Malicious information detection and repair detection method for intelligent network connection bus

By using parallel deep learning models and support vector machines to detect malicious information, and combining PF-PID control and cloud patching mechanisms, the problem of identifying and repairing malicious information in intelligent connected public transportation systems under DDoS attacks was solved, and the stability and security of the system were restored under the attack.

CN121125175APending Publication Date: 2025-12-12BEIJING JIAOTONG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511157926.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-19
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

When faced with distributed denial-of-service attacks, existing technologies struggle to effectively identify and repair malicious information when the state estimator fails, leading to the failure of the cooperative adaptive cruise control system and impacting traffic flow efficiency and system robustness.

Method used

A parallel deep learning model combined with a support vector machine is used to detect malicious information in network communication data. When malicious information is detected, the system switches to adaptive cruise control mode. After obtaining a cloud-based patch, the system returns to cooperative adaptive cruise control mode. The PF-PID controller is used for longitudinal queue stabilization, and malicious information is removed by combining cloud-based interactive patches.

Benefits of technology

It significantly improves the accuracy of DDoS attack identification, ensures the adaptive capability and control robustness of the intelligent connected bus system under attack, prevents the spread of malicious information, ensures safe vehicle following and traffic flow stability, and supports the system to recover its original performance after an attack.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125175A_ABST
    Figure CN121125175A_ABST
Patent Text Reader

Abstract

The invention provides an intelligent networked bus-oriented malicious information detection and repair detection method, which comprises the following steps of: performing malicious information detection on network communication data through a parallel deep learning model to obtain a detection result, the network communication data being communication data between a target vehicle and a cloud; switching a longitudinal control mode of the target vehicle from a cooperative adaptive cruise control (CACC) mode to an adaptive cruise control (ACC) mode under the condition that the detection result represents that malicious information exists; and in the ACC mode, a repair patch sent to the target vehicle by the cloud is obtained, the target vehicle is controlled to be switched back to the CACC mode under the condition that the repair patch takes effect, and the repair patch is used for clearing or isolating the malicious information. According to the invention, dynamic detection and self-repairing of malicious information attacks can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and particularly relates to a malicious information detection and repair method for intelligent networked public transport. BACKGROUND

[0002] With the rapid development of Vehicle-to-Everything (V2X) and intelligent transportation systems, intelligent networked public transport, as the core component of future urban travel, has important significance for improving road safety and traffic efficiency in terms of cooperative perception, cooperative decision-making and cooperative control capabilities. Among them, the Cooperative Adaptive Cruise Control (CACC) system has been widely used in intelligent public transport queues to realize longitudinal following control based on wireless communication between multiple vehicles.

[0003] However, in the actual deployment process, the communication link relied on by the intelligent networked public transport system is vulnerable to network attacks, especially typical malicious information attack forms such as Distributed Denial of Service (DDoS), which can occupy the communication channel, block data transmission, and tamper with traffic perception information in a short period of time, resulting in vehicle state estimation failure, control system abnormalities, and serious threats to the stable operation and driving safety of the public transport queue.

[0004] Existing research mainly focuses on attack detection methods based on state estimation residuals, such as Extended Kalman Filter and State Residual Chi-square Detection, which can effectively identify some abnormal data, but when encountering DDoS attacks, the state estimator itself is disturbed by channel blocking, and the detection accuracy significantly decreases. At the same time, there is currently a lack of security control strategies with joint detection and active repair capabilities, especially when the vehicle cannot obtain effective front vehicle information, the CACC system will completely fail, seriously affecting traffic flow efficiency and system robustness.

[0005] Therefore, there is an urgent need for a detection and repair method that can identify malicious information in a timely manner under the condition of state estimator failure. SUMMARY

[0006] The purpose of the present application is to overcome the shortcomings of the prior art and provide a malicious information detection and repair method for intelligent networked public transport.

[0007] In order to achieve the above-mentioned purpose, the present application adopts the following technical solutions.

[0008] In a first aspect, the present application provides a malicious information detection and repair method for intelligent networked public transport, comprising:

[0009] The network communication data is communication data between the target vehicle and the cloud.

[0010] In a case where the detection result indicates that the malicious information exists, switching a longitudinal control mode of the target vehicle from a cooperative adaptive cruise control (CACC) mode to an adaptive cruise control (ACC) mode.

[0011] In the ACC mode, a repair patch sent by the cloud to the target vehicle is obtained, and in a case where the repair patch takes effect, the target vehicle is controlled to switch back to the CACC mode, and the repair patch is used to clear or isolate the malicious information.

[0012] In some embodiments of the present application, the parallel deep learning model includes a long short-term memory network, a gated recurrent unit network, an additional fusion layer, a fully connected layer, and a Softmax layer.

[0013] The network communication data is communication data between the target vehicle and the cloud.

[0014] The long short-term memory network is used to extract long-term features in the network communication data, and the gated recurrent unit network is used to extract short-term features in the network communication data.

