Vehicle-mounted network with abnormal wake-up detection function, abnormal wake-up detection method, computer device, storage medium and vehicle

By managing controllers in the vehicle network through a central gateway and using a behavior detection model to analyze wake-up message data, the problem of distinguishing between normal and abnormal wake-ups of automotive components in a dormant state is solved. This enables the identification of abnormal wake-ups and the location of fault sources, reducing the risk of accidents.

CN120880871APending Publication Date: 2025-10-31CHINA FAW CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510853842.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

In existing technologies, it is difficult to distinguish between normal and abnormal wake-up of automotive components in a dormant state, which can mask the source of the fault and create potential safety hazards.

Method used

The controllers in the vehicle network are managed by a central gateway. The wake-up message data is analyzed by a behavior detection model to identify wake-up behavior patterns and distinguish between normal and abnormal wake-ups.

Benefits of technology

It enables accurate identification of controller wake-up events, discovers the source of abnormal wake-ups, and reduces potential safety hazards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880871A_ABST
    Figure CN120880871A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle-mounted network with abnormal wake-up detection, an abnormal wake-up detection method, a computer device, a storage medium and a vehicle, the vehicle-mounted network with abnormal wake-up detection comprises a central gateway and a plurality of controllers, and the central gateway is used for executing the following steps: in a sleep mode, the plurality of controllers are connected with the central gateway; and obtaining message data sent by the awakened controller, and detecting the message data by using the behavior detection model to obtain an awakening behavior mode of the message data. According to the method and the device, the message data sent when the controller is awakened in the sleep mode can be detected through the behavior detection model, so that the awakening behavior mode corresponding to the message data is judged, and whether the event of awakening the controller is the normal mode or the abnormal mode is determined through the awakening behavior mode; normal wake-up and abnormal wake-up of the controller can be distinguished, a fault source after abnormal wake-up can be found, and accident potential can be eliminated. The invention is widely applied to the technical field of automobiles.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of automotive technology, and in particular to an in-vehicle network with abnormal wake-up detection, an abnormal wake-up detection method, a computer device, a storage medium, and a vehicle. Background Technology

[0002] Cars have numerous electrical components that can be put into a dormant state when the car is not in use, thereby reducing energy consumption and wear and tear on power supply components such as batteries.

[0003] Some automotive components need to remain in a wake-up state while in sleep mode to ensure the vehicle's basic functions and emergency capabilities. For example, some automotive components connect to sensors to monitor relevant vehicle data (such as temperature) in real time or receive data transmitted from external sources. When the detected data falls within a specific range, they wake up and process the data (e.g., triggering an alarm in case of overheating). Therefore, even when the vehicle is in sleep mode, some automotive components are not completely stopped, but rather in a low-power state of data detection or reception that can be quickly woken up.

[0004] Based on this sleep state setting, when a car component is awakened, it usually means that a situation requiring a response has occurred—the kind of situation that the component would normally need to detect and respond to in its sleep state, such as overheating or detecting external control commands. However, malfunctions in car components or wiring, or overly sensitive sensors, can also trigger the awakening of a car component from its sleep state (for example, if the actual temperature is not excessively high but is only close to a threshold, but the sensor detects it as overheating, thus triggering a wake-up). This type of wake-up is an abnormal wake-up. The symptoms of an abnormal wake-up are the same as those of a car component being awakened while normally in sleep mode, causing confusion between normal response and abnormal state. This can easily lead to false triggering of car components, and more seriously, it can mask the fault source causing the abnormal wake-up, thus creating a potential safety hazard. Summary of the Invention

[0005] To address the technical problems of current automotive sleep state wake-up technologies, such as the ease with which normal wake-up and abnormal wake-up can be confused, thereby masking the source of faults and creating potential safety hazards, the present invention aims to provide an in-vehicle network with abnormal wake-up detection, an abnormal wake-up detection method, a computer device, a storage medium, and a vehicle.

[0006] On one hand, embodiments of the present invention include an in-vehicle network with abnormal wake-up detection, the in-vehicle network with abnormal wake-up detection comprising: Multiple controllers; Central gateway; the central gateway is used to manage data exchange between the controllers, and the central gateway is used to perform the following steps: In sleep mode, the message data sent by the woken controller is acquired; the sleep mode is the default sleep state of each controller. The message data is detected using a behavior detection model to obtain the wake-up behavior pattern of the message data; the wake-up behavior pattern belongs to a normal mode or an abnormal mode.

