A digital-twin-based vehicle-mounted electrical control unit debugging simulation system

CN121232630BActive Publication Date: 2026-08-11JIANGSU LIANYUNGANG SECONDARY VOCATIONAL SCHOOL
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-10
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0006]本发明的一个目的在于提出一种基于数字孪生的车载电气控制单元调试仿真方法与系统,针对现有技术在跨域数据对齐不准、通道级时延不可测、通信拥塞下达时难保障及调试动作安全性不足的缺陷,提出了采用统一时间基准与时延估计、构建多分量一致性差分谱及置信度、“基线补偿+事件校正”的对齐策略、结合语义编码与确定性和/或优先级调度并在安全不变集下仲裁与自适应降级的技术方案,本发明具备实现毫秒级双向协同调试、提升一致性收敛与安全性并兼顾带宽效率和控制权平滑切换的优点

Benefits of technology

[0045](1)统一驱动指标与三联闭环:以“多分量一致性差分谱+置信度”作为同步层、通信层与仲裁层的共用优化/门控信号,形成毫秒级闭环协同,使时间对齐、链路资源分配与安全调试决策同目标协同收敛。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121232630B_ABST
    Figure CN121232630B_ABST
Patent Text Reader

Abstract

This invention discloses a digital twin-based debugging and simulation system and method for vehicle electrical control units (ECUs). The system consists of modules for data aggregation and time reference, consistency assessment, synchronization and correction, semantic communication and scheduling, arbitration and safe debugging, cross-layer adaptive degradation, and execution and iteration. It estimates channel-level latency through a unified time reference, constructs a consistency differential spectrum containing amplitude, timing, event, and derivative components, and provides confidence levels. It calculates latency compensation and event-level alignment, and implements deterministic and priority scheduling based on semantic benefits. Under the constraint of a safety invariant set, it generates and limits actions such as amplitude parameter reinjection, message injection, task tick perturbation, and environmental stimuli. Based on confidence levels, it implements soft switching and gating of control rights, and performs graded degradation when confidence levels are low or constraints are triggered. It achieves millisecond-level bidirectional collaborative debugging between the digital twin and the physical ECU, improving consistency convergence, safety, and bandwidth timeliness.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle electronics and digital twin technology, and in particular to a debugging and simulation system for vehicle electrical control units based on digital twins. Background Technology

[0002] With the rapid development of automotive electronics technology, the functions of on-board electrical control units (ECUs) are becoming increasingly complex, involving numerous areas such as powertrain, chassis, body, and advanced driver assistance systems. The increasing integration and intelligence of ECUs have led to a significant increase in the complexity of their software logic, hardware interaction, and system-level collaboration. To ensure the reliability, stability, and functional safety of ECUs, precise and efficient debugging and simulation technologies are indispensable key aspects of automotive electronics R&D.

[0003] Currently, the debugging and simulation technologies for vehicle ECUs mainly include the following: (1) Traditional debugging tools: such as JTAG / SWD debuggers, logic analyzers, oscilloscopes, serial communication interface logs, etc. These tools can observe and control the underlying hardware and software execution of the ECU, but they are usually inefficient and difficult to simulate complex working scenarios or the behavior of multiple ECUs working together; (2) Software-in-the-loop simulation: running the ECU's target code on a PC or other simulation platform and interacting with the simulated environment model. SiL simulation is fast and convenient for large-scale testing and regression testing, but it cannot simulate the characteristics, timing and power consumption of real hardware; (3) Processor-in-the-loop simulation: running the ECU's target code in a real or simulated processor environment. It is usually similar to SiL, but focuses more on the timing and instruction set behavior at the processor level; (4) Hardware-in-the-loop simulation: Connect the physical ECU under test to a simulation platform that simulates the real vehicle operating environment. The HIL system can provide a realistic external environment and is an important means to verify the performance of the ECU under actual working conditions. (5) Preliminary application of the digital twin concept: In recent years, the digital twin concept has been introduced into the field of automotive electronics, aiming to create a dynamic, virtual copy of the physical ECU or the entire vehicle. Some preliminary digital twin applications may focus on verification in the design phase, monitoring of operating status, predictive maintenance, or constructing a static / semi-dynamic mapping of physical processes.