[0015] The long-term features and the short-term features are spliced through the additional fusion layer to obtain fusion features.

[0016] The fusion features are reduced in dimension and converted through the fully connected layer to obtain converted features, and the converted features are input into the Softmax layer to output the detection result.

[0017] In some embodiments of the present application, the parallel deep learning model is obtained in the following manner:

[0018] In a first training stage, the pre-constructed parallel deep learning model is trained using a training set to obtain a trained parallel deep learning model.

[0019] In a second training stage, an intermediate feature vector output by the additional fusion layer of the trained parallel deep learning model is input into a support vector machine for training of the support vector machine to obtain a trained support vector machine.

[0020] In some embodiments of the present application, switching the longitudinal control mode of the target vehicle from the CACC mode to the ACC mode includes:

[0021] The CACC mode is switched to the ACC mode by an intelligent networked public transport local control unit of the target vehicle.

[0022] In some embodiments of the present application, the target vehicle comprises a PF-PID longitudinal platoon stabilizer, and the method further comprises:

[0023] The longitudinal platoon control in the ACC mode is based on a PF-PID control mode, where PF refers to a single-vehicle communication topology, and the proportional-integral-derivative PID control expression is:

[0024]

[0025] wherein, is the expected acceleration of vehicle i under time delay τ, p i is the headway error, defined as the difference between the current actual distance and the expected distance, v i-1 is the speed of the preceding vehicle, v i is the speed of the subject vehicle, k pa , k va are the position error gain and speed error gain of the ACC controller, respectively.

[0026] In some embodiments of the present application, in the ACC mode, a repair patch sent by the cloud to the target vehicle is obtained, comprising:

[0027] In the ACC mode, based on the request mechanism triggered when the headway reaches the critical adjustment threshold, the lead intelligent connected bus in the platoon initiates a patch request to the cloud; the cloud returns the corresponding repair patch according to the unique identifier and state information of the affected vehicle, and distributes the repair patch to the target vehicle through the network transmission system.

[0028] In some embodiments of the present application, in the case where the repair patch takes effect, the target vehicle is controlled to switch back to the CACC mode, comprising:

[0029] When the target vehicle completes the reception and execution of the interactive repair patch and the communication state returns to normal, it is determined whether the safety of switching back to the CACC mode is met according to whether the current inter-vehicle distance meets the condition of the minimum headway h; if it is met, the longitudinal control mode of the target vehicle is restored to the CACC mode from the ACC mode, and the headway is adjusted to the default cooperative control headway h; after switching back, the target vehicle reuses the acceleration information from the preceding vehicle for accurate platoon following. c

[0030] In a second aspect, the present application further provides a malicious information detection and repair device for intelligent connected buses, comprising:

[0031] A detection module for detecting malicious information in network communication data through a parallel deep learning model to obtain a detection result, wherein the network communication data is the communication data between the target vehicle and the cloud;

[0032] ​Switching mode, for switching the longitudinal control mode of the target vehicle from the cooperative adaptive cruise control (CACC) mode to the adaptive cruise control (ACC) mode when the detection result is characterized as existing malicious information;

[0033] Patch mode, for acquiring a repair patch sent by the cloud to the target vehicle in the ACC mode, and controlling the target vehicle to switch back to the CACC mode in the case that the repair patch takes effect, the repair patch being used to clear or isolate the malicious information.

[0034] In a third aspect, the present application also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the method as described above when executing the program.

[0035] In a fourth aspect, the present application also provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the method as described above.

[0036] The method for malicious information detection and repair of intelligent networked public transport provided by the present application can accurately identify malicious data packets under various communication interference forms through the collaborative detection of the LSTM-GRU parallel deep network and the SVM classifier, significantly improves the DDoS attack identification accuracy, and provides reliable supplement in the state estimator failure scenario. The ACC emergency mode based on the PF-PID control realizes safe following under the cooperative control failure condition, effectively blocks the malicious information diffusion path, and ensures that no vehicle collision occurs through the headway management mechanism. The locally triggered mode switching mechanism ensures the instantaneity of decision-making, the mode switching is realized through communication recovery and vehicle distance evaluation, and the continuity and system stability of the queue control performance are ensured. Through the interactive patch mechanism for attack recovery, the malicious information is dynamically cleared by combining the cloud cooperation and local module hot repair, the safety switching after communication recovery and cooperative control recovery are supported, and the original performance and road traffic efficiency of the vehicle after being attacked can be gradually recovered. In summary, the present application can effectively improve the adaptive ability, control robustness and operation safety of the intelligent networked public transport system when facing malicious attacks, and has good practical value and promotion prospect.

[0037] Additional aspects and advantages of the application will be set forth in part in the description which follows, and in part will become apparent to those skilled in the art upon examination of the following description, or can be learned by practice of the application. BRIEF DESCRIPTION OF DRAWINGS

[0038] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiment description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort on the basis of these drawings.

