provided by the present invention.
[0090] Figure 10This is a comparison chart of the recall rates of the three methods provided by this invention.
[0091] Figure 11 This is a comparison chart of the F values of the three methods provided by the present invention. DETAILED DESCRIPTION
[0092] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments. Of course, the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0093] Example 1
[0094] This embodiment 1 provides a method for detecting malicious nodes in the Internet of Vehicles based on a multi-level reputation evaluation model. Figure 1 As shown, the following steps are included:
[0095] S1. Rapid initial screening of vehicle identity based on multi-dimensional reputation indicators;
[0096] S2. Vehicle direct credit value update;
[0097] S3, vehicle indirect reputation value update;
[0098] S4. Update the comprehensive reputation value of the vehicle;
[0099] S5. Accurately determine the identity of suspicious vehicles based on comprehensive credibility.
[0100] like Figure 2 As shown in FIG, the vehicle network architecture in the vehicle network malicious node detection method based on the multi-level reputation evaluation model includes: a trusted agency TA, a roadside unit RSU and a communication vehicle.
[0101] like Figure 3 As shown, the specific contents of S1 include the following steps:
[0102] S11, the roadside unit RSU collects multi-dimensional trust indicators of vehicles;
[0103] S111, evaluate the credibility of the car owner's identity, the method is: set the credibility score of the car owner's identity to S cert , assessing the reliability of the vehicle user or owner based on the vehicle owner's identity attributes. The assessment is based on the vehicle owner's social role and occupational attributes, and converted into a numerical reputation score. High-risk occupations (such as online ride-hailing drivers) score 0.2, ordinary occupations score 0.4, and privileged occupations (such as ambulance drivers) score 0.6;
[0104] S112, evaluate the credibility of the vehicle's historical behavior record, the method is: set the credibility score of the vehicle's historical behavior record to S history, which reflects the credibility and compliance of the vehicle in its past behavior. Calculated based on the vehicle's historical violation record, a vehicle with no violation record scores 0.8, with 0.2 points deducted for each violation, down to a minimum of 0.1;
[0105] S1121. Introduce a time decay factor into the historical reputation score. The method is as follows: Since historical reputation is affected by time, a time decay factor λ is added therein. The formula is as follows: Among them S history is the historical reputation after time decay, S' history is the initial historical reputation, Δt is the time difference, that is, the difference between the current time and the time when the historical event occurred, It is a natural exponential decay factor, which is used to simulate the natural decay process of reputation value decreasing rapidly over time;
[0106] S113, conduct credibility assessment on the vehicle hardware security level, the method is: set the credibility score of the hardware security level to S hardware It is a core indicator used to quantify the security of vehicle hardware devices in the Internet of Vehicles system, reflecting the ability of vehicle hardware to resist physical attacks, data tampering and malicious intrusion. hardware The value range is usually [0, 1], and different hardware security technologies are graded using a standardized evaluation system. If the vehicle hardware is TEE-certified, it is set to 1.0 points; if the hardware is a standard device, it is set to 0.5 points; if the hardware is an uncertified device, it is set to 0 points.
[0107] S12, the roadside unit RSU converts the vehicle's multi-dimensional trust index into a corresponding feature vector;
[0108] S121. Convert the three-dimensional behavior characteristic index into a three-dimensional characteristic vector x i , and sent to the trusted agency TA, where the subscript i represents the i-th vehicle. The specific formula is:
[0109]
[0110] S13. The trusted agency TA performs an initial classification on all vehicles;
[0111] S131, the trusted agency TA calculates the original score of the vehicle in different categories. The method is as follows: the trusted agency TA receives the feature vector x i Then, the preset weight matrix W and the bias term b are used for linear transformation to calculate the original score z of the vehicle in three categories (trustworthy, suspicious, and malicious) i , the specific formula is:
[0112] z i =W·x i +b.