[0004] Although existing debugging and simulation technologies have promoted the development process of ECUs to some extent, there are still significant shortcomings in achieving efficient and comprehensive collaborative debugging, especially in combining digital twin technology to achieve deep interaction with physical ECUs: (1) Insufficient real-time synchronization between digital twin models and physical ECUs: Most existing digital twin models are either static and fixed models, which are difficult to reflect the rapidly changing internal state and behavior of physical ECUs in actual operation in real time; or their simulation update cycle is long and cannot keep in sync with the real-time dynamics of physical ECUs, resulting in a disconnect between simulation results and actual situation; (2) Lack of true two-way data interaction and closed-loop control: Current attempts based on digital twins often focus on one-way mapping from the physical world to the digital world, and lack a mechanism that allows digital twin models to be more than just "observers", but to feed back instructions, parameters or status information to the operation of physical ECUs or their test environment in real time and bidirectionally based on their analysis results or preset debugging scenarios, forming an effective debugging closed loop; (3) Difficulty in effectively simulating and injecting complex and dynamic fault scenarios: Although HIL systems can inject some environmental faults, existing technologies struggle to use digital twins to simulate complex faults that may involve the internal state of the ECU, software logic, communication interactions, and hardware characteristic coupling with high precision and high fidelity, and to "inject" these faults into the operation of the physical ECU in real time for in-depth robustness testing.

[0005] Therefore, how to achieve real-time, bidirectional data interaction and collaborative debugging between digital twins and physical ECUs is a problem that needs to be solved by those skilled in the art. Summary of the Invention

[0006] One objective of this invention is to propose a debugging and simulation method and system for vehicle electrical control units based on digital twins. Addressing the shortcomings of existing technologies such as inaccurate cross-domain data alignment, unmeasurable channel-level latency, difficulty in ensuring timely communication during congestion, and insufficient security of debugging actions, this invention proposes a technical solution that employs a unified time base and latency estimation, constructs a multi-component consistency differential spectrum and confidence level, uses an alignment strategy of "baseline compensation + event correction," and combines semantic encoding with deterministic and / or priority scheduling, along with arbitration and adaptive degradation under a secure invariant set. This invention possesses the advantages of achieving millisecond-level bidirectional collaborative debugging, improving consistency convergence and security, while also considering bandwidth efficiency and smooth control handover.

[0007] A vehicle electrical control unit debugging and simulation system based on digital twin according to an embodiment of the present invention is characterized in that it includes:

[0008] The data aggregation and time reference module is used to collect data from the physical side and the digital twin side, establish a unified time reference, and estimate the channel-level end-to-end latency.

[0009] The consistency assessment module is used to align and calculate consistency indices and their confidence levels that include amplitude, time series, event and derivative components under a unified time base.

[0010] The synchronization and correction module is used to calculate channel-level delay compensation based on the consistency index and delay parameters, and to perform event-level alignment when event misalignment is detected, and output a consistent state.

[0011] The semantic communication and scheduling module is used to perform semantic encoding configuration and implement deterministic and / or priority scheduling based on the expected reduction amount, confidence level and deadline of the consistency index.

[0012] The arbitration and security debugging module is used to generate, filter, and limit debugging actions, and implement soft handover and gating of control rights based on the security invariant set and confidence level;

[0013] The cross-layer adaptive degradation module is used to perform tiered degradation when the confidence level is low or a security constraint is triggered.

[0014] The execution and iteration module is used to perform closed-loop execution at predetermined cycles and inject debugging actions into the physical system, while simultaneously feeding back new observations to update the digital twin.

[0015] A debugging and simulation method for an on-board electrical control unit based on digital twins according to an embodiment of the present invention, applied to the aforementioned debugging and simulation system for an on-board electrical control unit based on digital twins, is characterized by comprising:

[0016] S1. Collect bus messages, pin-level input / output signals and sensor quantities, task execution traces and interrupt traces and diagnostic information from the physical side, and collect the predicted status and events from the digital twin side, establish a unified time reference, and estimate the end-to-end transmission delay and processing delay of each acquisition channel.