[0039] Figure 1 One of the flowcharts of the malicious information detection and repair method for intelligent networked public transport provided by the embodiments of the present application;

[0040] Figure 2 The second flowchart of the malicious information detection and repair method for intelligent networked public transport provided by the embodiments of the present application;

[0041] Figure 3 The first training stage diagram of the model provided by the embodiments of the present application;

[0042] Figure 4 The second training stage diagram of the model provided by the embodiments of the present application. DETAILED DESCRIPTION

[0043] The embodiments of the present application will be described in detail below, and examples of the embodiments are shown in the drawings, wherein the same or similar notations represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the drawings are exemplary and are only used to explain the present application, and cannot be interpreted as a limitation on the present application.

[0044] Those skilled in the art can understand that, unless specifically stated, the singular forms "a", "an" and "the" used herein also include the plural forms. It should be further understood that the phrase "comprising" used in the specification of the present application means that the features, integers, steps, operations, elements and / or components exist, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or their combinations. It should be understood that when we say an element is "connected" or "coupled" to another element, it can be directly connected or coupled to the other element, or there can be intermediate elements. In addition, "connected" or "coupled" used herein can include wireless connection or coupling. The phrase "and / or" used herein includes any one of the associated listed items and all combinations of the associated listed items.

[0045] Those skilled in the art of the technology can understand that, unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs. It should also be understood that terms such as those defined in a general dictionary should be understood to have meanings consistent with those in the context of the prior art, and should not be interpreted in an idealized or overly formal sense unless defined as such.

[0046] Existing intelligent network-connected bus systems often rely on state estimators for anomaly detection and control repair when facing malicious information interference such as distributed denial of service attacks (DDoS). However, under strong DDoS attacks that occupy channel resources, the state estimator will lose its ability to distinguish, causing distortion of longitudinal control information, which in turn affects cooperative following performance, system stability, and vehicle driving safety. In addition, traditional control recovery methods mostly rely on redundant physical sensors or manual intervention, lacking efficient, intelligent, and closed-loop repair capabilities. Therefore, there is an urgent need for a method that can autonomously detect malicious information and repair longitudinal control under abnormal state estimation conditions to ensure the safe operation and stable coordination of intelligent network-connected bus systems in complex communication environments.

[0047] The following will be further explained and described with several specific embodiments as examples in conjunction with the accompanying drawings, and each embodiment does not constitute a limitation on the embodiments of the present application.

[0048] Embodiment 1

[0049] As shown in Figure 1 and Figure 2 A malicious information detection and repair method for intelligent network-connected buses includes the following steps:

[0050] S101, detecting malicious information in network communication data through a parallel deep learning model to obtain a detection result, the network communication data being communication data between a target vehicle and a cloud.

[0051] The communication data includes at least source IP address, destination IP address, source port, destination port, protocol type, timestamp, duration, service type, message length, and time to live.

[0052] After obtaining the network communication data, the unstructured fields (such as IP addresses) in the communication data are subjected to bag-of-words model or feature hash encoding to form an input feature vector in a unified format. Then, the input feature vector is input to the parallel deep learning model for malicious information detection to obtain a detection result.

[0053] The malicious information can be information subjected to a distributed denial of service (DDoS) attack.

[0054] S102, in the case where the detection result represents the presence of malicious information, switching the longitudinal control mode of the target vehicle from the cooperative adaptive cruise control (CACC) mode to the adaptive cruise control (ACC) mode.

[0055] S103, in the ACC mode, obtaining a repair patch sent by the cloud to the target vehicle, and in the case where the repair patch takes effect, controlling the target vehicle to switch back to the CACC mode, the repair patch being used to clear or isolate the malicious information.

[0056] In addition, in the ACC mode, the target vehicle adopts a PF-PID longitudinal controller for following control.

[0057] In some embodiments of the present application, the parallel deep learning model includes a long short-term memory (LSTM) network, a gated recurrent unit (GRU) network, an additional fusion layer, a fully connected layer, and a Softmax layer.

[0058] The parallel deep learning model is used to detect malicious information in network communication data to obtain a detection result, including:

[0059] The LSTM network is used to extract long-term features in the network communication data, and the GRU network is used to extract short-term features in the network communication data.

[0060] The LSTM is used to identify long-term dependencies in the communication data, and is suitable for adapting to the persistence and time extension characteristics of attack behaviors; the GRU is suitable for capturing rapidly changing short-term behavior signals and supplementing the perception ability of sudden attack characteristics.

[0061] The additional fusion layer is used to splice the long-term features and the short-term features to obtain high-quality fusion features.

[0062] The fully connected layer is used to reduce and convert the fusion features to obtain converted features; and the converted features are input into the Softmax layer to obtain the detection result. The fully connected layer maps a high-dimensional feature space to a low-dimensional output space, and the Softmax layer converts the output of the neural network into a probability estimate of the malicious class, and finally gives a preliminary binary classification result through the output layer.