[0113] Among them, x i Represents the vehicle's behavioral feature vector, x i ∈R 3 ,R represents the real number domain; the weight matrix W represents the classification weight parameter set by the system, W∈R 3×3 ; The bias term b introduces an offset for each category, b∈R 3 ;
[0114] S132, the trusted institution TA sends the vehicle's original score z i Converted into probability distribution P i (k) , the method is: the trusted agency TA uses the Softmax function to classify the original vehicle classification score z i Normalization is performed. The Softmax function can convert a real number vector into a probability distribution and is often used to output the probability of each category in multi-classification tasks. The specific formula is:
[0115]
[0116] Among them, j is a traversal index, represents the original score of vehicle i in the jth category (trust / suspect / malicious); k represents the probability of which category is currently being calculated. Indicates the original score of vehicle i belonging to the kth category,
[0117] S133, the trusted institution TA uses the maximum probability principle to calculate the probability distribution P i (k) The classification method is as follows: if the highest probability corresponds to the trustworthy class, the vehicle is judged to be trustworthy and normal communication is allowed; if it corresponds to the malicious class, the vehicle is considered malicious and its communication is prohibited; if it is a suspicious class, it enters the second stage of the collaborative identification process, undergoing fine-grained reputation evaluation and group judgment. The judgment formula is as follows:
[0118]
[0119] Among them, Label i represents the final classification label of vehicle i, Denotes the probability of choosing i (k) The largest category k is taken as the classification result;
[0120] like Figure 3 As shown, the specific content of S2 includes the following steps:
[0121] S21. Calculate the vehicle's direct reputation. Direct reputation calculation is a quantitative assessment of a vehicle's credibility based on the system's direct interaction history with the infrastructure and between vehicles. The specific formula is as follows:
[0122]
[0123] Among them, C d,v (t) represents the direct reputation value of vehicle v at the current time t. d,v (t+1) represents the direct reputation value of vehicle v at the next moment after the update. c is a weight parameter used to control the rate of reputation value update. Medium S v represents the number of data packets successfully transmitted by vehicle v, F v The formula represents the number of data packets that failed to be transmitted by vehicle v. This formula represents the interaction success rate, reflecting the reliability of data transmission of vehicle v in past interactions. The parameter d is the delay impact coefficient, which is usually negative and is used to control the impact of delay on reputation value. v Indicates the actual transmission delay of the vehicle in a certain interaction. Threshold is the preset delay threshold, which indicates the maximum delay range that the system can tolerate.
[0124] S22. Introduce a reputation degradation function in direct reputation calculation. The method is as follows: In order to prevent the vehicle from not participating in network activities for a long time, which leads to the vehicle v becoming untrustworthy, the system further introduces a reputation degradation function D(C d,v (t)) to adjust the reputation value of the vehicle. The specific formula is as follows:
[0125]
[0126] S221. Calculate the reputation degradation function:
[0127]
[0128] Among them, δ is the reputation degradation coefficient, which controls the speed of degradation of low-reputation nodes. τ is the reputation threshold. When C d,v When (t) < τ, the downgrade takes effect;
[0129] like Figure 3 As shown, the specific content of S3 includes the following steps:
[0130] S31. Differentiate and process the positive and negative recommendations of neighboring vehicles;
[0131] S311. Calculate the weighted contributions of all positive and negative recommended vehicles:
[0132]
[0133] Among them, Mpositive (t) represents the weighted contribution of all positively recommended vehicles at time t, M negative (t) represents the weighted contribution of all negatively recommended vehicles at time t, R i,v (t) is the recommended value of vehicle i to vehicle v, R i,v (t)>0 indicates positive recommendation, R i,v (t)<0 indicates negative recommendation, Actively recommend vehicle collection, Negatively recommended vehicle collection;
[0134] S312. Calculate the recommendation weight of vehicle i by setting the recommendation weight of vehicle i to reflect the degree of influence of the recommendation of vehicle i on the reputation score of vehicle v when updating the indirect reputation of vehicle v. The calculation formula is:
[0135]
[0136] Among them, the total number of vehicles is n, the recommendation weight of vehicle i and its reputation value C i (t) is proportional to the value of the vehicle, ensuring that the recommendation of high-reputation vehicles is more influential. j is the traversal index of all vehicles;