[0017] S2. Under a unified time reference, time-align the state of the digital twin side with the observation of the physical side, calculate the multi-component consistency difference spectrum composed of amplitude difference, timing deviation, event misalignment and derivative difference, and output the corresponding confidence level based on uncertainty assessment.

[0018] S3. Based on the consistency difference spectrum and delay estimation, the delay compensation amount of each channel is calculated using a time-series prediction model. The consistency state is obtained by combining continuous time state estimation and adaptive filtering. When an event misalignment is detected, the event-level micro-alignment is triggered. The event offset is obtained by dynamically time-warping the edge sequence of the interruption or message, and the delay compensation amount is corrected accordingly.

[0019] S4. Using the reduction of the consistency differential spectrum as the benefit index, and combining the confidence level and the deadline of each message, calculate the semantic benefits and priorities of signals and messages, perform semantic compression and joint source channel coding, redundancy configuration and retransmission window allocation, and implement deterministic scheduling and priority scheduling on the vehicle network to prioritize the communication flow that contributes to consistency convergence when bandwidth is limited or congested.

[0020] S5. Generate debugging action candidates based on consistency difference spectrum and confidence level, select debugging actions using a hierarchical strategy, and filter and limit the debugging action candidates through safety barrier constraints and prediction tests to obtain the actual execution actions that satisfy the safety invariant set. Calculate the soft handover weight of control authority based on consistency difference spectrum and confidence level, and perform gating and smooth handover of control intervention on the digital twin side and physical side.

[0021] S6. When the confidence level is lower than the threshold or a security constraint is triggered, an adaptive degradation strategy is executed.

[0022] S7. Repeat S2 to S6 in a millisecond-level loop, and inject the safety-constrained debugging actions into the physical vehicle electrical control unit or its test environment in real time. At the same time, feed back new observations from the physical side to the digital twin side so that the consistency differential spectrum gradually converges, thereby realizing real-time, bidirectional, and collaborative debugging between the digital twin and the physical vehicle electrical control unit.

[0023] Optionally, the establishment of a unified time reference and estimation of the end-to-end transmission delay and processing delay of each acquisition channel specifically involves: selecting the master clock as the global time reference and distributing it to each acquisition terminal; using time-stamped synchronization signals or common events to estimate the offset and frequency deviation between the local and global clocks; establishing a local-to-global time mapping; uniformly time-stamping bus messages, pin and sensor signals, and task and interrupt traces and converting them into global timestamps; estimating the transmission delay of each channel through round-trip ranging and event identification; recording time differences at key software points to estimate the processing delay; using recursive filtering to fuse the various estimates; and outputting the end-to-end delay, processing delay, jitter, and their confidence level for each channel, which serve as the basis for subsequent time alignment and delay compensation.

[0024] Optionally, the consistency difference spectrum is specifically as follows: based on the unified time base and delay parameters obtained in step S1, the corresponding signals of the digital twin side and the physical side are aligned, denoised and normalized, and resampled at multiple rates within a sliding window. Then, the amplitude difference (absolute error and mean square error), timing deviation (residual delay and jitter are obtained based on cross-correlation and phase offset), event misalignment (event matching is performed on message edges, task switching and interrupt triggering, and time offset and false alarms are statistically analyzed), and derivative difference (difference measurement is performed on the first and second derivatives of the smoothed signal) are calculated respectively. The signals are then weighted and aggregated according to the signal importance and the dimension normalization coefficient to form the consistency difference spectrum at the channel level and the system level.

[0025] The confidence level corresponding to the uncertainty assessment output is specifically as follows: the confidence level of the integrated sensor and link noise level, the uncertainty of the model or filter prediction, the alignment quality index and the out-of-distribution detection results are standardized and weighted to obtain the component level, channel level and system level confidence level. Based on this, the consistency difference spectrum is weighted and gated to output the difference spectrum and confidence level results for subsequent use.