[0063] In addition, the parallel deep learning model also includes a Dropout layer, which is used to process the long-term features and the short-term features respectively to suppress the risk of overfitting, and output the processed long-term features and the processed short-term features to the additional fusion layer to obtain the fusion features.

[0064] After the detection result shows that the communication data exists DDoS attack behavior, in order to protect the longitudinal control stability of the intelligent networked public transport vehicle and the overall traffic safety, further defense mechanism based on control mode switching is used to realize instant conversion of the control strategy under the network attack environment.

[0065] In some examples, in the neural network structure design, two parallel paths are introduced: one is a 300-unit long short-term memory network LSTM, mainly responsible for capturing long-term dependence features in the historical communication sequence; the other is a 300-unit gated recurrent unit network GRU, used to extract local patterns in a shorter time window. The outputs of the two paths are spliced into a comprehensive feature vector through an additional fusion layer, and then reduced and nonlinearly converted through a fully connected layer containing 128 neurons, and finally the classification probability of each type of information is output through a Softmax layer.

[0066] In some embodiments of the present application, the parallel deep learning model is obtained in the following way:

[0067] As shown in Figure 3 In the first training stage, the pre-constructed parallel deep learning model is trained using the training set to obtain the trained parallel deep learning model.

[0068] As shown in Figure 4 In the second training stage, the intermediate feature vector output by the additional fusion layer of the trained parallel deep learning model is input into the support vector machine for training of the support vector machine to obtain the trained support vector machine.

[0069] In some examples, the entire parallel neural network structure is trained end-to-end through the Holdout validation method: 90% of the total sample set is randomly extracted as the training set, and the remaining 10% is used as the validation set to evaluate the recognition accuracy and stability of the model on unknown data.

[0070] To further improve the robustness and discrimination ability of the model in complex attack scenarios, the intermediate feature output of the additional fusion layer is input into an independently constructed SVM classifier. The classifier learns and constructs the optimal separating hyperplane in the feature space to achieve fine division of malicious information and normal communication. The two-stage architecture formed by the parallel neural network and the SVM classifier fully integrates the advantages of deep feature learning and traditional statistical learning, significantly enhancing the detection accuracy and anti-interference ability of distributed denial of service (DDoS) attacks.

[0071] In this embodiment, the communication data is derived from an intelligent networked public transport communication scenario built based on an OMNeT++ simulation environment. The attack simulation includes HTTP denial-of-service attack, IRC protocol distributed denial-of-service, and SSH brute-force attack. The original communication data includes 10 types of network features such as source IP, destination IP, source port, destination port, protocol type, timestamp, duration, service type, message length, and TTL (Time to Live). For structured numerical fields, direct normalization processing is performed; for discrete fields such as IP address and service type, a Bag of Words (BoW) combined with feature hash coding method is used to convert them into vector form, ensuring that the data structure input into the neural network is uniform and consistent in dimension.

[0072] In the training phase, the Softmax layer output is only used for the first-stage supervised training target; after training is completed, the intermediate feature vector of the fusion layer output is intercepted as a deep semantic expression, which is input into a support vector machine classifier SVM for independent training in the second stage to construct a high-precision decision boundary based on features. This two-stage architecture improves the classification robustness on the one hand and enhances the recognition ability of the boundary fuzzy samples on the other hand.

[0073] In the parallel deep learning model training process, a Holdout validation strategy is used: 90% of the labeled data set is randomly extracted as the training set, and the remaining 10% is used as the test set. The training loss uses the cross-entropy function, the optimizer selects the Adam algorithm, and the initial learning rate is set to 0.001. The evaluation indicators include precision, recall, and F1-score, among which the detection accuracy is stably maintained above 95%, which has excellent potential for actual deployment.

[0074] It can be understood that the trained SVM can be used alone for malicious information detection of network communication data; or it can be used together with the parallel deep learning model for malicious information detection, and the detection results output by the parallel deep learning model and the detection results output by the SVM are weighted and averaged to obtain the final detection result, etc.

[0075] In some embodiments of the present application, switching the longitudinal control mode of the target vehicle from the cooperative adaptive cruise control CACC mode to the adaptive cruise control ACC mode includes:

[0076] Switching the CACC mode to the ACC mode by the intelligent networked public transport local control unit of the target vehicle.

[0077] It can be understood that when the DDoS type malicious information injection communication data is detected, and the key parameters necessary for cooperative control, such as the acceleration information and braking state of the preceding vehicle, cannot be stably obtained, the system triggers a “communication failure” determination event, which is a prerequisite for control switching and is received and analyzed by the local control unit in real time, so as to determine that the current cooperative adaptive cruise control (CACC) mode has failed to safely support the cooperative operation of the vehicle platoon. Therefore, it is necessary to switch the CACC mode to the ACC mode. The control mode switching is realized by the vehicle-mounted detection module sensing the communication quality of the preceding vehicle in real time, specifically by evaluating the data packet reception rate, information delay and integrity flag. If the detection module continuously identifies that the acceleration information of the preceding vehicle is missing or the data is abnormal (for example, repeated, too old, conflicting packets), and the abnormality lasts for more than a set time window (for example, 0.5 seconds), it is considered as communication failure, triggering the control switching mechanism.