[0137] S32. Calculate the vehicle's indirect reputation score. Indirect reputation refers to evaluating the credibility of a vehicle (recommended) based on recommendations from neighboring vehicles (recommenders). Vehicle v obtains recommendation information from other vehicle nodes passing through the road section to determine whether vehicle v has engaged in unreliable or malicious behavior. The specific formula is as follows:
[0138] C in,v (t+1)=C in,v (t)+β positive ×M positive (t)-β negative ×M negative (t)
[0139] Among them, C in,v (t) represents the indirect reputation value of vehicle v at the current time t; C in,v (t+1) represents the indirect reputation value of vehicle v at the next moment after the update; β positive and β negative Represents the weight factors of positive and negative recommendations, satisfying β positive >0,β negative >0;
[0140] like Figure 3 As shown, the specific contents of S4 include the following steps:
[0141] S41. Calculate the weights of the vehicle's direct reputation and indirect reputation using a dynamic entropy weight method;
[0142] S411. Calculate the entropy values of direct reputation and indirect reputation using the following method: In the comprehensive evaluation system, information entropy is used to measure the degree of data dispersion of reputation indicators. The entropy formula for each indicator is as follows:
[0143]
[0144] Among them, m is the total number of vehicles, X1 and X2 represent direct reputation and indirect reputation respectively, p1(x i ) represents the relative proportion of vehicle i’s direct reputation among all vehicles, p2(x i ) represents the relative proportion of indirect reputation of vehicle i among all vehicles;
[0145] S412. Calculate the total information entropy value H total :H total =H(X1)+H(X2);
[0146] S413. Calculate weights θ1 and θ2 based on the entropy value. The specific formula is as follows:
[0147]
[0148] Among them, θ1 and θ2 satisfy θ1+θ2=1, and the weight of each factor is proportional to its entropy value;
[0149] S42. Calculate the vehicle's comprehensive reputation score by combining the vehicle's direct and indirect reputation scores according to weights to generate a dynamically updated comprehensive reputation score. The formula is as follows:
[0150] C v (t+1)=θ1·C d,v (t+1)+θ2·C in,v (t+1)
[0151] Among them, C v (t+1) represents the comprehensive reputation value of vehicle v at the next moment after the update;
[0152] like Figure 3 As shown, the specific contents of S5 include the following steps:
[0153] S51. Calculate a dynamic threshold value of the vehicle's comprehensive reputation value;
[0154] S511, calculate the average value of the comprehensive reputation value of all vehicles, the method is: set μ is the comprehensive reputation value C of all vehicles v The average value reflects the central trend of the overall credibility level. N is the total number of suspicious vehicles. The specific calculation process of μ is as follows:
[0155]
[0156] S512. Calculate the standard deviation of the comprehensive reputation values of all vehicles by setting σ as the standard deviation, which is used to measure the dispersion of the comprehensive reputation values and reflect the volatility of the data distribution. The specific calculation formula is as follows:
[0157]
[0158] S513, calculate the dynamic threshold, the method is: set Th T is a dynamic threshold, which is used to distinguish between credible and malicious vehicles among suspicious vehicles by the mean and standard deviation method. The specific calculation formula is as follows: Th T =μ-k·σ. Where k is the sensitivity adjustment parameter, set k=2;
[0159] S52. Accurately judge suspicious vehicles based on the comprehensive reputation value and dynamic threshold;
[0160] S521. Consider the comprehensive reputation C of vehicle v v and threshold Th T The specific formula for the impact on this classification is as follows:
[0161]
[0162] If the comprehensive reputation value of a suspicious vehicle is greater than the dynamic threshold, it is considered a trustworthy vehicle; otherwise, it is considered a malicious vehicle and its communication is prohibited.
[0163] In order to verify the feasibility of this embodiment, the reputation changes of this embodiment 1 are analyzed:
[0164] Simulation design and reputation changes:
[0165] 1. The scheme simulation design is as follows:
[0166] a) If Figure 4 As shown in Figure 2, this experiment uses SUMO as the simulation platform for the connected vehicle environment. The Python script's Traci interface is used to connect to the SUMO platform to simulate vehicle behavior and implement the reputation evaluation model. The platform is configured with an Intel(R) Core(TM) i7-8565U processor and 8GB of memory.
[0167] b) If Figure 4 As shown in Figure 2, an accident scenario is set up in the simulation. After the accident, a malicious vehicle sends false information in an attempt to influence the decisions of other vehicles. During this process, we record the vehicle's direct reputation, indirect reputation, and final comprehensive reputation, and analyze the impact of the malicious vehicle on the overall Internet of Vehicles environment.