[0026] Optionally, the uniform state is a state vector obtained under a unified time reference after time delay compensation and filtering;

[0027] The delay compensation amount is specifically as follows: based on the channel delay and timing deviation components, a coarse estimate of the residual delay (including the cross-correlation peak position, the hysteresis of the filter innovation, and the phase drift) is calculated for each channel within a sliding window. The residual delay of the next cycle is then predicted using a timing prediction model feedforward. The two are fused through adaptive filtering to obtain the channel-level baseline delay compensation amount. Based on this, time mapping and resampling are performed on the observations or predictions, driving the continuous-time state estimator to output a consistent state. Subsequently, for discrete events, edge sequences such as messages, interruptions, and task switching are matched using dynamic... Time warping yields the event time offset. Robust statistics (including median or confidence-weighted average) are taken as the event offset and used as a correction term to be added to the corresponding channel's delay compensation or to replace the fast component, forming a combined compensation of "baseline compensation + event correction". To suppress jitter, step size and rate of change constraints are set for the compensation update, and group-level constraints are applied (the same bus shares a common baseline compensation, and the signal is only fine-tuned). When the confidence is low, the update is frozen or updated in small steps. Finally, the updated channel-level delay compensation parameters are output for time alignment and state estimation in the next cycle.

[0028] Optionally, the implementation of deterministic scheduling and priority scheduling specifically involves: based on the real-time link status (including bandwidth utilization, latency jitter, and packet loss) and the cutoff dates of each flow, combined with the expected reduction in the consistency differential spectrum and its confidence level, calculating the semantic gain and urgency of each signal and message and determining its priority, and adaptively configuring the code rate and protection level of semantic compression and joint source channel coding accordingly. Higher precision and necessary redundancy are allocated to high-priority flows, and retransmission windows are set. Deterministic or priority scheduling is implemented in the vehicular Ethernet and controller area network to ensure timely delivery of critical flows. When congestion is detected, high-gain flows are prioritized. Degradation is achieved by reducing the code rate and transmission frequency of non-critical flows, tightening retransmissions, and temporarily silencing low-priority flows when necessary. Priority, code rate, redundancy, and scheduling parameters are updated in a closed loop at millisecond intervals based on actual arrival time, bit errors, packet loss, and differential spectrum changes to maximize consistency convergence under limited bandwidth.

[0029] Optionally, the debugging actions include parameter backfeeding, message injection, task tick perturbation, and environmental stimulus injection;

[0030] Specifically, S5 involves defining the action parameter space (including target object, amplitude, step size, duration, and frequency) for parameter backfeeding, message injection, task beat perturbation, and environmental stimulus injection, and loading the safety invariant set and the physical and functional constraints of the actuator, bus, and task.

[0031] Based on the components and channels with the highest contribution in the consistency difference spectrum, and combined with the confidence level to screen credible targets, several candidate actions are generated. The "expected reduction in the difference spectrum" is used as the benefit, and the risk and resource consumption penalties are superimposed to obtain a comprehensive score.

[0032] The higher layer selects the intervention type and target subsystem, while the lower layer determines specific parameters (including amplitude, duration, injection location, and perturbation phase). Confidence level is used for gating and amplitude scaling. At low confidence levels, only low-amplitude, short-duration, or observational actions are allowed.

[0033] Apply safety barrier constraints and boundary conditions (including speed, torque, current, temperature, voltage, bus load limit, task duty and jitter limits) to each candidate action. If the conditions are not met, the action will be eliminated. The action can be retried by limiting the amplitude, shortening the duration, or changing the point of action.

[0034] In the short prediction time domain, digital twins are used to perform look-ahead simulations to evaluate the probability of constraint violation and the deviation from the worst case under model uncertainty and disturbance. If the threshold is exceeded, the action level is reduced or the action is rejected. If the action passes, it is solidified as an executable action.

[0035] The weights of the control intervention on the digital twin side and the physical side are calculated based on the consistency differential spectrum and confidence level. Amplitude limiting and gradual filtering are used to achieve shockless switching. Dwell time and rate limits are set. When safety constraints are triggered or confidence level drops sharply, the weights are quickly reduced or the system switches back to the physical side.

[0036] Actions are scheduled and executed based on scores and conflict relationships. During execution, key constraints and differences in the spectrum are continuously monitored. If out-of-bounds or negative divergence occurs, the action is immediately rolled back, canceled, or downgraded. At the same time, action-response samples are recorded for subsequent adaptive updates of strategies and thresholds.

