Vehicle-mounted network intrusion detection system and method based on BiParc1d-Net model
By combining the BiParc1d-Net model with BiLSTM and Parc1d-Net, the computational complexity and latency issues of the vehicle CAN bus intrusion detection system under complex attack modes are solved, achieving efficient and accurate detection of multiple types of attacks and adapting to changes in the communication modes of different vehicle ECUs.
Patent Information
- Application Number
- CN202510991044.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-18
- Publication Date
- 2025-11-07
AI Technical Summary
Existing vehicle CAN bus intrusion detection systems suffer from high computational complexity, long latency, and difficulty adapting to new attack types when facing complex attack patterns, especially when multiple types of attacks occur simultaneously, resulting in low accuracy.
The BiParc1d-Net model is adopted, which combines a bidirectional long short-term memory network (BiLSTM) and a one-dimensional deep feature analysis network (Parc1d-Net). The BiLSTM extracts temporal features and combines them with message features for binary classification detection. Parc1d-Net is used for multi-class attack classification, which reduces computational complexity and improves detection accuracy.
It achieves efficient intrusion detection in vehicle networks, reduces computational complexity and latency, and improves the detection capability and accuracy against new types of attacks. It adapts to changes in the communication modes of different vehicle ECUs and has good robustness and high detection accuracy.
Smart Images

Figure CN120915495A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of intelligent networked vehicle information security, and in particular relates to a vehicle-mounted network intrusion detection system and method based on a BiParc1d-Net model. BACKGROUND
[0002] With the rapid development of intelligent transportation systems and vehicle networking technologies, the security of vehicle-mounted networks is increasingly prominent. As a core component of intelligent transportation, the in-vehicle network is responsible for communication between various electronic control units (ECUs) in vehicles, especially the controller area network (CAN) based communication system, which is widely used in various electronic subsystems of vehicles. However, the CAN protocol itself lacks authentication of the identities of both parties and message encryption mechanisms, making it vulnerable to various malicious attacks, such as message tampering, impersonation attacks, and denial of service (DoS) attacks.
[0003] Existing vehicle-mounted CAN bus intrusion detection systems (IDSs) can be mainly divided into several categories, including fingerprint-based detection methods, rule-based detection methods, information theory-based detection methods, and machine learning-based detection methods. Fingerprint-based methods detect attacks by identifying specific communication characteristics, such as the signature matching technology used by the MTH-IDS system. Although this method can effectively detect known attacks, it relies on predefined attack signatures, which greatly reduces its detection ability when faced with new, unknown attack patterns. Rule-based methods, such as the SAIDuCANT system, detect low-latency attacks by monitoring the real-time response latency of the CAN bus. However, these methods perform poorly in processing actual attack data and have poor adaptability to new attack patterns.
[0004] With the development of deep learning technologies, neural network-based methods have become an important direction for solving CAN bus security problems. In recent years, researchers have proposed various deep neural network (DNN) based methods to improve the detection ability of IDSs. For example, hybrid models based on convolutional neural networks (CNNs) and recurrent neural networks (RNNs) can effectively extract spatiotemporal features to identify complex attack patterns in CAN buses. However, these methods usually rely on a large amount of training data and require powerful computing resources, which cannot meet the needs of hardware platforms with limited computing power in vehicle-mounted networks. In addition, existing deep learning-based IDS systems have insufficient multi-classification recognition ability for attack types, especially when multiple attack types occur simultaneously, the accuracy is low.
[0005] Currently, the vehicle CAN bus intrusion detection technology still faces many challenges, including high computational complexity, long training time, and difficulty in handling multi-class attacks. With the popularity of the Internet of Vehicles, more and more vehicle devices and external networks are interconnected, and the security threats faced by vehicle networks are increasing. SUMMARY
[0006] In view of the defects that the existing vehicle CAN bus intrusion detection method has complex model, high latency and is difficult to effectively adapt to new attack types, the application provides a vehicle network intrusion detection system and method based on a BiParc1d-Net model. The system combines a bidirectional long short-term memory network (BiLSTM) and a one-dimensional deep feature analysis network (Parc1d-Net), and is optimized for the special needs of vehicle networks. The BiLSTM network focuses on processing the time series data of CAN messages, relying on its forward and backward structures and the forgetting gate mechanism, it can capture the long-term dependencies between messages evolving over time, and strengthen the modeling of dynamic communication behavior characteristics. This mechanism can effectively retain key historical information and improve the recognition accuracy in time series anomaly detection scenarios. The Parc1d-Net network focuses on extracting spatial features and can effectively identify abnormal patterns in data streams. The combination of the two not only improves the accuracy of detection, but also significantly reduces the computational complexity and latency, enabling the system to run efficiently in real-time and resource-constrained environments of vehicle networks.
[0007] In order to achieve the above purpose, the application is realized by the following technical scheme:
[0008] The application is a vehicle network intrusion detection system based on a BiParc1d-Net model. The vehicle network intrusion detection system detects attacks by training a two-stage architecture model, BiParc1d-Net model. The BiParc1d-Net model includes a bidirectional long short-term memory network (BiLSTM) model and a one-dimensional deep feature analysis network (Parc1d-Net) model,
[0009] In the first stage, the bidirectional long short-term memory network (BiLSTM) model extracts the time series features of the controller area network (CAN) bus data, and combines the features extracted by the message feature extraction module of the controller area network (CAN) to perform attack binary classification detection on the controller area network (CAN) bus data, obtaining the attack data of the first stage. In the second stage, the one-dimensional deep feature analysis network (Parc1d-Net) model extracts the spatial features of the controller area network (CAN) data, and performs multi-class attack classification on the attack data identified in the first stage.
[0010] Further improvements of the present application are that the bidirectional long short-term memory network (BiLSTM) model comprises a first BiLSTM layer, a first batch normalization layer, a first Dropout layer, a second BiLSTM layer, a second batch normalization layer, a second Dropout layer and a full connection layer arranged in sequence, the first BiLSTM layer adopts a bidirectional LSTM layer structure, each LSTM layer is composed of 64 hidden units, the first batch normalization layer normalizes the output of the first BiLSTM layer to improve the training stability and convergence speed, and the first Dropout layer is used to prevent overfitting, and the Dropout rate is set to 0.5;
[0011] The second BiLSTM layer adopts a bidirectional LSTM layer structure, each LSTM layer is composed of 32 hidden units, the second batch normalization layer normalizes the output of the second BiLSTM layer to further enhance the stability of the feature representation, and the second Dropout layer is used to prevent overfitting, and the Dropout rate is set to 0.5.