[0168] c) If Figure 4As shown in the figure, the experimental data includes vehicle trajectory information, communication records, reputation value change trends, etc. All data are stored in CSV format and processed and analyzed by Python.
[0169] d) If Figure 4 As shown in the figure, the simulation scenario is a one-way, four-lane road section with a speed limit of 120 km / h and a length of 5000 meters. Roadside units (RSUs) and cameras are deployed along the road for data collection and anomaly detection. Initially, all vehicles follow normal traffic rules and gradually accumulate reputation points. This experiment sets three vehicle categories: trustworthy vehicles are set as yellow, malicious vehicles are set as red, and suspicious vehicles are set as blue. The specific simulation parameters are shown in Table 1 below.
[0170] Table 1
[0171]
[0172]
[0173] 2. Changes in credit are as follows:
[0174] The experiment categorized vehicle behavior into benign and malicious, assigning different impact weights to each behavior. Data values were then generated based on the set number of times each behavior occurred. Random behavior sequences were used to disrupt the order of the behaviors to simulate the uncertainty inherent in real-world vehicle behavior. Table 2 below shows various vehicle behavior parameters.
[0175] Table 2
[0176]
[0177] In order to verify the system's response speed and sensitivity in detecting malicious behavior and rewarding trustworthy behavior, 200 random vehicle behaviors were set up, of which 40% were malicious behaviors and 60% were trustworthy behaviors. Figure 4 The figure shows how a vehicle's reputation changes under different behaviors. As can be seen, for behaviors numbered 5, 42, 82, and 143, the reputation value decreases rapidly due to the vehicle's continued malicious behavior, demonstrating that the system is able to immediately punish malicious behavior. For behaviors numbered 40, 65, 75, and 135, the vehicle maintains good behavior, and its reputation value increases rapidly, demonstrating that the system is able to quickly identify and reward trustworthy behavior. For behaviors numbered 50 to 70, 100 to 120, and 170 to 200, the rise and fall in reputation value are moderate, indicating that the system's reputation value does not rapidly adjust in response to a single malicious behavior. Instead, it only significantly decreases after the accumulation of multiple malicious behaviors. This prevents system misjudgments and maintains model stability. The system also supports dynamic reputation management, allowing vehicles to gradually restore their reputation value through continuous positive behavior.
[0178] From the above analysis, we can see that this reputation assessment model has high sensitivity and adaptability, ensuring the accurate and dynamic identification of malicious behavior, while also giving trusted vehicles a reasonable opportunity to restore their reputation, making the entire trust mechanism more reliable and fair, and taking into account the robustness and stability of the system.
[0179] Example 2
[0180] To verify the performance of this embodiment, Example 2 compares the performance of this embodiment with other reputation management solutions, including Solution 1 proposed by scholars Chen JM et al. in "TMEC: a trust management based on evidence combination on attack-resistant and collaborative internet of vehicles" and Solution 2 proposed by scholars Sato F et al. in "A reputation system that resists a collusive attack focused on a specific target".
[0181] 1. Performance Analysis
[0182] (1) Comparison of Malicious Vehicle Detection Accuracy
[0183] Figure 9 The experimental results of the accuracy of the three solutions under different proportions of malicious vehicles are compared. As can be seen from the figure, as the proportion of malicious vehicles increases, the accuracy of the three methods generally shows a downward trend. This is because the objective limitations of the reputation mechanism make it difficult to withstand a large number of malicious vehicles in the network. The solutions of the present invention are higher in accuracy than the TMEC and RS solutions. When the proportion of malicious vehicles reaches 25%, the accuracy of the present invention remains above 90%. This is because the present invention adopts a three-dimensional initial reputation model. This method constructs the initial reputation through a linear combination of professional attributes, historical behavior, and hardware security, taking into account both static identity and dynamic behavior. It can more comprehensively evaluate the credibility of the vehicle, reduce the deviation of single-dimensional evaluation, and effectively identify malicious vehicles in the network.
[0184] (2) Comparison of recall rates for malicious vehicle detection
[0185] Figure 10The following experimental results compare the recall rates of the three methods under varying proportions of malicious vehicles. While the recall rates of all three methods decrease as the proportion of malicious vehicles increases, the recall rate of the present invention remains consistently higher than that of TMEC and RS. This is primarily due to the present invention's comprehensive consideration of direct and indirect reputation, and its use of an entropy weighting method to dynamically assign weights, thereby improving detection accuracy when calculating comprehensive reputation. Compared to methods that rely on a single data source, the present invention reduces bias and enhances system robustness, significantly improving recall rates.