[0007] Furthermore, the step of acquiring message data sent by the awakened controller in sleep mode includes: During the first time period in the sleep mode, the message data sent by each of the awakened controllers is collected.

[0008] Further, the step of using a behavior detection model to detect the message data and obtain the wake-up behavior pattern of the message data includes: Iterate through multiple combinations of abnormal controllers to be identified, and perform a corresponding detection process for each combination of abnormal controllers to be identified. Based on the detection results of each detection process, determine the wake-up behavior pattern of each message data; Each of the detection processes includes the following steps: At least one controller is determined from each of the controllers to form the combination of the anomaly controllers to be identified in the current detection process; Obtain the normal controller combination to be identified corresponding to the detection process described in this article; the normal controller combination to be identified includes all controllers except the abnormal controller combination to be identified. The message data from the combination of normal controllers to be identified is acquired and used as normal samples to train the behavior detection model; The message data from the combination of abnormal controllers to be identified is obtained, and the data is input into the behavior detection model for processing to obtain the wake-up behavior pattern of the message data of each controller in the combination of abnormal controllers to be identified, which is used as the detection result of the detection process.

[0009] Further, determining the wake-up behavior pattern of each message data based on the detection results of each detection process includes: For any of the aforementioned message data, the total number of votes that the detection process identifies as the abnormal pattern of the message data is determined by a voting method; The wake-up behavior pattern of the message data with the largest total number of votes is determined as the abnormal mode, and the wake-up behavior patterns of the other message data are determined as the normal mode. Further, determining at least one controller from among the controllers to form the combination of anomaly controllers to be identified corresponding to the current detection process includes: Obtain the aging curve of the vehicle network; Based on the aging curve, determine the estimated number of the combination of the anomaly controllers to be identified; Based on the estimated number, a corresponding number of the controllers are determined from each of the controllers to form the group of controllers to be identified as an anomaly.

[0010] Furthermore, the central gateway is used to perform the following steps: Based on the wake-up behavior pattern of the message data, locate the abnormal controller among the multiple controllers; An abnormal wake-up detection report is generated based on the abnormality controller.

[0011] On the other hand, embodiments of the present invention also include an abnormal wake-up detection method for an in-vehicle network, wherein the in-vehicle network includes multiple controllers, and the abnormal wake-up detection method for the in-vehicle network includes: In sleep mode, acquire message data sent by the awakened controller; The message data is detected using a behavior detection model to obtain the wake-up behavior pattern of the message data; the wake-up behavior pattern belongs to a normal mode or an abnormal mode.

[0012] On the other hand, embodiments of the present invention also include a computer device, including a memory and a processor, the memory for storing at least one program, and the processor for loading at least one program to execute the abnormal wake-up detection method for in-vehicle networks in the embodiments.

[0013] On the other hand, embodiments of the present invention also include a computer-readable storage medium storing a processor-executable program, which, when executed by a processor, is used to perform the abnormal wake-up detection method for in-vehicle networks in the embodiments.

[0014] On the other hand, embodiments of the present invention also include a vehicle, the vehicle including the in-vehicle network with abnormal wake-up detection as described in the embodiments.

[0015] The beneficial effects of the present invention are as follows: The in-vehicle network with abnormal wake-up detection and the abnormal wake-up detection method for the in-vehicle network in the embodiments can detect the message data sent by the controller when it is woken up in sleep mode through the behavior detection model, thereby determining the wake-up behavior mode corresponding to the message data. This enables the analysis of the wake-up events of multiple controllers in the car in sleep mode, and determines whether the event that wakes up the controller is a normal mode or an abnormal mode by the wake-up behavior mode. It can distinguish between normal wake-up and abnormal wake-up of the controller, discover the fault source behind the abnormal wake-up, and help eliminate potential accident hazards. Attached Figure Description

[0016] Figure 1 This is a schematic diagram of the structure of an in-vehicle network with abnormal wake-up detection in the embodiment. Figure 2 This is a schematic diagram of the controller connection in the embodiment; Figure 3 This is a schematic diagram illustrating the steps performed by the central gateway in the embodiment, which is the abnormal wake-up detection method for the in-vehicle network. Figure 4 This is a schematic diagram illustrating the controller sending message data to the central gateway in the embodiment. Figure 5 This is a schematic diagram illustrating the working principle of the behavior detection model in the embodiment; Figure 6 This is a schematic diagram illustrating the principle of steps S201-S202 in the embodiment; Figure 7 This is a schematic diagram illustrating the principle of determining the wake-up behavior pattern through a voting method in the embodiment. Figure 8 This is a schematic diagram of the aging curve in the embodiment; Figure 9 This is a schematic diagram of the abnormal wake-up detection system in the embodiment; Figure 10 This is a schematic diagram of the computer device in the embodiment. Detailed Implementation