[0037] Optionally, the adaptive degradation strategy includes freezing debugging actions, reducing the coding rate and redundancy of non-critical communication flows, and switching to observer-only mode;

[0038] Specifically, S6 is as follows: when the confidence level is lower than the threshold or a security constraint is triggered, a graded degradation is initiated with hysteresis and dwell time: the debugging action being executed is frozen or rolled back and new actions are gated; the communication layer reduces the bit rate and frequency of non-critical flows and tightens retransmissions; critical flows are preserved or protected; the control side attenuates the digital twin control authority according to the level and limits the amplitude and rate; if necessary, it switches back to the physical side without impact to maintain safe output; the synchronization and estimation sides reduce the computational load (relax the step size, window, and pause fast micro-alignment) to ensure basic alignment; and the highest level enters the observation-only mode.

[0039] Once the recovery criteria are met (confidence level above the upper threshold, positive safety margin, and dwell time maintained), the action, bit rate, and redundancy are gradually restored in the order of "trial run - partial recovery - full recovery". A change rate limit is applied to avoid oscillations. At the same time, degradation and recovery events are recorded for adaptive updates of thresholds and policies.

[0040] Optionally, S7 specifically involves: running a loop with a fixed millisecond cycle and using a sliding window and double buffer to ensure real-time performance; executing S2-S5 in a pipelined manner in each cycle and monitoring the triggering conditions of S6 in parallel; performing a final safety check and short-term prediction on the debugging actions and scheduling instructions to be executed; and injecting them through post-atomicization.

[0041] S4 deterministically transmits and records timestamps and ACKs or timeouts as feedback via Ethernet or CAN, and feeds back new physical observations with unified timestamps to drive the closed-loop update of digital twin and state estimation.

[0042] Based on the consistency difference spectrum trend and confidence, the weights, step size, window, bit rate, and redundancy are adaptively adjusted, and S6 is triggered in advance when divergence or approximation constraints occur.

[0043] Real-time monitoring of computation and bandwidth margins; lightweight degradation of timeout risks to ensure critical path arrival; isolation and rollback in case of link or execution anomalies, and switching to observation-only mode; recording of differential spectrum, confidence level, compensation amount and execution results for each cycle for traceability and parameter and threshold updates to promote gradual convergence of the consistency differential spectrum.

[0044] The beneficial effects of this invention are:

[0045] (1) Unified driving index and three-way closed loop: "Multi-component consistency differential spectrum + confidence" is used as the common optimization / gating signal of the synchronization layer, communication layer and arbitration layer to form millisecond-level closed loop collaboration, so that time alignment, link resource allocation and security debugging decisions are coordinated and converged with the target.

[0046] (2) The combined mechanism of baseline delay compensation and event-level micro-alignment: the residual delay is compensated by "time series prediction + adaptive filtering". When event misalignment is detected, differentiable DTW is used to estimate the event offset and superimpose it as a correction term, taking into account the alignment robustness of continuous quantities and discrete events.

[0047] (3) Cross-layer coupling of semantic communication and security arbitration: The communication layer drives priority, code rate, redundancy and retransmission window with "expected differential spectrum reduction, confidence level and deadline"; the arbitration layer generates candidates with a hierarchical strategy and uses CBF+risk-sensitive MPC to screen and limit the amplitude, and finally realizes soft handover between digital twin and physical side through confidence level gating. Attached Figure Description

[0048] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:

[0049] Figure 1 This is a flowchart of a debugging and simulation method for an on-board electrical control unit based on digital twin proposed in this invention;

[0050] Figure 2 This is a comparison chart of convergence of the system-level consistency difference spectrum. Detailed Implementation

[0051] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.

[0052] A digital twin-based vehicle electrical control unit debugging and simulation system, characterized in that it includes:

[0053] The data aggregation and time reference module is used to collect data from the physical side and the digital twin side, establish a unified time reference, and estimate the channel-level end-to-end latency.

[0054] The consistency assessment module is used to align and calculate consistency indices and their confidence levels that include amplitude, time series, event and derivative components under a unified time base.

[0055] The synchronization and correction module is used to calculate channel-level delay compensation based on the consistency index and delay parameters, and to perform event-level alignment when event misalignment is detected, and output a consistent state.