[0186] (3) Comparison of F-values for malicious vehicle detection
[0187] Figure 11 The experimental results of the three schemes on the F value (harmonic mean of precision and recall) under different malicious vehicle proportions are shown. As can be seen from the figure, the F value of the scheme of the present invention is better than other schemes in different malicious vehicle proportion scenarios. Especially when the proportion of colluding malicious vehicles reaches 40%, the F value of the present invention can still be maintained at around 85%, which is much higher than the TMEC and RS schemes, indicating that the present invention still has strong robustness and anti-attack capabilities when facing large-scale malicious nodes. The key to this performance improvement is that the present invention introduces the data packet success rate and response delay in the direct reputation calculation, so that the reputation value can more accurately reflect the communication quality and behavior stability of the vehicle, thereby effectively suppressing the long-term disguise of malicious nodes and reducing the misjudgment and missed judgment rates.
[0188] The above two examples fully demonstrate the sensitivity and accuracy of this embodiment in detecting malicious vehicles. At the same time, the performance comparison with other existing reputation management solutions fully demonstrates the innovation and performance superiority of the present invention.
[0189] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A method for detecting malicious nodes in an Internet of Vehicles based on a multi-level reputation evaluation model, characterized in that: The steps include: S1. Rapid initial screening of vehicle identity based on multi-dimensional reputation indicators; S2. Vehicle direct credit value update; S3, vehicle indirect reputation value update; S4. Update the comprehensive reputation value of the vehicle; S5. Accurately determine the identity of suspicious vehicles based on comprehensive credibility.
2. The method for detecting malicious nodes in an Internet of Vehicles based on a multi-level reputation evaluation model according to claim 1, characterized in that: The S1 step includes the following steps: S11, the roadside unit RSU collects multi-dimensional trust indicators of vehicles; In step S11, the process of the roadside unit RSU collecting the vehicle's multi-dimensional trust indicators includes the following steps: S111, evaluate the credibility of the car owner's identity, the method is: set the credibility score of the car owner's identity to S cert , assess the reliability of the vehicle user or owner based on the vehicle owner's identity attributes, and evaluate the vehicle owner's social role and occupational attributes, and convert it into a numerical reputation value. High-risk occupations score 0.2, ordinary occupations score 0.4, and privileged occupations score 0.6; S112, evaluate the credibility of the vehicle's historical behavior record, the method is: set the credibility score of the vehicle's historical behavior record to S history , calculated based on the vehicle's historical violation record, a vehicle with no violation record will score 0.8 points, and 0.2 points will be deducted for each violation, which can be reduced to a minimum of 0.1; In step S112, the process of completing the credibility assessment of the vehicle historical behavior record includes the following steps: S1121. Introducing a time decay factor into the historical reputation score. The method is as follows: Since historical reputation is affected by time, a time decay factor λ is added therein. The formula is as follows: Among them S history is the historical reputation after time decay, S' history is the initial historical reputation, Δt is the time difference, that is, the difference between the current time and the time when the historical event occurred, It is a natural exponential decay factor, which is used to simulate the natural decay process of reputation value decreasing rapidly over time; S113, conduct credibility assessment on the vehicle hardware security level, the method is: set the credibility score of the hardware security level to S hardware , S hardware The value range is [0,1]. Different hardware security technologies are graded through a standardized evaluation system. If the vehicle hardware passes TEE authentication, it is set to 1.0 points; if the hardware is a common device, it is set to 0.5 points; if the hardware is an uncertified device, it is set to 0 points. S12, the roadside unit RSU converts the vehicle's multi-dimensional trust index into a corresponding feature vector; In step S12, the process of converting the vehicle multi-dimensional trust index into a feature vector by