[0017] Terminology Explanation: Vehicle hibernation mode: refers to the vehicle's electronic control system (such as ECU) and its connected sensors and controllers actively entering a low-power standby mode when the vehicle is not in use, in order to reduce static power consumption, prevent battery depletion, and maintain basic monitoring functions while waiting to be woken up; Central Gateway: The central gateway is a core component of the automotive electronic and electrical architecture. It enables protocol conversion, data routing, and security management between heterogeneous networks and serves as the technological foundation for vehicle intelligence and connectivity. For example, the central gateway can connect to multiple different controllers, which can connect to sensors, motors, hydraulic mechanisms, and other components. This allows them to collect data or respond to control commands to take action. The controllers can generate messages from the data collected by the sensors and send them to the central gateway. The central gateway can generate messages from the control commands and send them to the controllers to control the motors, hydraulic mechanisms, and other components. The central gateway can also forward messages from one controller to another, thereby enabling communication between different controllers.

[0018] Support Vector Machine (SVM) is a type of generalized linear classifier that performs binary classification of data using supervised learning. It can also perform non-linear classification using kernel methods.

[0019] Decision Tree (DT) is a decision analysis method that, based on the known probabilities of various scenarios, constructs decision branches to calculate the probability that the expected net present value is greater than or equal to zero. It is used to evaluate project risk and determine its feasibility. Because the decision branches are drawn graphically like the branches of a tree, it is called a decision tree. In machine learning, a decision tree is a predictive model that represents a mapping relationship between object attributes and object values.

[0020] In this embodiment, the structure of the vehicular network with abnormal wake-up detection is as follows: Figure 1 As shown. (Refer to...) Figure 1 The in-vehicle network with abnormal wake-up detection includes a central gateway and multiple controllers such as Controller 1 and Controller 2. These controllers communicate with the central gateway via CAN bus or other means. (See reference...) Figure 2 Taking controller 1 as an example, controller 1 can connect to moving parts such as motors and sensors, thus forming an integrated vehicle-mounted device as shown in the dashed box. The central gateway manages the data exchange between the controllers. For example, when controller 1 needs to send data to controller 2, controller 1 can send the data to the central gateway, and the central gateway will then send the data to controller 2.

[0021] In this embodiment, the central gateway has functions such as communication, data processing, and control. For example... Figure 3 As shown, the central gateway can perform the following steps: S1. In sleep mode, acquire message data sent by the woken controller; S2. Use a behavior detection model to detect the message data and obtain the wake-up behavior pattern of the message data.

[0022] In this embodiment, the central gateway can execute steps S1-S2 when it detects that each controller has entered sleep mode, or actively controls each controller to enter sleep mode. Sleep mode is the default sleep state for each controller; that is, each controller is in sleep mode by default, suspending multiple functions and only retaining basic data detection and judgment functions, thereby maintaining low energy consumption. For example, when a controller is in sleep mode, it can only call its connected sensors for data detection. The controller can quickly exit sleep mode based on the detected data; for example, when a controller calls its sensor and detects that a certain data is too high, the controller exits sleep mode, meaning the controller is woken up by the detected data.

[0023] When a controller is woken up, it can immediately send message data to the central gateway. In this embodiment, a message data sent by a controller may include a timestamp, message content, and source controller ID. The timestamp indicates the time when the controller generated the message data. The message content may contain the controller's identification result of the event that woke it up, such as the event type (specifically, "overheating") and level (specifically, "slightly overheating"). The source controller ID represents the ID information of the controller that generated and sent the message data. The message content is identified by the controller, and the event type it represents (e.g., "overheating") may be factual, meaning that an "overheating" event actually occurred and was detected by the controller, thus waking it up. Alternatively, it may not be factual, meaning that no "overheating" event actually occurred, but the controller was mistakenly woken up due to abnormal reasons such as excessive sensitivity or line failure.

[0024] If no controller generates or sends message data, the central gateway may skip step S1. If a controller generates and sends message data, the central gateway executes step S1 to receive the message data sent by the controller.

[0025] In this embodiment, when the central gateway performs step S1, which is to obtain the message data sent by the woken-up controller in sleep mode, it can specifically perform the following steps: S101. During the first time period in sleep mode, collect the message data sent by each controller that is woken up.