[0012] The full connection layer is used to map the features output by the second BiLSTM layer to the final detection result for binary classification detection.
[0013] Further improvements of the present application are that the message feature extraction module comprises a message data load entropy feature module and a controller area network message ID frequency mean deviation feature module, load entropy features and frequency mean deviation features are extracted through the message data load entropy feature module and the controller area network message ID frequency mean deviation feature module, and feature fusion is performed to construct a complete feature matrix, wherein:
[0014] The message data load entropy feature module analyzes the load bytes of each controller area network (CAN) message and calculates the entropy value according to Shannon information theory, and the formula is:
[0015]
[0016] Wherein, H(X) represents information entropy, P(m i ) represents the byte value m iThe probability of occurrence in the load, M represents the number of different byte values, the calculated entropy value is taken as a feature of each controller area network (CAN) message, and is stored in a feature matrix. The higher the load entropy value, the greater the randomness of the data, and the lower the entropy value, the stronger the regularity of the data. Normal controller area network (CAN) communication usually has a relatively stable entropy value range, while attack behavior causes abnormal changes in entropy value. By measuring the distribution of byte values in the load, the vehicle-mounted network intrusion detection system detects abnormal data patterns that may indicate malicious activities; the message feature extraction module is used to quantify the complexity and randomness of the load data and provide auxiliary feature input for the BiLSTM network.
[0017] The controller area network message ID frequency mean deviation feature module aims to detect abnormal situations in the frequency distribution of messages. By tracking the frequency of each controller area network message ID in a dynamic time window and calculating the frequency deviation of each controller area network message ID from the mean frequency of all controller area network message IDs in the time window, it helps to identify message controller area network (CAN) IDs with abnormal frequency in potential attack scenarios.
[0018] A further improvement of the present application is that the frequency deviation of each controller area network message ID from the mean frequency of all controller area network message IDs in the time window is calculated as follows:
[0019] First, calculate the frequency f of the current controller area network message ID in the time window i :
[0020]
[0021] Where count(i) represents the number of occurrences of the current controller area network message ID in the time window, and w is the size of the time window.
[0022] Second, calculate the average frequency of all controller area network message IDs in the time window
[0023]
[0024] Where f j is the frequency of the jth controller area network message ID in the time window, and n is the number of different controller area network message IDs in the time window.
[0025] Finally, calculate the controller area network message ID frequency mean deviation D f , by comparing the frequency f of the current controller area network message ID with the average frequency to measure the frequency mean deviation:
[0026]
[0027] wherein D f represents the frequency mean deviation, f i represents the frequency of the current CAN message ID in the time window, represents the average frequency of all CAN message IDs in the time window, the module is used for identifying abnormal communication behaviors and frequency patterns in the CAN message.
[0028] The further improvement of the application is that the Parc1d-Net model is used for processing attack data output in the first stage and represented as a one-dimensional feature vector, and the Parc1d-Net model comprises an embedding layer and at least one Parc1d Block module; the embedding layer is used for mapping the input feature vector to a high-dimensional feature space.
[0029] The further improvement of the application is that the one-dimensional deep feature analysis network model, namely the Parc1d-Net, comprises an embedding layer and at least one Parc1d Block module.
[0030] The embedding layer is used for mapping the input feature vector to a high-dimensional feature space.
[0031] The Parc1d Block module is a core calculation unit for deep feature extraction and pattern analysis, the Parc1d Block module adopts a double residual structure and is sequentially connected by a convolution attention submodule and a feedforward network submodule; the convolution attention submodule itself comprises a first normalization layer, a one-dimensional deep separable convolution layer and a channel attention module; the feedforward network submodule comprises a second normalization layer and a feedforward network module, the Parc1d Block module processes the input feature and generates an output feature.
[0032] The further improvement of the application is that the Parc1d Block module processes the input feature and generates an output feature, and the process specifically comprises the following steps:
[0033] Step 1, temporarily storing the input feature received by the Parc1d Block module;
[0034] Step 2, sending the input feature to the convolution attention submodule, in the convolution attention submodule, the input feature first passes through the first normalization layer, and then the normalized feature is sent to the one-dimensional deep separable convolution layer and the channel attention module at the same time, the output of the one-dimensional deep separable convolution layer is multiplied by the attention weight generated by the channel attention module element by element to obtain a weighted feature;
[0035] Step 3, element-wise addition of the weighted features obtained in Step 2 and the input features temporarily stored in Step 1 to obtain the first residual connection result;
[0036] Step 4, temporary storage of the first residual connection result obtained in Step 3;
[0037] Step 5, sending the first residual connection result obtained in Step 4 to the feedforward network sub-module. Inside the feedforward network sub-module, the weighted features obtained in Step 2 first pass through a second normalization layer, and then the normalized features are sent to the feedforward network module for nonlinear transformation;
[0038] Step 6, element-wise addition of the output of the feedforward network module in Step 5 and the first residual connection result temporarily stored in Step 4;
[0039] Step 7, taking the addition result in Step 6 as the final output feature of the Parc1d Block module.
[0040] A further improvement of the present application is that the feedforward network module includes a dimension expansion unit and a dimension recovery unit;
[0041] The dimension expansion unit uses a first 1x1 convolutional layer for expanding the channel dimension and a GELU nonlinear activation function to perform nonlinear mapping on the features fused by the convolutional attention sub-module and the first residual connection, so as to learn higher-dimensional feature representations;
[0042] The dimension recovery unit includes a second 1x1 convolutional layer for recovering the original channel dimension, and can optionally include one or more dropout layers to suppress model overfitting. The features processed by the dimension expansion unit are subjected to channel dimension recovery, and the calculation result is taken as the final output of the feedforward network module to further refine and abstract the deep semantic information of the features.