[0078] In the ACC mode, the vehicle no longer relies on the inter-vehicle wireless communication link, but completely relies on the vehicle-mounted sensors (such as millimeter wave radar, laser radar, visual camera, etc.) to obtain the relative distance and speed between the preceding vehicle and the vehicle, and independently decides the longitudinal acceleration and deceleration control behavior accordingly. Since this switching process does not depend on additional commands of the central controller or the cloud scheduling platform, but is autonomously completed by the control logic in the vehicle, it has high response speed and anti-interference ability, and is particularly suitable for the communication congestion or data pollution scenario caused by DDoS attack.

[0079] It can be understood that the above control mode switching is not triggered based on time rotation or preset conditions, but is driven by a communication availability real-time monitoring module. When the module confirms that valid acceleration information of the preceding vehicle cannot be obtained continuously for more than a set threshold, it is determined that the “cooperative control failure state” is reached. After confirming the state, the vehicle will execute the following control migration instructions: (a) stop tracking and responding to the acceleration of the preceding vehicle; (b) switch to the ACC longitudinal control model based on the headway control; (c) maintain the current speed or gradually adjust the acceleration according to the safety distance rule to prevent the risk of rear-end collision caused by sudden deceleration. After the switching is completed, the vehicle system enters the ACC running state, and the communication recovery state is continuously monitored during this period, so as to complete the reverse switching and system recovery in the subsequent stage.

[0080] In addition, in the CACC mode, the intelligent networked bus needs to obtain the speed and acceleration information of the preceding vehicle to achieve precise longitudinal control based on the feedforward amount. After suffering from DDoS attack, the feedforward signal is unavailable, and the embodiment selects to immediately switch to the ACC mode. In the ACC mode, the vehicle control only relies on the vehicle sensors (millimeter wave radar, camera, inertial navigation system) to obtain the relative position and relative speed of the preceding vehicle, and uses feedback control to achieve following.

[0081] During the switching process, the cooperative input module in the original CACC controller is disabled, and the longitudinal control is completely handed over to the ACC module. When the ACC module is initialized, the current headway, following speed and acceleration state are taken as the initial boundary conditions, and a takeover smoothing strategy is adopted to ensure the continuity of the control input transition and avoid safety hazards such as sudden acceleration or braking jumps.

[0082] In some embodiments of the present application, when the vehicle completes the switching from the cooperative adaptive cruise control (CACC) to the adaptive cruise control (ACC) mode, the system needs to ensure that it can still achieve stable and safe longitudinal following control in the absence of front vehicle acceleration information. To this end, the present application introduces a proportional-integral-derivative (PID) controller based on the "predecessor following" topology (PF-PID controller) for maintaining vehicle spacing and speed stability in ACC mode and preventing rear-end collisions or queue fluctuations.

[0083] Specifically, the target vehicle includes a PF-PID longitudinal queue stabilizer, and the method further comprises:

[0084] The longitudinal queue control in ACC mode is based on the PF-PID control mode, where PF refers to a single-vehicle communication topology, and the proportional-integral-derivative (PID) control expression is:

[0085]

[0086] In the formula, is the desired acceleration of vehicle i with time delay τ, p i (t-τ) is the headway error, defined as the difference between the current actual distance and the desired distance, v i-1 (t-τ) is the front vehicle speed, v i is the vehicle speed, k pa ,k va are the position error gain and speed error gain of the ACC controller, respectively.

[0087] To ensure the stable operation of the intelligent networked public transportation (i.e., the target vehicle) longitudinal control system, the position error gain k pa and the speed error gain k va must be set reasonably. These parameters determine the response degree of the vehicle to the distance error and speed error of the front vehicle, and their values should meet the requirements of "internal stability" and "queue stability" of the system.

[0088] The internal stability of the system requires that the system will not "oscillate" or "diverge" on its own without external disturbances. By analyzing the transfer function of the control system through Laplace transform, the denominator of the characteristic equation is obtained as:

[0089] s 2 +k va s+k pa =0

[0090] where s is a complex variable used in Laplace transform.

[0091] According to the Routh-Hurwitz stability criterion, the condition for the internal stability of the second-order system is:

[0092] k va > 0, k pa > 0.

[0093] The platoon stability requires that a small change in a preceding vehicle cannot be amplified in subsequent vehicles, and the sufficient condition for stability includes:

[0094]

[0095] where v max is the upper bound of speed, a max is the upper bound of acceleration, and h min is the minimum headway.

[0096] To meet the above conditions in practice, the position error gain k pa speed error gain k va : k va = 0.8, k pa = 2.