[0026] In step S101, the first time period is a specific continuous time period during which the central gateway continuously collects message data sent by each woke-up controller. During the first time period, the central gateway can buffer the message data sent by the woke-up controller until the end of the first time period before proceeding with subsequent processing.

[0027] For example, refer to Figure 4 Assuming that within the first time period, controller 1 sends message data 1, controller 6 sends message data 6, and controller 8 sends message data 8, then the central gateway can obtain message data 1, message data 6, and message data 8 as the result of executing step S101.

[0028] After the central gateway completes step S1, it proceeds to step S2, referring to... Figure 5 The central gateway uses a behavior detection model to detect message data and obtain the wake-up behavior pattern of the message data.

[0029] In this embodiment, the behavior detection model used by the central gateway in step S2 can be a frequency detection model. When the behavior detection model detects that the sending frequency of the message data is higher than the frequency threshold, the wake-up behavior mode of the message data is determined to be an abnormal mode.

[0030] In this embodiment, the behavior detection model used by the central gateway in step S2 can specifically be a support vector machine or a decision tree.

[0031] In this embodiment, the principle of step S2 is as follows: Figure 5 As shown. (Refer to...) Figure 5 Taking the processing of message data 1 using a support vector machine as the behavior detection model as an example, the central gateway can directly obtain the trained behavior detection model, or... Figure 5 As shown, normal samples are used to train the behavior detection model, enabling it to obtain appropriate classification boundaries. Normal samples refer to data whose content is of the same type as message data 1 (including timestamps, message content, and source controller ID, etc.), and which are confirmed to correspond to "normal wake-up" (i.e., confirming that the "overheating" event described by the normal sample is a real occurrence). The behavior detection model trained on normal samples learns their features and has the ability to identify whether an input message contains features identical to those of a normal sample, thus determining whether the input message corresponds to the same type as the normal sample (i.e., both correspond to "normal wake-up").

[0032] For example, in step S2, such as Figure 5As shown, the behavior detection model identifies message data 1. If it identifies the same features as normal samples in message data 1, the behavior detection model can determine that message data 1 corresponds to the same type as normal samples, that is, both correspond to "normal wake-up". This means that the event that triggers controller 1 to detect message data 1 and wake up message data 1 (e.g., "overheating") is real, and the behavior detection model outputs the wake-up behavior pattern of "normal mode". Conversely, if it does not identify the same features as normal samples in message data 1, the behavior detection model can determine that message data 1 corresponds to a different type than normal samples, that is, message data 1 corresponds to "abnormal wake-up". This means that the event that triggers controller 1 to detect message data 1 and wake up message data 1 (e.g., "overheating") is not real, but is due to controller 1 being overly sensitive or a line fault causing controller 1 to be mistakenly woken up, and the behavior detection model outputs the wake-up behavior pattern of "abnormal mode".

[0033] The in-vehicle network with abnormal wake-up detection in this embodiment can detect the message data sent by the controller when it is woken up in sleep mode by executing steps S1-S2. This allows the network to determine the wake-up behavior mode corresponding to the message data. For example, if the wake-up behavior mode is determined to be "normal mode", it means that the event detected and woken up by the controller may have actually occurred. If the wake-up behavior mode is determined to be "abnormal mode", it means that the event detected and woken up by the controller may not have actually occurred, but was caused by misjudgment or malfunction. This allows the network to analyze the wake-up events of multiple controllers in sleep mode in the vehicle. By determining the wake-up behavior mode, it can determine whether the event that wakes up the controller is normal mode (actually occurred) or abnormal mode (not actually occurred, but caused by malfunction or other abnormal reasons). This can distinguish between normal and abnormal wake-up of the controller, discover the fault source behind the abnormal wake-up, and help eliminate potential safety hazards.

[0034] In this embodiment, the central gateway can use common normal samples from the database to train the behavior detection model.

[0035] In this embodiment, when the central gateway performs step S2, which is to use the behavior detection model to detect the packet data and obtain the wake-up behavior pattern of the packet data, the following steps can be performed: S201. Traverse multiple combinations of abnormal controllers to be identified, and perform a corresponding detection process for each combination of abnormal controllers to be identified; wherein any detection process includes the following steps: S20101. Determine at least one controller from each controller to form the combination of abnormal controllers to be identified in this detection process; S20102. Obtain the normal controller combination to be identified corresponding to this detection process; the normal controller combination to be identified includes all controllers except the abnormal controller combination to be identified. S20103. Obtain message data from the combination of normal controllers to be identified, and use it as normal samples to train the behavior detection model; S20104. Obtain message data from the combination of abnormal controllers to be identified, input it into the behavior detection model for processing, and obtain the wake-up behavior pattern of the message data of each controller in the combination of abnormal controllers to be identified, which is used as the detection result of this detection process.