[0043] A further improvement of the present application is that the one-dimensional depthwise separable convolutional layer is used to independently perform one-dimensional convolution operation on each feature channel to capture local patterns within the features, and the operation process is defined by the following formula:
[0044]
[0045] where Y dw (d,t) is the value of the d-th channel of the output feature map at position t, X norm1 is the input tensor after batch normalization, w dw(d, k) is the depth convolution kernel weight dedicated to the d-th channel, K represents the size of the convolution kernel, k is the position index within the convolution kernel, and p represents the padding added to keep the sequence length consistent.
[0046] A further improvement of the present application is that the channel attention module comprises a Squeeze unit and an Excitation unit, which are specifically implemented as:
[0047] The Squeeze unit adopts an adaptive one-dimensional global average pooling (Adaptive 1D Global Average Pooling) operation to compress the feature map output by the one-dimensional depth separable convolution layer in the sequence dimension, thereby generating a global information descriptor for each feature channel.
[0048] The Excitation unit is used to learn the nonlinear dependence between channels and generate normalized channel weight coefficients, and sequentially comprises a first 1x1 convolution layer for reducing the channel dimension, a ReLU nonlinear activation function, a second 1x1 convolution layer for restoring the original channel dimension, and a Sigmoid activation function; the final output of the channel attention module is to multiply the channel weight coefficients generated by the Excitation unit with the feature map output by the one-dimensional depth separable convolution layer channel by channel, so as to enhance the key feature channels and suppress the non-key feature channels.
[0049] The present application is a vehicle-mounted network intrusion detection method based on a BiParc1d-Net model, which specifically comprises the following steps:
[0050] Step 1, obtain a public data set and preprocess the data, clean, format convert and normalize the CAN message data, specifically:
[0051] Step 1.1, obtain a public Car-Hacking (automobile hacker) data set;
[0052] Step 1.2, data cleaning of CAN message data, including extracting specific columns of CAN message data and adding field names, filling missing values, converting hexadecimal data to decimal, replacing numerical labels, specifically: extract specific columns 1, 3, 4, 5, 6, 7, 8, 9, 10, 11 in CAN message as data, and add corresponding field names 'p1', 'p2', 'p3', 'p4', 'p5', 'p6', 'p7', 'p8' representing each data field in the vehicle controller area network message data, 'Label' column as data label column, then fill in the default value of the missing value; CAN_ID and Data columns use '0000' and '00', Label column uses 'R', then replace all entries with value 'R' in the data column with '0', next convert all hexadecimal strings in the columns to decimal integers, and finally replace the corresponding numerical labels to represent attack data, 1 represents DoS abnormal data, 2 represents Fuzzy abnormal data, 3 represents Gear abnormal data, and 4 represents RPM abnormal data.
[0053] Step 2, generate CAN message data load entropy feature and controller area network message ID frequency mean deviation feature as supplementary original features according to the CAN message data preprocessed in step 1, and perform data standardization processing on the expanded feature matrix. The formula for data standardization is as follows:
[0054]
[0055] Wherein, standardized_data represents the feature matrix after standardization processing, data represents the feature matrix after calculating the CAN message data load entropy feature and the controller area network message ID frequency mean deviation feature in step 2, mean represents the mean of the feature matrix after calculating the CAN message data load entropy feature and the controller area network message ID frequency mean deviation feature in step 2, and std represents the standard deviation of the feature matrix after calculating the CAN message data load entropy feature and the controller area network message ID frequency mean deviation feature in step 2.
[0056] Step 3, input the CAN message data load entropy feature, controller area network message ID frequency mean deviation feature and other time series features, load features extracted in step 2 into the built BiLSTM model, train the BiLSTM model, find the appropriate BiLSTM model hyperparameters and weights, and finally classify the attack data and record; The optimizer used to train the BiLSTM model is Adam optimizer, and the loss function is BCEWithLogitsLoss, i.e. binary cross entropy loss function.
[0057] Step 4: Input the attack data identified by the BiLSTM network into the built Parc1d-Net model, train the Parc1d-Net model, find the appropriate hyperparameters and weights of the Parc1d-Net model, and use the Adam optimizer as the optimizer for training the Parc1d-Net model, the activation function is softmax, and the loss function is CrossEntropyLoss, i.e. cross-entropy loss function.
[0058] Step 5: According to the output results of the Parc1d-Net model, perform multi-class attack classification to determine whether there is an intrusion behavior.
[0059] Step 6: Based on the classification results, output the accuracy and category information of the intrusion detection, and determine whether there is a network attack.
[0060] The beneficial effects of the present application are:
[0061] The data load entropy feature module and the controller area network message ID frequency mean deviation feature module proposed in the present application can effectively capture the abnormal patterns of CAN messages. The load entropy quantifies the complexity and randomness of the data load, enabling the detection system to identify attack behaviors with abnormal load content; the dynamic frequency feature can reflect the frequency anomaly of the controller area network message ID, effectively identifying behaviors such as DoS attacks and replay attacks. This multi-dimensional feature extraction significantly improves the recognition ability of the detection system.
[0062] Through the two-stage vehicle network intrusion detection system based on BiParc1d-Net, the present application achieves high detection accuracy while maintaining computational efficiency. The BiLSTM network in the first stage can quickly identify abnormal behaviors, and the Parc1d-Net network in the second stage can accurately classify the identified abnormalities. Experimental results show that this method achieves high levels in terms of detection accuracy, precision, recall rate, and F1 score, while maintaining low computational overhead.
[0063] The feature extraction method adopted in the present application has good adaptability to changes in CAN bus communication patterns. Through dynamic time window frequency analysis and load entropy calculation, it can adapt to differences in communication patterns of different vehicle ECUs, has strong detection ability for new types of attacks, and improves the robustness of the system in complex environments.