[0097] In some embodiments of the present application, when the intelligent connected bus completes the switching from the cooperative adaptive cruise control (CACC) mode to the adaptive cruise control (ACC) mode, the system enters the repair phase of attack response, aiming to clear the malicious information hidden in the target vehicle through interactive patches.

[0098] Specifically, in the ACC mode, the repair patch sent by the cloud to the target vehicle is obtained, including:

[0099] In the ACC mode, the request mechanism triggered when the headway reaches the critical adjustment threshold h c is initiated by the lead intelligent connected bus in the platoon to the cloud; the cloud returns the corresponding repair patch according to the unique identifier (such as VIN code) and state information of the affected vehicle, and distributes the repair patch to the target vehicle through the network transmission system. The patch request contains the unique identifier (such as VIN code) and real-time running state of the affected vehicle, which is used to accurately match the required patch content.

[0100] After receiving the request, the cloud platform generates a customized interaction patch in combination with the attack type, vehicle model, and communication log. The patch content may include configuration reloading, exception rule clearing, or communication module logic reconstruction. The cloud sends the patch to the affected vehicle through an encrypted communication channel and ensures that the module is hot-fixed without interrupting normal driving functions.

[0101] In some embodiments of the present application, after the vehicle local control unit receives the interaction patch, it automatically completes parsing and injection, and preferentially restores the communication link and control logic module. This process is carried out without interrupting vehicle operation, ensuring that the overall driving stability of the vehicle fleet is not affected. After the patch is repaired and communication stability is restored, the system needs to restore the original cooperative control logic of intelligent networked public transport under the condition of ensuring safety.

[0102] In the case where the repair patch takes effect, the control target vehicle switches back to the CACC mode, including:

[0103] When the target vehicle completes the reception and execution of the interaction repair patch and the communication state returns to normal, according to whether the current vehicle spacing meets the minimum vehicle headway h, it is determined whether the safety of switching back to the CACC mode is met; if so, the longitudinal control mode of the target vehicle is restored from the ACC mode to the CACC mode, and the vehicle headway is adjusted from h to the default cooperative control headway h; after switching back, the target vehicle reuses the acceleration information from the preceding vehicle for accurate platooning. c

[0104] In this step, the repair process includes the following steps:

[0105] 1. Triggering condition of repair mechanism

[0106] The vehicle enters the ACC mode operation;

[0107] The current vehicle headway with the preceding vehicle reaches the critical threshold.

[0108] 2. Construction and uploading of repair request

[0109] The lead vehicle constructs a repair request message through the embedded secure communication module, including but not limited to:

[0110] Unique identifier of the attacked vehicle (such as VIN code);

[0111] Summary of current network communication state (such as packet loss rate, delay information);

[0112] Longitudinal control mode change record of the vehicle in the past N seconds;

[0113] Type identification of modules that need to be repaired (such as controller exception, perception redundancy failure, etc.).

[0114] ​The repair request is sent to the cloud control platform through the fleet-cloud interface, and the platform confirms the legality and priority of the request.

[0115] 3. Generation and distribution of repair patches

[0116] After receiving the request, the cloud system will combine the vehicle's historical operation log, attack detection mode characteristics, and current sensor state to perform the following operations:

[0117] Patch content generation: generate targeted repair patches based on attack characteristics, including malicious code cleaning scripts, communication protocol rule reloading configurations, or controller security variable initialization instructions, etc.

[0118] Patch consistency check: verify patch integrity and legality through hash signature and encryption mechanism to prevent counterfeit update package injection;

[0119] Patch pushing and writing: use reliable broadcast mechanism to distribute repair patches to the target vehicle's local communication module, and complete writing and activation by the secure execution engine.

[0120] 4. Feedback and monitoring of repair process

[0121] The patch application process is controlled by the vehicle's local system. After writing is completed, the vehicle starts a short self-test task to judge the following indicators:

[0122] Whether the normal communication with the preceding vehicle is restored;

[0123] Whether legal cooperative control data is detected again;

[0124] Whether the local control parameters are consistent with those before the communication interruption.

[0125] If all indicators are met, a repair completion signal is generated and reported to the cloud platform, and the vehicle state is switched to the standby cut-back state, preparing to restore the CACC control mode.

[0126] After the patch repair is completed and the communication state is confirmed to be normal, to achieve comprehensive recovery of vehicle cooperative control performance, the research designs a safe cut-back mechanism for the control mode, enabling the intelligent networked bus to safely cut back from the adaptive cruise control (ACC) mode to the cooperative adaptive cruise control (CACC) mode, rebuilding the cooperative following relationship between vehicles, and ensuring the overall stability and driving efficiency of the system.

[0127] 1. Cut-back condition determination

[0128] The system determines whether the cut-back condition is met through the local control unit, which includes:

[0129] Communication recovery: continuously receive and verify acceleration information from the preceding vehicle to ensure stable communication;

[0130] Safety gap: current headway meets the minimum requirement of cooperative mode, i.e. d i ≥ h · v i ;

[0131] Information consistency: the state of the front vehicle obtained by perception and communication is consistent, and the difference is less than the tolerance threshold.