[0036] S202. Based on the detection results of each detection process, determine the wake-up behavior pattern of each message data.

[0037] The principle of steps S201-S202 is as follows: Figure 6 As shown.

[0038] Reference Figure 6 The central gateway collects message data sent by multiple controllers within the first time period. Assuming that controller 1, controller 2... controller 8, etc. are all controllers that have been awakened and sent message data to the central gateway, they form "all controllers".

[0039] Reference Figure 6 Steps S201-S202 involve selecting controllers from the "all controllers" in quantities equal to the estimated number to form a combination of controllers to be identified as abnormal, while the remaining controllers form a combination of controllers to be identified as normal. This allows for multiple combinations, resulting in multiple combinations of controllers to be identified as abnormal. Each combination of controllers to be identified has a corresponding combination of controllers to be identified as normal. Step S201 involves iterating through all combinations of controllers to be identified as abnormal (and simultaneously iterating through all combinations of controllers to be identified as normal), performing a detection process for each combination of controllers to be identified as abnormal (and its corresponding combination of normal).

[0040] Let's take one of the testing processes as an example for illustration. (Refer to...) Figure 6 Assuming the estimated number is 2, meaning the combination of abnormal controllers to be identified contains 2 controllers, in step S20101, controller 1 and controller 7 are selected from all controllers to form the combination of abnormal controllers to be identified for this detection process. Meanwhile, in step S20102, the other controllers, namely controller 2, controller 3, controller 4, controller 5, controller 6 and controller 8, form the combination of normal controllers to be identified for this detection process.

[0041] In step S20103, message data from the combination of normal controllers to be identified is acquired and used as normal samples to train the behavior detection model. Specifically, refer to... Figure 6 The behavior detection model is trained using message data 2 from controller 2, message data 3 from controller 3, message data 4 from controller 4, message data 5 from controller 5, message data 6 from controller 6, and message data 8 from controller 8 as normal samples. After training is complete, step S20104 is executed.

[0042] In step S20104, refer to Figure 6 The system acquires message data from the combination of controllers to be identified as abnormal, inputs it into the behavior detection model for processing, and obtains the wake-up behavior pattern of the message data of each controller in the combination of controllers to be identified as abnormal. For example, Figure 6 In this process, the message data of controller 1 is input into the trained behavior detection model to identify the wake-up behavior pattern of controller 1 (specifically, normal mode or abnormal mode) identified in this detection process; the message data of controller 7 is input into the trained behavior detection model to identify the wake-up behavior pattern of controller 7 (specifically, normal mode or abnormal mode) identified in this detection process; the wake-up behavior patterns of controller 1 and controller 7 are used as the detection results of this detection process.

[0043] Reference Figure 6 After performing steps S20101-S20104 (the current detection process) on the abnormal controller combination to be identified, namely "controller 1 and controller 7", it is checked whether all abnormal controller combinations to be identified have been traversed (specifically, combinations formed by selecting controllers with a number equal to the estimated number from all controllers). If not, the next detection process is executed. In the next detection process, the abnormal controller combination to be identified is updated (for example, it becomes the combination of controller 1 and controller 8), and the normal controller combination to be identified is also updated accordingly... until all abnormal controller combinations to be identified have been traversed.

[0044] After traversing all combinations of abnormal controllers to be identified, multiple detection processes have been performed. During these processes, the message data sent by each controller is input into the behavior detection model as the message data corresponding to the abnormal controller combination to be identified, to detect the wake-up behavior pattern. In step S202, a voting method can be used to count the total number of votes for each message data whose wake-up behavior pattern is identified as an "abnormal mode" after all detection processes have been performed. The wake-up behavior pattern of the message data with the highest total number of votes is determined as an abnormal mode, while the wake-up behavior patterns of other message data are determined as normal modes (even if these message data may also be detected as "abnormal modes" in some detection processes).

[0045] For example, refer to Figure 7 Assuming that after multiple detection processes, each message data is input into the behavior detection model n times for wake-up behavior pattern detection, the total number of votes for message data 1-8 identified as "abnormal mode" is A to H respectively, and the total number of votes for being identified as "normal mode" is nA to nH respectively, where D is the maximum value among A to H. Then in step S202, message data 4 corresponding to D is determined as abnormal mode, and other message data are determined as normal mode.