the roadside unit RSU includes the following steps: S121. Convert the three-dimensional behavior characteristic index into a three-dimensional characteristic vector x i , and sent to the trusted agency TA, where the subscript i represents the i-th vehicle, and the formula is: S13. The trusted authority TA performs initial identity classification on all vehicles; In step S13, the process of the trusted institution TA performing initial identity classification on all vehicles includes the following steps: S131, the trusted agency TA calculates the original score of the vehicle in different categories. The method is as follows: the trusted agency TA receives the feature vector x i Then, the preset weight matrix W and the bias term b are used for linear transformation to calculate the original score z of the vehicle in the three categories of credible, suspicious, and malicious. i , the formula is: z i =W·x i +b. Among them, x i Represents the vehicle's behavioral feature vector, x i ∈R 3 ,R represents the real number domain; the weight matrix W represents the classification weight parameter set by the system, W∈R 3×3 ; The bias term b introduces an offset for each category, b∈R 3 ; S132, the trusted institution TA sends the vehicle's original score z i Converted into probability distribution P i (k) , the method is: the trusted agency TA uses the Softmax function to classify the original vehicle classification score z i After normalization, the Softmax function converts the real number vector into a probability distribution, which is used to output the probability of each category in multi-classification tasks. The formula is: Among them, j is a traversal index, represents the original score of vehicle i in the jth category (trust / suspect / malicious); k represents the probability of which category is currently being calculated. Indicates the original score of vehicle i belonging to the kth category, S133, the trusted institution TA uses the maximum probability principle to calculate the probability distribution P i (k) The classification method is as follows: if the highest probability corresponds to the trustworthy class, the vehicle is judged to be trustworthy and normal communication is allowed; if it corresponds to the malicious class, the vehicle is considered malicious and its communication is prohibited; if it belongs to the suspicious class, it enters the second stage of the collaborative identification process, undergoing fine-grained reputation evaluation and group judgment. The judgment formula is as follows: Among them, Label i represents the final classification label of vehicle i, Denotes the probability of choosing i (k) The largest category k is taken as the classification result.
3. The method for detecting malicious nodes in an Internet of Vehicles based on a multi-level reputation evaluation model according to claim 1, characterized in that: The S2 step includes the following steps: S21. Calculate the vehicle's direct reputation. The method is as follows: Direct reputation calculation is a quantitative assessment of a vehicle's credibility based on the system's direct interaction history between the vehicle and infrastructure, and between vehicles. The specific formula is as follows: Among them, C d,v (t) represents the direct reputation value of vehicle v at the current time t, C d,v (t+1) represents the direct reputation value of vehicle v at the next moment after the update, and c is a weight parameter used to control the rate of reputation value update. Medium S v represents the number of data packets successfully transmitted by vehicle v, F v represents the number of data packets that failed to be transmitted by vehicle v. This formula represents the interaction success rate, reflecting the reliability of data transmission in vehicle v’s past interactions. The parameter d is the delay impact coefficient, which is used to control the impact of delay on the reputation value. v Indicates the actual transmission delay of the vehicle in a certain interaction. Threshold is the preset delay threshold, which indicates the maximum delay range that the system can tolerate. S22. Introduce a reputation degradation function in direct reputation calculation. The method is as follows: introduce a reputation degradation function D(C d,v (t)) to adjust the reputation value of the vehicle, the formula is as follows: In step S22, the process of introducing the reputation degradation function into direct reputation calculation includes the following steps: S221. Calculate the reputation degradation function: Among them, δ is the reputation degradation coefficient, which controls the speed of degradation of low-reputation nodes, τ is the reputation threshold, when C d,v When (t)<τ, degradation takes effect.