[0132] 2. Re-switching process execution

[0133] Once the re-switching condition is met, the system automatically performs the following operations:

[0134] Switch the longitudinal controller to the CACC mode;

[0135] Reconstruct the control input using the front vehicle acceleration information obtained by communication;

[0136] Restore the headway target from h c to the cooperative control headway h;

[0137] Broadcast the re-switching completion status to the rear vehicle to maintain the consistency of the platoon control.

[0138] 3. Abnormal fallback protection

[0139] If the communication is abnormal again or the data is inconsistent after re-switching, the system can automatically switch back to the ACC mode to ensure safe operation.

[0140] The intelligent network-connected bus malicious information detection and repair method provided by the embodiments of the present application can accurately identify malicious data packets under various communication interference forms through the cooperative detection of the LSTM-GRU parallel deep network and the SVM classifier, significantly improve the DDoS attack identification accuracy, and provide reliable supplement in the state estimator failure scenario. The ACC emergency mode based on the PF-PID control realizes safe following under the cooperative control failure condition, effectively blocks the malicious information diffusion path, and ensures that no vehicle collision occurs through the headway management mechanism. The locally triggered mode switching mechanism ensures the instantaneity of decision-making; the communication recovery and vehicle distance evaluation realize mode re-switching, ensuring the persistence of platoon control performance and system stability. Through the attack recovery-oriented interactive patch mechanism, combined with cloud cooperation and local module hot repair, the dynamic removal of malicious information is realized; the safety re-switching and cooperative control recovery after communication recovery are supported, ensuring that the vehicle can gradually recover the original performance and road traffic efficiency after being attacked. In summary, the present application can effectively improve the adaptive ability, control robustness and operation safety of the intelligent network-connected bus system when facing malicious attacks, and has good practical value and promotion prospect.

[0141] Embodiment 2

[0142] Based on embodiment 1, this embodiment 2 provides an intelligent network connection-oriented public transport malicious information detection and repair device, which corresponds to the intelligent network connection-oriented public transport malicious information detection and repair method described above, and specifically includes:

[0143] The detection module is configured to detect malicious information in the network communication data by using the parallel deep learning model to obtain a detection result, wherein the network communication data is communication data between the target vehicle and the cloud.

[0144] The switching mode is configured to switch the longitudinal control mode of the target vehicle from the cooperative adaptive cruise control (CACC) mode to the adaptive cruise control (ACC) mode when the detection result indicates the presence of malicious information.

[0145] The patch mode is configured to obtain a repair patch sent by the cloud to the target vehicle in the ACC mode, and control the target vehicle to switch back to the CACC mode when the repair patch takes effect, wherein the repair patch is used to clear or isolate the malicious information.

[0146] For specific details, refer to the description of the intelligent network connection-oriented public transport malicious information detection and repair method, which will not be repeated here.

[0147] Embodiment 3

[0148] Embodiment 3 of the present application provides an electronic device comprising a memory and a processor, the processor and the memory being in communication with each other, the memory storing program instructions executable by the processor, and the processor invoking the program instructions to execute the intelligent network connection-oriented public transport malicious information detection and repair method, which comprises the following flow steps:

[0149] Detect malicious information in the network communication data by using the parallel deep learning model to obtain a detection result, wherein the network communication data is communication data between the target vehicle and the cloud.

[0150] Switch the longitudinal control mode of the target vehicle from the cooperative adaptive cruise control (CACC) mode to the adaptive cruise control (ACC) mode when the detection result indicates the presence of malicious information.

[0151] In the ACC mode, obtain a repair patch sent by the cloud to the target vehicle, and control the target vehicle to switch back to the CACC mode when the repair patch takes effect, wherein the repair patch is used to clear or isolate the malicious information.

[0152] Embodiment 4

[0153] Embodiment 4 of the present application provides a computer readable storage medium storing a computer program, the computer program being executed by a processor to implement a malicious information detection and repair method for intelligent network connection oriented public transport, the method comprising the following flow steps:

[0154] malicious information detection is performed on the network communication data by a parallel deep learning model to obtain a detection result, the network communication data being communication data between the target vehicle and the cloud;

[0155] in a case where the detection result indicates that malicious information exists, switching a longitudinal control mode of the target vehicle from a cooperative adaptive cruise control (CACC) mode to an adaptive cruise control (ACC) mode;

[0156] in the ACC mode, a repair patch sent by the cloud to the target vehicle is acquired, and in a case where the repair patch takes effect, the target vehicle is controlled to switch back to the CACC mode, the repair patch being used to clear or isolate the malicious information.

[0157] Those skilled in the art can understand that the drawings are only schematic diagrams of an embodiment, and the modules or flows in the drawings are not necessarily required to implement the present application.