[0064] The performance of the BiParc1d-Net model is comprehensively evaluated in this application, covering multiple indicators such as accuracy, recall rate, F1 score, etc. By multiplying the performance results of the first and second stages, the model's excellent performance in various indicators is obtained. The experimental results show that the model has achieved 99.99%, 99.99%, 99.99%, and 99.99% in accuracy, precision, recall rate, and F1 score, respectively. These results indicate that the BiParc1d-Net model has excellent performance in vehicle network intrusion detection, can accurately identify malicious traffic in the Internet of Vehicles, effectively ensure the safety of vehicle driving, and demonstrate its significant advantages in the field of intelligent transportation and Internet of Vehicles security. BRIEF DESCRIPTION OF DRAWINGS
[0065] Figure 1 is the overall architecture diagram of the intrusion detection system model of the present application.
[0066] Figure 2 is the flowchart of the training of the intrusion detection system model of the present application.
[0067] Figure 3 is the confusion matrix of the predicted label and the real label. DETAILED DESCRIPTION
[0068] The embodiments of the present application will be described below with reference to the drawings. Many practical details will be described in the following description for the purpose of clear illustration. However, it should be understood that these practical details should not be used to limit the present application. That is, in some embodiments of the present application, these practical details are not necessary. In addition, for the purpose of simplifying the drawings, some conventional structures and components will be shown in the drawings in a simple schematic manner.
[0069] As Figure 1As shown, the application is a vehicle-mounted network intrusion detection system based on a BiParc1d-Net model, which detects attacks by training a two-stage architecture model, i.e., a BiParc1d-Net model. The BiParc1d-Net model includes a bidirectional long short-term memory network (BiLSTM) model and a one-dimensional deep feature analysis network (Parc1d-Net) model. In the first stage, the bidirectional long short-term memory network (BiLSTM) model is used to extract the time sequence features of the vehicle controller area network (CAN) bus data, and the attack binary classification detection is performed on the controller area network (CAN) bus data combined with the features extracted by the controller area network (CAN) message feature extraction module, to obtain the attack data of the first stage. In the second stage, the one-dimensional deep feature analysis network (Parc1d-Net) model is used to extract the spatial features of the controller area network (CAN) data, and the multi-class attack classification is performed on the attack data identified in the first stage.
[0070] The bidirectional long short-term memory network (BiLSTM) model includes a first BiLSTM layer, a first batch normalization layer, a first Dropout layer, a second BiLSTM layer, a second batch normalization layer, a second Dropout layer, and a full connection layer arranged in sequence. The first BiLSTM layer adopts a bidirectional LSTM layer structure, each LSTM layer is composed of 64 hidden units, the first batch normalization layer normalizes the output of the first BiLSTM layer to improve the training stability and convergence speed, and the first Dropout layer is used to prevent overfitting with a Dropout rate of 0.5.
[0071] The second BiLSTM layer adopts a bidirectional LSTM layer structure, each LSTM layer is composed of 32 hidden units, the second batch normalization layer normalizes the output of the second BiLSTM layer to further enhance the stability of feature representation, and the second Dropout layer is used to prevent overfitting with a Dropout rate of 0.5.
[0072] The full connection layer is used to map the features processed by the second BiLSTM layer to the final detection result for binary classification detection.
[0073] The application adopts batch normalization (BN) to process data, significantly stabilizes the network training process, accelerates model convergence, and reduces the sensitivity to parameter initialization. The normalization layer is followed by a Dropout layer, which randomly discards part of the neurons at a rate of 0.5, effectively preventing network overfitting and enhancing the generalization ability of the model. Finally, the feature is mapped to the output space through the fully connected layer, and the BCEWithLogitsLoss is used as the loss function, which combines the Sigmoid activation and binary cross-entropy loss into one operation, which has advantages in numerical stability and computational efficiency. This hierarchical design not only enhances the network's ability to extract time series features, but also maintains the model's sensitivity to abnormal samples, providing a high-precision discrimination basis for vehicle CAN bus intrusion detection.
[0074] The one-dimensional deep feature analysis network model, namely Parc1d-Net, comprises an embedding layer and at least one Parc1dBlock module; the embedding layer is used to map the input feature vector to a high-dimensional feature space; the Parc1dBlock module is a core calculation unit for deep feature extraction and pattern analysis, which adopts a double residual structure and is sequentially connected by a convolution attention submodule and a feedforward network submodule; the convolution attention submodule itself comprises a first normalization layer, a one-dimensional deep separable convolution layer and a channel attention module; the feedforward network submodule comprises a second normalization layer and a feedforward network module, and the Parc1dBlock module processes the input features and generates output features.
[0075] The process of processing the input features by the Parc1d Block module and generating the output features, specifically comprising the following steps:
[0076] Step 1, temporarily storing the input features received by the Parc1d Block module;
[0077] Step 2, inputting the input features into the convolution attention submodule, in which the input features first pass through the first normalization layer, and then the normalized features are simultaneously input into the one-dimensional deep separable convolution layer and the channel attention module, the output of the one-dimensional deep separable convolution layer is multiplied by the attention weight generated by the channel attention module element by element, and the weighted features are obtained;
[0078] Step 3, element-wise adding the weighted features obtained in step 2 and the input features temporarily stored in step 1 to obtain the first residual connection result;
[0079] Step 4, the first residual connection result obtained in step 3 is temporarily stored;
[0080] Step 5, the first residual connection result obtained in step 4 is sent to the feedforward network submodule, and in the feedforward network submodule, the weighted features obtained in step 2 are first subjected to a second normalization layer, and then the normalized features are sent to the feedforward network module for nonlinear transformation;
[0081] Step 6, the output of the feedforward network module in step 5 is element-wise added to the first residual connection result temporarily stored in step 4;
[0082] Step 7, the addition result in step 6 is taken as the final output feature of the Parc1d Block module.
[0083] The feedforward network module includes a dimension expansion unit and a dimension recovery unit; the dimension expansion unit adopts a first 1x1 convolution layer for expanding the channel dimension and a GELU nonlinear activation function, and performs nonlinear mapping on the features fused by the convolution attention submodule and the first residual connection, so as to learn a higher-dimensional feature representation; the dimension recovery unit includes a second 1x1 convolution layer for recovering the original channel dimension, and can selectively include one or more dropout layers to suppress model overfitting; the features processed by the dimension expansion unit are subjected to channel dimension recovery, and the calculation result is taken as the final output of the feedforward network module, so as to further refine and abstract the deep semantic information of the features.