4. The method for detecting malicious nodes in an Internet of Vehicles based on a multi-level reputation evaluation model according to claim 1, characterized in that: The S3 step includes the following steps: S31. Differentiate and process the positive and negative recommendations of neighboring vehicles; In step S31, the process of distinguishing positive and negative recommendations of neighboring vehicles includes the following steps: S311. Calculate the weighted contributions of all positive and negative recommended vehicles: Among them, M positive (t) represents the weighted contribution of all positively recommended vehicles at time t, M negative (t) represents the weighted contribution of all negatively recommended vehicles at time t, R i,v (t) is the recommended value of vehicle i to vehicle v, R i,v (t)>0 indicates positive recommendation, R i,v (t)<0 indicates negative recommendation, Actively recommend vehicle collection, Negatively recommended vehicle collection; S312. Calculate the recommendation weight of vehicle i by setting the recommendation weight of vehicle i to reflect the degree of influence of the recommendation of vehicle i on the reputation score of vehicle v when updating the indirect reputation of vehicle v. The calculation formula is: Among them, the total number of vehicles is n, the recommendation weight of vehicle i and its reputation value C i (t) is proportional to, j is the traversal index of all vehicles; S32. Calculate the vehicle's indirect reputation score. Indirect reputation refers to evaluating the vehicle's credibility through recommendations from neighboring vehicles. Vehicle v obtains recommendation information from other vehicle nodes passing through the road section to determine whether vehicle v has engaged in unreliable or malicious behavior. The formula is as follows: C in,v (t+1)=C in,v (t)+β positive ×M positive (t)-β negative ×M negative (t) Among them, C in,v (t) represents the indirect reputation value of vehicle v at the current time t; C in,v (t+1) represents the indirect reputation value of vehicle v at the next moment after the update; β positive and β negative Represents the weight factors of positive and negative recommendations, satisfying β positive >0,β negative >0.
5. The method for detecting malicious nodes in an Internet of Vehicles based on a multi-level reputation evaluation model according to claim 1, characterized in that: The S4 step includes the following steps: S41. Calculate the weights of the vehicle's direct reputation and indirect reputation using a dynamic entropy weight method; In step S41, the process of calculating the weights of the vehicle's direct reputation and indirect reputation using the dynamic entropy weight method includes the following steps: S411. Calculate the entropy values of direct reputation and indirect reputation using the following method: In the comprehensive evaluation system, information entropy is used to measure the degree of data dispersion of reputation indicators. The entropy formula for each indicator is as follows: Among them, m is the total number of vehicles, X1 and X2 represent direct reputation and indirect reputation respectively, p1(x i ) represents the relative proportion of vehicle i’s direct reputation among all vehicles, p2(x i ) represents the relative proportion of indirect reputation of vehicle i among all vehicles; S412. Calculate the total information entropy value H total :H total =H(X1)+H(X2); S413. Calculate weights θ1 and θ2 based on the entropy value. The specific formula is as follows: Among them, θ1 and θ2 satisfy θ1+θ2=1, and the weight of each factor is proportional to its entropy value; S42. Calculate the comprehensive reputation score of the vehicle by combining the direct and indirect reputation values of the vehicle according to weights to generate a dynamically updated comprehensive reputation score. The formula is as follows: C v (t+1)=θ1·C d,v (t+1)+θ2·C in,v (t+1) Among them, C v (t+1) represents the comprehensive reputation value of vehicle v at the next moment after the update.
6. The method for detecting malicious nodes in an Internet of Vehicles based on a multi-level reputation evaluation model according to claim 1, characterized in that: The S5 step includes the following steps: S51. Calculate a dynamic threshold value of the vehicle's comprehensive reputation value; In step S51, the process of calculating the dynamic threshold value of the vehicle comprehensive reputation value includes the following steps: S511, calculate the average value of the comprehensive reputation value of all vehicles, the method is: set μ is the comprehensive reputation value C of all vehicles v The average value reflects the central tendency of the overall credibility level. N is the total number of suspicious vehicles. The calculation process of μ is as follows: S512. Calculate the standard deviation of the comprehensive reputation values of all vehicles. The method is as follows: let σ be the standard deviation, which is used to measure the dispersion of the comprehensive reputation value and reflect the volatility of the data distribution. The calculation formula is as follows: S513, calculate the dynamic threshold, the method is: set Th T is a dynamic threshold, which is used to distinguish between credible and malicious vehicles among suspicious vehicles by the mean and standard deviation method. The calculation formula is as follows: Th T =μ-k·σ, where k is the sensitivity adjustment parameter, set k=2; S52. Accurately judge suspicious vehicles based on the comprehensive reputation value and dynamic threshold; In step S521, the process of accurately judging a suspicious vehicle based on the comprehensive credibility value and the dynamic threshold includes the following steps: S521. Consider the comprehensive reputation C of vehicle v v and threshold Th T The impact of this classification is as follows: If the comprehensive reputation value of a suspicious vehicle is greater than the dynamic threshold, it is considered a trustworthy vehicle; otherwise, it is considered a malicious vehicle and its communication is prohibited.