[0158] Each embodiment in the specification is described in a progressive manner, and the same or similar parts of each embodiment can be referred to each other, and each embodiment mainly describes the difference from other embodiments. In particular, for the method or system embodiment, since it is basically similar to the method embodiment, it is described more simply, and the related parts can be referred to the part of the method embodiment. The above described method and system embodiments are only schematic, and the units described as separate components can be or can not be physically separated, and the components displayed as units can be or can not be physical units, that is, they can be located in one place, or can be distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiment scheme according to the actual needs. Those skilled in the art can understand and implement without creative labor.

[0159] The above is only a preferred specific embodiment of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for malicious information detection and repair for intelligent networked public transportation, characterized in that, The method comprises: detecting malicious information in network communication data between the target vehicle and the cloud by a parallel deep learning model to obtain a detection result; switching a longitudinal control mode of the target vehicle from a cooperative adaptive cruise control (CACC) mode to an adaptive cruise control (ACC) mode when the detection result indicates that there is malicious information; in the ACC mode, obtaining a repair patch sent by the cloud to the target vehicle, and switching the target vehicle back to the CACC mode when the repair patch takes effect, the repair patch being used to clear or isolate the malicious information.

2. The method of claim 1, wherein, The parallel deep learning model comprises a long short-term memory network, a gated recurrent unit network, an additional fusion layer, a fully connected layer, and a Softmax layer. The detection of malicious information in the network communication data by the parallel deep learning model comprises: extracting long-term features in the network communication data by the long short-term memory network and extracting short-term features in the network communication data by the gated recurrent unit network; splicing the long-term features and the short-term features by the additional fusion layer to obtain fusion features; dimensionally reducing and converting the fusion features by the fully connected layer to obtain converted features, and inputting the converted features into the Softmax layer to output the detection result.

3. The method of claim 2, wherein, The parallel deep learning model is obtained in the following manner: in a first training stage, training a pre-constructed parallel deep learning model by using a training set to obtain a trained parallel deep learning model; in a second training stage, inputting an intermediate feature vector output by the additional fusion layer of the trained parallel deep learning model into a support vector machine to train the support vector machine to obtain a trained support vector machine.

4. The method of claim 1, wherein, The switching of the longitudinal control mode of the target vehicle from the CACC mode to the ACC mode comprises: switching the CACC mode to the ACC mode by an intelligent connected bus local control unit of the target vehicle.

5. The method of claim 1, wherein, The target vehicle comprises a PF-PID longitudinal queue stabilizer, and the method further comprises: the longitudinal queue control in the ACC mode is based on a PF-PID control mode, wherein PF refers to a single-vehicle communication topology, and a proportional-integral-derivative (PID) control expression is: where, is the desired acceleration of vehicle i with time delay τ, p i (t-τ) is the headway error, defined as the difference between the current actual distance and the desired distance, v i-1 (t-τ) is the front vehicle speed, v i is the host vehicle speed, k pa ,k va are the position error gain and speed error gain of the ACC controller, respectively.

6. The method of claim 1, wherein, in the ACC mode, initiating a patch request to the cloud by a lead intelligent connected bus in the vehicle fleet based on a request mechanism triggered when a headway reaches a critical adjustment threshold; the cloud returns a corresponding repair patch according to a unique identifier and state information of an affected vehicle, and distributes the repair patch to the target vehicle through a network transmission system. The switching of the target vehicle back to the CACC mode when the repair patch takes effect comprises:

7. The method of claim 1, wherein, ​ When the target vehicle completes the reception and execution of the interactive repair patch, and the communication state returns to normal, it is determined whether the safety of switching back to the CACC mode is met according to whether the current vehicle distance meets the condition of the minimum vehicle headway h; if yes, the longitudinal control mode of the target vehicle is restored to the CACC mode from the ACC mode, and the vehicle headway is adjusted to the default cooperative control headway h; after switching back, the target vehicle reuses the acceleration information from the front vehicle to perform accurate platooning. c adjustment to the default cooperative control headway h; after switching back, the target vehicle reuses the acceleration information from the front vehicle to perform accurate platooning.

8. An intelligent network connection-oriented bus malicious information detection and repair device, characterized in that, ​ The detection module is configured to perform malicious information detection on network communication data between the target vehicle and the cloud by using a parallel deep learning model to obtain a detection result. The switching mode is configured to switch a longitudinal control mode of the target vehicle from a cooperative adaptive cruise control (CACC) mode to an adaptive cruise control (ACC) mode when the detection result indicates that there is malicious information. The patch mode is configured to obtain a repair patch sent by the cloud to the target vehicle in the ACC mode, and control the target vehicle to switch back to the CACC mode when the repair patch takes effect, the repair patch being used to clear or isolate the malicious information.

9. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor implements the method according to any one of claims 1-7 when executing the program.

10. A computer-readable storage medium, characterized in that, The computer program is stored in the computer readable storage medium and is executed by the processor to implement the method according to any one of claims 1-7.