[0084] The message feature extraction module includes a message data load entropy feature module and a controller area network message ID frequency mean deviation feature module, and the load entropy feature and the frequency mean deviation feature are extracted by the message data load entropy feature module and the controller area network message ID frequency mean deviation feature module, and then the features are fused to construct a complete feature matrix.
[0085] The process of load entropy feature extraction is as follows:
[0086] (1) First, the effective payload field is extracted from the preprocessed CAN message data. For each CAN message, the payload_columns parameter specifies the effective payload part, including 'p1', 'p2', 'p3', 'p4', 'p5', 'p6', 'p7', 'p8', etc. fields, which correspond to different positions of data information in the CAN message.
[0087] (2) Calculate the entropy value of the load data of each CAN message. In this step, the system first regards the extracted load value as byte data, simulates the actual byte data by mapping the value to the interval range of 0-255, and then counts the frequency of each byte value, i.e., the probability distribution p(x i ) of the byte value.
[0088] (3) Calculate the entropy value of the load data of each message according to the information entropy calculation formula. The information entropy calculation formula is:
[0089]
[0090] where H(X) represents the information entropy, P(m i ) represents the probability of the byte value m i appearing in the load, and M represents the number of different byte values.
[0091] (4) The calculated entropy value is stored in the feature matrix as one of the characteristics of each CAN message. The higher the load entropy value, the greater the randomness of the data, and the lower the entropy value, the stronger the regularity of the data. Normal CAN communication usually has a relatively stable entropy value range, while attack behavior causes abnormal changes in the entropy value. By measuring the distribution of byte values in the load, the vehicle network intrusion detection system detects abnormal data patterns that may indicate malicious activities. The message feature extraction module is used to quantify the complexity and randomness of the load data and provide auxiliary feature input for the BiLSTM network.
[0092] The CAN message ID frequency mean deviation feature module aims to detect abnormal situations in the frequency distribution of the message. By tracking the frequency of each CAN message ID in a dynamic time window and calculating the frequency deviation of each CAN message ID from the mean frequency of all CAN message IDs in the time window, it helps to identify CAN message IDs with abnormal frequency in potential attack scenarios.
[0093] The extraction process of the frequency of the CAN message ID is performed according to the following steps:
[0094] (1) Time series analysis based on dynamic sliding window mechanism. For each CAN message in the data stream, the system defines a time window with a fixed length of window_size = 30, i.e., the same length as the sequence, which contains the current message and a number of messages before it.
[0095] (2) For each CAN message in the time window, first extract its ID identifier, which is specified by the id_column parameter, usually the 'AID' field, then calculate the number of occurrences of the current CAN message ID in the time window, and divide by the size of the time window to obtain the occurrence frequency f of the ID i .
[0096] (3) At the same time, count all the CAN message IDs that appear in the time window and their occurrence frequencies, calculate the frequency distribution of each ID, and calculate the average of all ID frequencies
[0097] (4) According to the frequency average deviation calculation formula, calculate the occurrence frequency f of the current CAN message ID in the time window i , the average frequency of all CAN message IDs in the time window , and the frequency average deviation D of the current CAN message ID f , specifically:
[0098] First, calculate the occurrence frequency f of the current CAN message ID in the time window i :
[0099]
[0100] Where count(i) represents the number of occurrences of the current CAN message ID in the time window, and w is the size of the time window.
[0101] Second, calculate the average frequency of all CAN message IDs in the time window
[0102]
[0103] Where f j is the frequency of the jth CAN message ID in the time window, and n is the number of different CAN message IDs in the time window.
[0104] Finally, calculate the CAN message ID frequency average deviation D f , by comparing the frequency f of the current CAN message ID with the average frequency of all CAN message IDs in the time window to measure the frequency average deviation:
[0105]
[0106] Where D f represents the frequency average deviation, and f irepresents the frequency of the current CAN message ID in the time window, represents the average frequency of all CAN message IDs in the time window. This module is used to identify abnormal communication behavior and frequency patterns in CAN messages.
[0107] (5) The calculated frequency mean deviation is added to the feature matrix as another important feature of the CAN message. The frequency mean deviation can reflect the degree of abnormality of the frequency of the CAN message ID, and help identify attack behaviors such as DoS attacks, replay attacks, etc. that exhibit abnormal frequencies.
[0108] After completing the extraction of the load entropy feature and the frequency mean deviation feature, the following feature fusion and preprocessing steps are performed:
[0109] (1) The extracted load entropy feature and frequency mean deviation feature are fused with the original CAN message data such as 'p1' to 'p8' field values to construct a complete feature matrix.
[0110] (2) The feature matrix is standardized to distribute the feature values within the same numerical range, avoiding certain features from dominating the model training process due to their large value range. The standardization process uses the following formula:
[0111]
[0112] where standardized_data is the standardized feature value, data is the original feature value, mean is the mean of the feature, and std is the standard deviation of the feature.
[0113] (3) The standardized feature matrix is reorganized according to the time sequence to construct a sequence data structure suitable for BiLSTM network input, with each sequence containing sequence_length length of consecutive CAN message features.
[0114] Through the above feature extraction steps, the present application establishes a feature representation system that can effectively capture CAN bus communication anomalies. The load entropy feature focuses on quantifying the complexity and randomness of data content, while the ID frequency mean deviation feature focuses on the timing pattern of communication behavior. The two features complement each other and provide rich feature input for the subsequent BiLSTM network, enhancing the model's ability to identify various attack behaviors.
[0115] The core of the Parc1d-Net is its Parc1d Block module. This module abandons the structure in traditional two-dimensional convolutional networks that is not suitable for one-dimensional sequences, and is designed specifically for in-depth analysis of one-dimensional feature vectors corresponding to a single CAN message. It aims to deeply mine the complex patterns inside the feature vector through a series of ingenious calculation steps, thereby achieving accurate differentiation of different attack types.
[0116] The core calculation steps of the Parc1d Block module for processing input features are as follows:
[0117] Step 1: After receiving the one-dimensional feature vector X_input representing the abnormal message, the module first sends it to a batch normalization layer (BN) to obtain the normalized feature X_norm1. This step aims to stabilize and speed up the network training process.