[0046] In this embodiment, each detection process during steps S201-S202 can be executed independently and in parallel. For example, each detection process trains a new behavior detection model, rather than continuing to train the behavior detection model trained in the previous detection process.

[0047] In this embodiment, the principle behind steps S201-S202 is as follows: the selected combination of normal controllers to be identified in each detection process is a controller that is assumed to generate normal samples, i.e., a controller that is assumed to be normally awakened, while the corresponding combination of abnormal controllers to be identified is a controller that is assumed to be abnormally awakened. This ensures that sufficient normal samples are generated in each detection process to train the behavior detection model. It utilizes the statistical principle that "among controllers awakened within a certain period, most are normally awakened and a few are abnormally awakened," meaning that the controllers identified as part of the combination of abnormal controllers to be identified in each detection process are used to identify their "abnormal patterns." The result only indicates that the message data of this controller was identified as having different characteristics from most other message data during this detection process, and does not represent the final identification result. After all the behavior detection models have been executed, the message data with the largest total number of votes for being identified as "abnormal mode" in each detection process determined by the voting method is the message data with the greatest difference in characteristics from other message data. According to the statistical principle that "among controllers that are woken up within a period of time, most are normal wake-ups and a few are abnormal wake-ups", the message data (controller) can be identified as belonging to "abnormal mode", while the other message data (controller) is "normal mode".

[0048] In this embodiment, the estimated number used to determine the number of controllers in the combination of abnormal controllers to be identified can be a fixed value, or it can be based on... Figure 8 The aging curve of the vehicle network shown is used to determine this. Figure 8 The aging curve in the diagram represents the proportion of estimated abnormal controllers in the vehicle network as a percentage of all controllers over time. Specifically, it can be a straight line with a positive slope or an exponential curve with a positive exponent. Each time steps S201-S202 are executed, the time frame in the aging curve can be determined based on the vehicle's usage stage (e.g., purchase date or mileage), thereby determining the proportion. Then, based on the proportion and the total number of controllers, the estimated number can be determined.

[0049] By determining the estimated number of controllers in the combination of abnormal controllers to be identified based on the aging curve, the estimated number can be dynamically determined according to the use of the vehicle, thereby enabling the appropriate setting of the number of controllers in the combination of abnormal controllers to be identified and more accurately identifying the wake-up behavior patterns of each controller.

[0050] In this embodiment, in addition to executing steps S1-S2, the central gateway may also execute the following steps: S3. Locate the abnormal controller among multiple controllers based on the wake-up behavior pattern of the message data; S4. Generate an abnormal wake-up detection report based on the abnormality controller.

[0051] In step S3, based on the execution results of steps S201-S202, the message data whose wake-up behavior mode is ultimately identified as "abnormal mode" is determined as abnormal message data, and the controller that sent the abnormal message data is determined as the abnormal controller. The abnormal controller identified in step S3 is a controller identified as having abnormal wake-up, meaning its wake-up is not due to a normally detected actual event, but rather due to an inherent malfunction (such as excessive sensitivity or a line fault causing a misjudgment). Therefore, in step S4, an abnormal wake-up detection report can be generated, recording information such as the abnormal controller's ID, thus locating the abnormal controller. The central gateway can send the abnormal wake-up detection report as an alarm message to vehicle owners, repair service providers, and other personnel, facilitating troubleshooting operations such as monitoring, inspection, repair, and replacement of the abnormal controller, ensuring the normal operation of the vehicle network.

[0052] In this embodiment, the central gateway can execute an abnormal wake-up detection method for the vehicular network, referring to... Figure 3 The abnormal wake-up detection method for vehicular networks includes the following steps: S1. In sleep mode, acquire message data sent by the woken controller; S2. Use a behavior detection model to detect the message data and obtain the wake-up behavior pattern of the message data; the wake-up behavior pattern belongs to the normal mode or the abnormal mode.

[0053] In this embodiment, an abnormal wake-up detection system is also provided, referring to... Figure 9 The abnormal wake-up detection system includes: The first module is used to acquire message data sent by the woken-up controller in sleep mode; The second module is used to detect message data using a behavior detection model to obtain the wake-up behavior pattern of the message data; the wake-up behavior pattern is either a normal mode or an abnormal mode.

[0054] The first and second modules in the vehicle system upgrade system are used to execute steps S1 and S2 in the abnormal wake-up detection method for vehicle networks, respectively, thereby achieving the technical effects of the abnormal wake-up detection method for vehicle networks.