[0056] The semantic communication and scheduling module is used to perform semantic encoding configuration and implement deterministic and / or priority scheduling based on the expected reduction amount, confidence level and deadline of the consistency index.

[0057] The arbitration and security debugging module is used to generate, filter, and limit debugging actions, and implement soft handover and gating of control rights based on the security invariant set and confidence level;

[0058] The cross-layer adaptive degradation module is used to perform tiered degradation when the confidence level is low or a security constraint is triggered.

[0059] The execution and iteration module is used to perform closed-loop execution at predetermined cycles and inject debugging actions into the physical system, while simultaneously feeding back new observations to update the digital twin.

[0060] refer to Figure 1 A digital twin-based debugging and simulation method for vehicle electrical control units, applied to a digital twin-based vehicle electrical control unit debugging and simulation system, characterized in that it includes:

[0061] S1. Collect bus messages, pin-level input / output signals and sensor quantities, task execution traces and interrupt traces and diagnostic information from the physical side, and collect the predicted status and events from the digital twin side, establish a unified time reference, and estimate the end-to-end transmission delay and processing delay of each acquisition channel.

[0062] S2. Under a unified time reference, time-align the state of the digital twin side with the observation of the physical side, calculate the multi-component consistency difference spectrum composed of amplitude difference, timing deviation, event misalignment and derivative difference, and output the corresponding confidence level based on uncertainty assessment.

[0063] S3. Based on the consistency difference spectrum and delay estimation, the delay compensation amount of each channel is calculated using a time-series prediction model. The consistency state is obtained by combining continuous time state estimation and adaptive filtering. When an event misalignment is detected, the event-level micro-alignment is triggered. The event offset is obtained by dynamically time-warping the edge sequence of the interruption or message, and the delay compensation amount is corrected accordingly.

[0064] S4. Using the reduction of the consistency differential spectrum as the benefit index, and combining the confidence level and the deadline of each message, calculate the semantic benefits and priorities of signals and messages, perform semantic compression and joint source channel coding, redundancy configuration and retransmission window allocation, and implement deterministic scheduling and priority scheduling on the vehicle network to prioritize the communication flow that contributes to consistency convergence when bandwidth is limited or congested.

[0065] S5. Generate debugging action candidates based on consistency difference spectrum and confidence level, select debugging actions using a hierarchical strategy, and filter and limit the debugging action candidates through safety barrier constraints and prediction tests to obtain the actual execution actions that satisfy the safety invariant set. Calculate the soft handover weight of control authority based on consistency difference spectrum and confidence level, and perform gating and smooth handover of control intervention on the digital twin side and physical side.

[0066] S6. When the confidence level is lower than the threshold or a security constraint is triggered, an adaptive degradation strategy is executed.

[0067] S7. Repeat S2 to S6 in a millisecond-level loop, and inject the safety-constrained debugging actions into the physical vehicle electrical control unit or its test environment in real time. At the same time, feed back new observations from the physical side to the digital twin side so that the consistency differential spectrum gradually converges, thereby realizing real-time, bidirectional, and collaborative debugging between the digital twin and the physical vehicle electrical control unit.

[0068] In this embodiment, the specific implementation of step S1 is as follows:

[0069] The system selects the hardware master clock of the test platform as the global time reference. It distributes the time to each acquisition terminal via timestamp synchronization signals or common events, and uses least-squares fitting within a sliding window to establish an affine mapping from local to global time. This unifies the local time of each acquisition terminal onto the same global time axis. The mapping relationship is as follows:

[0070] ;

[0071] in This indicates that the acquisition end The global time estimate obtained by mapping the local time of any of the above events. Indicates the data acquisition end Recorded local timestamps Indicates the data acquisition end Frequency offset compensation coefficient relative to the global master clock, Indicates the data acquisition end Time offset estimation relative to the global master clock Indicates the channel index;

[0072] After unifying the time scale, bidirectional timing is used for network channels to obtain unidirectional transmission delay observations. The master end is at the global time. A synchronization request is sent, and the global time is obtained by mapping the received and transmitted local time at the acquisition end as described above. and The master end is in global time. If the feedback is received, the one-way transmission delay is estimated as follows:

[0073] ;

[0074] in Indicates channel One-way transmission delay estimation, This represents the global time at which the request was sent by the master. This represents the time after the data acquisition terminal receives the request and maps it to the global time. This represents the time after the data is sent back from the acquisition end and mapped to the global time. Indicates the global time received and transmitted by the master end;

[0075] For non-network channels such as pin and sensor signals, select a common identifiable event or inject a synchronization marker, record and map it to the global timeline simultaneously at both the master and acquisition ends, using the arrival time difference as the time axis. Supplementary observations are used for fusion together with network observations;

[0076] To estimate processing latency, timestamp points are placed along the critical path of the control software under test to convert the local time of inputs and outputs into global time. and Calculate the first Processing delay for subsamples:

[0077] ;

[0078] in Indicates channel In the sample index Processing delay estimation at the location, Indicates the first The time of the secondary processing link input on the global time axis. Indicates the first The time of the secondary processing link output on the global timeline. Indicates the sample index;

[0079] To obtain a continuous and stable end-to-end delay estimate, a cyclic method is used at the millisecond level. By using an exponential recursive method to fuse transmission and processing delays, we obtain:

[0080] ;

[0081] in Indicates channel In the loop End-to-end delay estimation at time point, Indicates channel The fusion step size coefficient, and These represent the loops. Always on the channel The transmission delay and processing delay are observed or estimated. Indicates a circular index;

[0082] Within the sliding window The time delay jitter is obtained by statistically analyzing the dispersion of the sequence. Based on this, the normalized confidence level is given:

[0083] ;

[0084] in Indicates channel confidence level Indicates channel Time delay jitter estimation based on sliding window variance This represents the reference jitter constant used for scale normalization;

[0085] The final output is the end-to-end delay estimate for each channel. Processing delay statistics Shaking and its confidence level and mapping parameters With fusion step size Online updates serve as the basis for subsequent time alignment and latency compensation.

[0086] In this embodiment, the specific implementation of step S2 is as follows:

[0087] Based on the unified time reference and channel delay parameters obtained in step S1, the corresponding signals of the digital twin and the physical twin are time-aligned, denoised, and normalized within a sliding window, and different sampling rates are resampled to a common sampling interval. Set up a passage In the window The alignment sequences within are respectively and And note:

[0088] ;

[0089] in Indicates channel The physical side in the first Normalized values ​​of each global sampling point Indicates channel Digital twin side in the first Normalized values ​​of each global sampling point Indicates channel The set of sliding window indices Indicates the number of samples within the window. Indicates the common sampling interval after resampling;

[0090] The amplitude component is measured using the root mean square error:

[0091] ;

[0092] in Indicates channel The amplitude difference index within the current window;

[0093] The residual time delay is obtained from the cross-correlation peak value of the timing deviation component. First, the optimal lag that makes the cross-correlation reach its peak value is calculated:

[0094] and take ;

[0095] in Indicates channel In the lag search set Internally, it maximizes the cross-correlation and lag index. Indicates channel Allowed search of discrete lag sets, Indicates channel Residual delay estimation, Indicates channel The timing deviation index;

[0096] The event misalignment component is obtained through edge event matching. Let the set of matching event pairs be... and The physical side and the twin side The global times for each matched event are as follows: and The false alarm rate and the missed detection rate within the window were respectively and ,definition:

[0097] ;

[0098] in Indicates channel Event misalignment indicator and These represent the penalty coefficients for missed detections and false alarms, respectively. and All events are based on a unified time standard. Indicates the number of matched event pairs. A set of indices representing the matching event pairs;

[0099] The derivative component is used to measure differences in trends of change, denoted as... and They are respectively at the sampling interval Top and The discrete derivative obtained by forward differencing is then measured using the root mean square error.