[0118] Step 2: The normalized feature X_norm1 is input into a one-dimensional deep separable convolution layer. The number of groups of the convolution kernel of this convolution layer is set to equal the dimension D of the input feature, so that the convolution operation is performed independently on each feature channel to efficiently capture the local dependency within the feature. The output of this step is the feature map U, whose operation process is defined by the following formula:
[0119]
[0120] Where the value of U at the dth channel and position t is Y_dw(d, t)
[0121] Step 3: To dynamically learn and enhance the expression of key feature channels, the feature map U is sent to a channel attention module (SE Block). The processing process of this module can be divided into:
[0122] Step 3.1: An adaptive one-dimensional global average pooling is used to operate on the feature map U, compressing the global spatial information of each channel into a single numerical value to obtain a channel descriptor with a dimension of D x 1.
[0123] Step 3.2: The channel descriptor is sequentially sent to a first 1x1 convolution layer for dimension reduction (the number of channels is reduced from D to D / 4), a ReLU activation function, a second 1x1 convolution layer for dimension increase (the number of channels is restored from D / 4 to D), and finally a Sigmoid activation function to generate a channel weight vector w with a dimension of D x 1. Each element in the vector w has a value domain between 0 and 1, representing the importance of the corresponding channel.
[0124] Step 3.3: Perform channel-wise multiplication (Broadcasted Element-wise Multiplication) on the feature map U output from Step 2 and the channel weight vector w generated in Step 3b to obtain the recalibrated feature map U'. The formula can be expressed as:
[0125] U ′ (d,t)=w(d) * U(d,t) where w(d) is the d-th element of vector w.
[0126] Step 4: Add the recalibrated feature map U' output from Step 3 element-wise to the input feature map X_input from Step 1, completing the first residual connection. This design aims to fuse the original information with the information processed by convolution and attention, preventing gradient vanishing. Its output X_res1 can be expressed as:
[0127] X_res1=X_input+U'
[0128] Step 5: To further enhance the model's representational power, the output X_res1 of the first residual connection is fed into a feedforward network module (FFN). This module first performs batch normalization (BN) on the input, then sequentially passes it through: a first 1x1 convolutional layer to expand the channel dimension from D to 2D, a GELU non-linear activation function, a Dropout layer, a second 1x1 convolutional layer to compress the channel dimension from 2D back to D, and a second Dropout layer. The Dropout layer is used for regularization to prevent overfitting. The output of this step is Y_ffn.
[0129] Step 6: Add the feature Y_ffn output from Step 5 element-wise to the input X_res1 of this step, completing the second residual connection. This connection ensures smooth information transfer even in deep networks. The final output X_output of this Parc1d Block module can be expressed as:
[0130] X output =X res1 +Y ffn
[0131] like Figure 2 As shown, this application presents a vehicle network intrusion detection method based on the BiParc1d-Net model, which specifically includes the following steps:
[0132] Step 1: Obtain the publicly available dataset and preprocess the data, including cleaning, format conversion, and normalization of the CAN message data; specifically, the following steps are included:
[0133] Step 1.1, obtain the public Car-Hacking dataset;
[0134] Step 1.2, data cleaning of CAN message data, including extracting specific columns of CAN message data and adding field names, filling missing values, converting hexadecimal represented data to decimal, replacing numerical labels, specifically: extracting specific columns 1, 3, 4, 5, 6, 7, 8, 9, 10, 11 in CAN message as data, and adding corresponding field names 'p1', 'p2', 'p3', 'p4', 'p5', 'p6', 'p7', 'p8' representing each data field in the vehicle controller area network message data, 'Label' column as the label column of data, and filling the default value of missing values; CAN_ID and Data columns use '0000' and '00', Label column uses 'R', and then replace all entries with value 'R' in the data column with '0', next convert all hexadecimal strings in the columns to decimal integers, and finally replace the corresponding numerical labels to represent attack data, 1 represents DoS abnormal data, 2 represents Fuzzy abnormal data, 3 represents Gear abnormal data, and 4 represents RPM abnormal data.
[0135] Specifically, the data cleaned by step 1.2 has distinguished normal data and the remaining four types of abnormal data flow. Due to the large amount of data, this embodiment uses stratified sampling method to sample the data to ensure the distribution ratio of each type of data in the training set and the test set is consistent. Specifically, use the train_test_split function to divide the data, set test_size = 0.7, stratify = data['attack'] parameter, ensure stratified sampling according to the label of attack type, maintain the distribution ratio of each category in the original data, and save the extracted data for subsequent use.
[0136] Step 2, generate CAN message data load entropy features and controller area network message ID frequency mean deviation features as supplementary original features according to the CAN message data preprocessed by step 1, and perform data standardization processing on the supplemented feature matrix;
[0137] Step 3, input the CAN message data load entropy features, controller area network message ID frequency mean deviation features and other time series features, load features extracted in step 2 into the built BiLSTM model, train the BiLSTM model, find the appropriate BiLSTM model hyperparameters and weights, and finally classify the attack data and record. The hyperparameter settings of the BiLSTM model training are as follows Table 1;
[0138] Table 1 BiLSTM model hyperparameter settings
[0139] Hyperparameters for training Values Learning rate 0.01 Loss function BCEWithLogitsLoss loss function Optimizer Adam optimizer Batch size 256 Training epochs 5
[0140] Step 4: input the attack data identified by the BiLSTM network into the built Parc1d-Net model, train the Parc1d-Net model, and find the hyperparameters and weights suitable for the Parc1d-Net model. The hyperparameters of the Parc1d-Net model training are set as shown in Table 2.
[0141] Table 2 Parc1d-Net model hyperparameter settings
[0142] Hyperparameters for training Values Learning rate 0.01 Loss function CrossEntropyLoss loss function Optimizer Adam optimizer Batch size 64 Training epochs 5
[0143] In the model training process, the performance of the model is continuously optimized and evaluated, the optimal parameters and weights are determined, and these parameters and weights are saved to the specified path. For subsequent use.