[0055] Please see Figure 10 , Figure 10 The hardware structure of a computer device according to another embodiment is illustrated. The computer device includes: The processor 901 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application. The memory 902 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 902 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 902 and is called and executed by the processor 901 to execute the abnormal wake-up detection method for in-vehicle networks according to the embodiments of this application. The input / output interface 903 is used to implement information input and output; The communication interface 904 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). Bus 905 transmits information between various components of the device (e.g., processor 901, memory 902, input / output interface 903, and communication interface 904); The processor 901, memory 902, input / output interface 903, and communication interface 904 are connected to each other within the device via bus 905.

[0056] Taking the example of a processor and memory in a computer device being connected via a bus, memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the control processor, and these remote memories can be connected to the control device via a network.

[0057] The non-transient software program and instructions required to implement the abnormal wake-up detection method for vehicle networks in the above embodiments are stored in the memory. When executed by the processor, the abnormal wake-up detection method for vehicle networks in the above embodiments is executed.

[0058] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0059] It should be noted that, unless otherwise specified, when a feature is referred to as "fixed" or "connected" to another feature, it can be directly fixed or connected to the other feature, or indirectly fixed or connected to the other feature. Furthermore, the descriptions of "upper," "lower," "left," and "right" used in this disclosure are only relative to the relative positional relationships of the components of this disclosure in the accompanying drawings. The singular forms "a" and "the" used in this disclosure are also intended to include the plural forms, unless the context clearly indicates otherwise. Moreover, unless otherwise defined, all technical and scientific terms used in this embodiment have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in this embodiment specification is only for describing particular embodiments and is not intended to limit the invention. The term "and / or" as used in this embodiment includes any combination of one or more of the associated listed items.

[0060] It should be understood that although the terms first, second, third, etc., may be used to describe various elements in this disclosure, these elements should not be limited to these terms. These terms are only used to distinguish elements of the same type from each other. For example, a first element may also be referred to as a second element without departing from the scope of this disclosure, and similarly, a second element may also be referred to as a first element. The use of any and all instances or exemplary language (“e.g.,” “such as,” etc.) provided in this embodiment is intended only to better illustrate embodiments of the invention and, unless otherwise required, does not impose a limitation on the scope of the invention.

[0061] It should be recognized that embodiments of the present invention can be implemented or carried out by computer hardware, a combination of hardware and software, or by computer instructions stored in a non-transitory computer-readable storage medium. The method can be implemented using standard programming techniques—including a non-transitory computer-readable storage medium configured with a computer program, wherein such a storage medium causes the computer to operate in a specific and predefined manner—according to the methods and drawings described in the specific embodiments. Each program can be implemented in a high-level procedural or object-oriented programming language to communicate with the computer system. However, if desired, the program can be implemented in assembly or machine language. In any case, the language can be a compiled or interpreted language. Furthermore, for this purpose, the program can run on a programmed application-specific integrated circuit (ASIC).

[0062] Furthermore, the procedures described in this embodiment can be performed in any suitable order unless otherwise indicated by this embodiment or otherwise obviously contradict the context. The procedures (or variations and / or combinations thereof) described in this embodiment can be executed under the control of one or more computer systems configured with executable instructions, and can be implemented by hardware or a combination thereof as code (e.g., executable instructions, one or more computer programs, or one or more applications) that commonly executes on one or more processors. A computer program includes a plurality of instructions executable by one or more processors.

[0063] Furthermore, the method can be implemented in any suitable type of computing platform, including but not limited to personal computers, minicomputers, mainframes, workstations, networked or distributed computing environments, standalone or integrated computer platforms, or in communication with charged particle tools or other imaging devices, etc. Aspects of the invention can be implemented as machine-readable code stored on a non-transitory storage medium or device, whether removable or integrated into a computing platform, such as a hard disk, optical read and / or write storage medium, RAM, ROM, etc., such that it is readable by a programmable computer, and when the storage medium or device is read by the computer, it can be used to configure and operate the computer to perform the processes described herein. Furthermore, the machine-readable code, or portions thereof, can be transmitted via wired or wireless networks. The invention of this embodiment includes these and other different types of non-transitory computer-readable storage media when such media comprises instructions or programs that implement the steps above in conjunction with a microprocessor or other data processor. When programmed according to the methods and techniques of the invention, the invention also includes the computer itself.