[0144] In this embodiment, the trained BiLSTM and Parc1d-Net combined two-stage model is evaluated for prediction, and the evaluation indicators are set as accuracy, precision, recall, and F1-score, and the calculation formulas are as follows:
[0145]
[0146] Among them, TP represents the number of positive class samples (normal data) correctly predicted by the model, TN represents the number of negative class samples (abnormal data) correctly predicted by the model, FP represents the number of negative class samples incorrectly predicted as positive class samples by the model, and FN represents the number of positive class samples incorrectly predicted as negative class samples by the model.
[0147] The application also tests the accuracy, precision, recall, and F1 score of KNN (nearest neighbor algorithm), SVM (support vector machine), DCNN (deep convolutional neural network), and CANet (An unsupervised intrusion detection system for high dimensional CAN bus data published model) on the Car-hacking data set. The results are shown in Table 3.
[0148] Table 3 Experimental results of each model on Car-hacking
[0149] Model Accuracy Recall Precision F1 score The present application 0.9999 0.9999 0.9999 0.9999 KNN 0.9741 0.9673 0.9632 0.9344 SVM 0.9650 0.9580 0.9570 0.9337 DCNN 0.9993 0.9984 0.9984 0.9991 CANet 0.9875 0.9875 0.9909 0.9889
[0150] The application is excellent in accuracy, precision, recall rate and F1-score, and the model performance is outstanding. The accuracy is 0.0258, 0.0349, 0.0021 and 0.0124 higher than KNN, SVM, DCNN and CANet respectively. The F1 score is 0.0652, 0.0659, 0.0030 and 0.0107 higher than KNN, SVM, DCNN and CANet respectively. Moreover Figure 3 The confusion matrix obtained by using ParC to implement attack multi-classification on the attack data of binary classification further proves that the BiParc1d-Net two-stage model has excellent ability to distinguish various attack categories.
[0151] In addition, the application also evaluates the number of parameters, parameter memory, throughput rate and average processing time of BiParc1d-Net, and the results are shown in Table 4 as follows:
[0152] Table 4 BiParc1d-Net model performance evaluation results
[0153] Parameter number Memory size (MB) Throughput (samples / s) Average processing time (ms) 81641 0.52 37858.79 0.05
[0154] As can be seen from Table 4, the application shows excellent performance indicators in the evaluation process: the number of parameters is 81641, and the memory usage is only 0.52MB, showing low resource consumption; the throughput rate of the model reaches 37858.79 samples / second, and the average time of batch processing is 0.05 milliseconds, embodying high processing capacity and fast response speed.
[0155] In order to verify the importance of the CAN message data load entropy feature (referred to as "LEF") and the controller area network message ID frequency mean deviation feature (referred to as "IDF"), the application carries out a feature module ablation experiment on the CarHacking data set. The experimental results are shown in Table 5, and through the ablation experiment, it can be seen that the BiParcld-Net model with LEF and IDF features added shows significant performance improvement in various indicators, verifying the key role of the two features in intrusion detection.
[0156] Table 5 Feature module ablation comparison
[0157] Model Accuracy Recall Precision F1 score The present application 0.9999 0.9999 0.9999 0.9999 w / o IDF 0.9573 0.7112 0.9999 0.8312 w / o LEF 0.9998 0.9990 0.9999 0.9995 w / o LEF & IDF 0.9573 0.7113 0.9998 0.8313
[0158] The above only describes the embodiments of the application and is not used to limit the application. For those skilled in the art, the application can have various changes and variations. Any modification, equivalent replacement, improvement, etc. within the spirit and principles of the application shall be included in the scope of the claims of the application.
Claims
1.A vehicle-mounted network intrusion detection system and method based on a BiParc1d-Net model, characterized in that: The vehicle-mounted network intrusion detection system detects attacks by training a two-stage architecture model, BiParc1d-Net model, which includes a bidirectional long short-term memory network model, BiLSTM, and a one-dimensional deep feature analysis network model, Parc1d-Net; the first stage uses the bidirectional long short-term memory network model to extract the time sequence features of the controller area network bus data, and combines the features extracted by the controller area network message feature extraction module to perform attack binary classification detection on the controller area network bus data, obtaining attack data of the first stage; the second stage uses the one-dimensional deep feature analysis network model to extract the spatial features of the controller area network data, and performs multi-class attack classification on the attack data identified in the first stage. 2.The BiParc1d-Net model based vehicle-mounted network intrusion detection system and method of claim 1, wherein: The bidirectional long short-term memory network model comprises a first BiLSTM layer, a first batch normalization layer, a first Dropout layer, a second BiLSTM layer, a second batch normalization layer, a second Dropout layer and a full connection layer arranged in sequence; The first BiLSTM layer adopts a bidirectional LSTM layer structure, each LSTM layer is composed of 64 hidden units, the first batch normalization layer performs normalization processing on the output of the first BiLSTM layer, and the first Dropout layer is used to prevent overfitting; The second BiLSTM layer adopts a bidirectional LSTM layer structure, each LSTM layer is composed of 32 hidden units, the second batch normalization layer performs normalization processing on the output of the second BiLSTM layer, and the second Dropout layer is used to prevent overfitting; The full connection layer is used to map the features processed by the second BiLSTM layer to the final detection result for binary classification detection. 3.The BiParc1d-Net model based vehicle-mounted network intrusion detection system and method of claim 1, wherein: The message feature extraction module comprises a message data load entropy feature module and a controller area network message ID frequency mean deviation feature module, which extracts load entropy features and frequency mean deviation features through the message data load entropy feature module and the controller area network message ID frequency mean deviation feature module, and performs feature fusion to construct a complete feature matrix, wherein: The message data load entropy feature module analyzes the load bytes of each controller area network message and performs entropy value calculation, and the formula is: where H(X) represents information entropy, P(m i ) represents the probability of the byte value m i appearing in the load, and M represents the number of different byte values. The calculated entropy value is stored in a feature matrix, and the vehicle-mounted network intrusion detection system detects abnormal data patterns indicating malicious activities. The controller area network message ID frequency mean deviation feature module detects abnormal conditions in the frequency distribution of messages, tracks the frequency of each controller area network message ID in a dynamic time window, and calculates the frequency mean deviation of each controller area network message ID from the frequency of all controller area network message IDs in the time window. 4.The BiParc1d-Net model based vehicle-mounted network intrusion detection system and method of claim 3, wherein: The frequency mean deviation of each controller area network message ID from the frequency of all controller area network message IDs in the time window is calculated as follows: First, the frequency f of the current controller area network message ID in the time window is calculated i : Wherein, count(i) represents the number of occurrences of the current controller area network message ID in the time window, and w is the size of the time window. Secondly, calculate the average frequency of all controller area network message IDs within the time window wherein f j is the frequency of the jth CAN message ID within the time window, and n is the number of different CAN message IDs within the window. Finally, the controller area network message ID frequency mean deviation D is calculated f The frequency mean deviation is measured by comparing the frequency f of the current controller area network message ID with the average frequency of all controller area network message IDs within the time window where D f represents the frequency mean deviation, f i represents the frequency of the current controller area network message ID in the time window, represents the average frequency of all controller area network message IDs in the time window. 5.The BiParc1d-Net model based vehicle-mounted network intrusion detection system and method of claim 1, wherein: The one-dimensional deep feature analysis network model, namely Parc1d-Net, comprises an embedding layer and at least one Parc1d Block module; The embedding layer is used for mapping the input feature vector to a high-dimensional feature space; The Parc1d Block module is a core calculation unit for deep feature extraction and pattern analysis, which adopts a double residual structure and is sequentially connected by a convolution attention submodule and a feedforward network submodule; the convolution attention submodule itself comprises a first normalization layer, a one-dimensional deep separable convolution layer and a channel attention module; the feedforward network submodule comprises a second normalization layer and a feedforward network module, and the Parc1d Block module processes the input features and generates output features. 6.The BiParc1d-Net model based vehicle-mounted network intrusion detection system and method of claim 5, wherein: The process that the Parc1d Block module processes the input features and generates output features specifically comprises the following steps: Step 1, temporarily storing the input features received by the Parc1d Block module; Step 2, sending the input features into the convolution attention submodule, in which the input features first pass through the first normalization layer, and then the normalized features are sent into the one-dimensional deep separable convolution layer and the channel attention module at the same time, the output of the one-dimensional deep separable convolution layer is multiplied by the attention weight generated by the channel attention module element by element to obtain weighted features; Step 3, element by element adding the weighted features obtained in step 2 and the input features temporarily stored in step 1 to obtain the first residual connection result; Step 4, temporarily storing the first residual connection result obtained in step 3; Step 5, sending the first residual connection result obtained in step 4 into the feedforward network submodule, in which the weighted features obtained in step 2 first pass through the second normalization layer, and then the normalized features are sent into the feedforward network module for nonlinear transformation; Step 6, element by element adding the output of the feedforward network module in step 5 and the first residual connection result temporarily stored in step 4; Step 7, taking the addition result in step 6 as the final output features of the Parc1d Block module. 7.The BiParc1d-Net model based vehicle-mounted network intrusion detection system and method of claim 6, wherein: The feedforward network module comprises a dimension expansion unit and a dimension recovery unit; The dimension expansion unit adopts a first 1x1 convolution layer for expanding the channel dimension and a GELU nonlinear activation function to perform nonlinear mapping on the features fused after the convolution attention submodule and the first residual connection; The dimension recovery unit comprises a second 1x1 convolution layer for recovering the original channel dimension and one or more dropout layers (Dropout Layer) to recover the channel dimension of the features processed by the dimension expansion unit, and the calculation result is taken as the final output of the feedforward network module. 8.The BiParc1d-Net model based vehicle-mounted network intrusion detection system and method of claim 5, wherein: The one-dimensional deep separable convolution layer is used for independently performing one-dimensional convolution operation on each feature channel to capture the local patterns inside the features, and the operation process is defined as where Y dw (d,t) is the value of the output feature map at position t in the d-th channel, X norm1 is the input tensor after batch normalization, w dw (d,k) is the weight of the depth convolution kernel in the d-th channel, K represents the size of the convolution kernel, k is the position index within the convolution kernel, and p is the padding amount. 9.The BiParc1d-Net model based vehicle-mounted network intrusion detection system and method of claim 5, wherein: The channel attention module comprises a Squeeze unit and an Excitation unit, the Squeeze unit adopts an adaptive one-dimensional global average pooling operation to compress the feature map output by the one-dimensional depth separable convolution layer in the sequence dimension, and generates a global information descriptor for each feature channel; the Excitation unit learns the nonlinear dependence between channels and generates normalized channel weight coefficients, the Excitation unit learning comprises a first 1x1 convolution layer for reducing the channel dimension, a ReLU nonlinear activation function, a second 1x1 convolution layer for restoring the original channel dimension, and a Sigmoid activation function, the channel weight coefficients generated by the Excitation unit are multiplied with the feature map output by the one-dimensional depth separable convolution layer as the final output of the channel attention module, which realizes the enhancement of key feature channels and the suppression of non-key feature channels. 10.The BiParc1d-Net model based vehicle-mounted network intrusion detection system and method of claim 1, wherein: The step 1 specifically comprises the following steps: Step 1.1, obtaining a public automobile hacking data set; Step 1.2, data cleaning of CAN message data, including extracting specific columns of CAN message data and adding field names, filling missing values, converting hexadecimal data to decimal, and replacing numerical labels, specifically: extracting specific columns 1, 3, 4, 5, 6, 7, 8, 9, 10, 11 in the CAN message data as data, and adding corresponding field names 'p1', 'p2', 'p3', 'p4', 'p5', 'p6', 'p7', 'p8' representing each data field in the vehicle controller area network message data, 'Label' column as a label column of data, and filling the default value of missing values; the controller area network message ID and Data column use '0000' and '00', the Label column uses 'R', and then all entries with a value of 'R' in the data column are replaced with '0', next, all hexadecimal strings in the column are converted to decimal integers, and finally, for attack data, replace the corresponding numerical label to represent attack data, 1 represents DoS abnormal data, 2 represents Fuzzy abnormal data, 3 represents Gear abnormal data, and 4 represents RPM abnormal data.