[0064] A computer program can be applied to input data to perform the functions of this embodiment, thereby transforming the input data to generate output data stored in non-volatile memory. The output information can also be applied to one or more output devices, such as a display. In a preferred embodiment of the invention, the transformed data represents physical and tangible objects, including specific visual depictions of physical and tangible objects generated on the display.

[0065] The above are merely preferred embodiments of the present invention. The present invention is not limited to the above-described embodiments. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention, as long as they achieve the technical effects of the present invention by the same means, should be included within the scope of protection of the present invention. Within the scope of protection of the present invention, the technical solutions and / or implementation methods can have various modifications and variations.

Claims

1. A vehicle-mounted network with abnormal wake-up detection, characterized in that, The in-vehicle network with abnormal wake-up detection includes: Multiple controllers; Central gateway; the central gateway is used to manage data exchange between the controllers, and the central gateway is used to perform the following steps: In sleep mode, the message data sent by the woken controller is acquired; the sleep mode is the default sleep state of each controller. The message data is detected using a behavior detection model to obtain the wake-up behavior pattern of the message data; the wake-up behavior pattern belongs to a normal mode or an abnormal mode.

2. The in-vehicle network with abnormal wake-up detection according to claim 1, characterized in that, In sleep mode, acquiring message data sent by the awakened controller includes: During the first time period in the sleep mode, the message data sent by each of the awakened controllers is collected.

3. The abnormal wake-up detection method for vehicular networks according to claim 2, characterized in that, The step of using a behavior detection model to detect the message data and obtain the wake-up behavior pattern of the message data includes: Iterate through multiple combinations of abnormal controllers to be identified, and perform a corresponding detection process for each combination of abnormal controllers to be identified. Based on the detection results of each detection process, determine the wake-up behavior pattern of each message data; Each of the aforementioned detection processes includes the following steps: At least one controller is determined from each of the controllers to form the combination of the anomaly controllers to be identified in the current detection process; Obtain the normal controller combination to be identified corresponding to the detection process described in this article; the normal controller combination to be identified includes all controllers except the abnormal controller combination to be identified. The message data from the combination of normal controllers to be identified is acquired and used as normal samples to train the behavior detection model; The message data from the combination of abnormal controllers to be identified is obtained, and the data is input into the behavior detection model for processing to obtain the wake-up behavior pattern of the message data of each controller in the combination of abnormal controllers to be identified, which is used as the detection result of the detection process.

4. The abnormal wake-up detection method for vehicular networks according to claim 3, characterized in that, The step of determining the wake-up behavior pattern of each message data based on the detection results of each detection process includes: For any of the aforementioned message data, the total number of votes that the detection process identifies as the abnormal pattern of the message data is determined by a voting method; The wake-up behavior pattern of the message data with the largest total number of votes is determined as the abnormal mode, and the wake-up behavior pattern of the other message data is determined as the normal mode.

5. The abnormal wake-up detection method for vehicular networks according to claim 3, characterized in that, The step of determining at least one controller from each of the controllers to form the combination of anomaly controllers to be identified corresponding to the current detection process includes: Obtain the aging curve of the vehicle network; Based on the aging curve, determine the estimated number of the combination of the anomaly controllers to be identified; Based on the estimated number, a corresponding number of the controllers are determined from each of the controllers to form the group of controllers to be identified as an anomaly.

6. The abnormal wake-up detection method for vehicular networks according to any one of claims 1-5, characterized in that, The central gateway is used to perform the following steps: Based on the wake-up behavior pattern of the message data, locate the abnormal controller among the multiple controllers; An abnormal wake-up detection report is generated based on the abnormality controller.

7. A method for detecting abnormal wake-up in vehicular networks, characterized in that, The in-vehicle network includes multiple controllers, and the abnormal wake-up detection method for the in-vehicle network includes: In sleep mode, acquire message data sent by the awakened controller; The message data is detected using a behavior detection model to obtain the wake-up behavior pattern of the message data; the wake-up behavior pattern belongs to a normal mode or an abnormal mode.

8. A computer device, characterized in that, It includes a memory and a processor, the memory being used to store at least one program, and the processor being used to load at least one program to execute the abnormal wake-up detection method for in-vehicle networks as described in claim 7.

9. A computer-readable storage medium storing a processor-executable program, characterized in that, The processor-executable program, when executed by the processor, is used to perform the abnormal wake-up detection method for vehicular networks as described in claim 7.

10. A vehicle, characterized in that, The vehicle includes an in-vehicle network with abnormal wake-up detection as described in any one of claims 1-6.