[0100] ;

[0101] in Indicates channel The derivative difference index, and Indicates the interval The discrete first derivative obtained on;

[0102] The four components are aggregated into a channel-level consistency index based on their importance and dimensional normalization weights:

[0103] ;

[0104] in Indicates channel Consistency difference aggregation index, They represent channels respectively. The four components have non-negative weights and satisfy the following conditions: ;

[0105] The confidence score fusion takes into account information such as noise, prediction uncertainty, alignment residuals, and out-of-distribution detection, and takes:

[0106] ;

[0107] in Indicates channel confidence level Indicates channel The normalized value of noise intensity. Indicates channel The normalized amount of uncertainty in the model or filter prediction. Indicates channel The normalized value of the alignment residuals, Indicates channel The normalized value of the out-of-distribution detection score. The non-negative fusion coefficient for the corresponding channel;

[0108] The system layer uses confidence-weighted aggregation with channel importance to obtain scalarized metrics:

[0109] ;

[0110] in This represents the system-level consistency difference index. This represents the set of channels being counted. and Indicates channel Weighting coefficients at the system layer;

[0111] The final output consists of component-level, channel-level, and system-level consistency difference spectra and their confidence levels for use in subsequent steps.

[0112] In this embodiment, the specific implementation of step S3 is as follows:

[0113] The system loops in milliseconds. The timing deviation, event misalignment, and confidence level output from step S2 are used to evaluate each channel. A delay compensation structure of "baseline compensation + event correction" is constructed to drive state estimation and obtain a consistent state. First, a prediction-correction model is used to form the baseline compensation amount for the residual delay, taking:

[0114] ;

[0115] in Indicates channel In the loop Baseline delay compensation estimation at time point, This indicates the update value that will be used in the next loop. and Indicates a channel Coefficients and biases of time-series prediction models with slow residual delay drift. This represents the adaptive gain that is positively correlated with the confidence level. Indicates in the loop The channel obtained from step S2 Residual delay observation;

[0116] When an edge sequence match is detected and an event misalignment exists, in the set of matching event pairs The event time offset is obtained using robust statistics:

[0117] ;

[0118] in Indicates channel Event-level time correction amount, and They represent channels respectively. No. The timing of a matching event on the physical and digital twin sides under a unified time base. Indicates channel Matching event index set within the window;

[0119] Subsequently, the event correction is superimposed on the baseline compensation using confidence gating, and amplitude and rate of change constraints are applied to obtain the combined compensation:

[0120] ;

[0121] in Indicates channel In the loop The combined delay compensation amount will be used. This indicates that an upper bound on the amplitude is applied simultaneously. Upper bound of the rate of change of adjacent cycles The amplitude limiting and speed limiting operators, Indicates that the channel The event correction weight is determined by the current confidence level; at low confidence levels... Take the smaller value to freeze or update in small steps;

[0122] Channels within the same bus group share common baseline components and only allow channel-level fine-tuning to meet group-level consistency constraints, thereby avoiding conflicting compensations from the same source link; the observations of each channel are processed... Time mapping at global sampling time Resampled and stacked into synchronous observation vectors ;

[0123] in Indicates the first The global timestamp of the next loop, Indicates channel Normalized observations at a given global time;

[0124] The unified state is then updated using a predicted correction structure:

[0125] ;

[0126] in and Representing loops and The system-consistent state estimation, and These represent the given state transition and observation models of the digital twin, respectively. Indicates a loop Known external inputs or control variables, This represents the gain matrix that aligns with the observation reliability and noise level.

[0127] Final output and It also records the time alignment and corrections used in the next cycle.

[0128] In this embodiment, the specific implementation of step S4 is as follows:

[0129] The system uses the component-level and channel-level consistency differential spectrum and its confidence level obtained in step S2 as a basis, and combines the real-time status of the link and the deadline of each message to perform semantic coding configuration and cross-network deterministic and priority scheduling of communication.

[0130] First, for each communication stream or message Define semantic benefits to quantify their contribution to consistency convergence and reflect deadline urgency, taking:

[0131] ;

[0132] in Indicates message The semantic benefit scalar, Indicates message The confidence level inherited by the channel or its fusion result. This indicates that if the message is successfully transmitted and correctly decoded in the current cycle... The expected reduction in the consistency difference index of the system or target channel. Indicates message The remaining time margin before the deadline, This represents an extremely small positive number set to avoid division by zero;

[0133] Based on this, priority scores that can be used for scheduling and resource allocation are given:

[0134] ;

[0135] in Indicates message Priority score, This represents the trade-off coefficient between semantic benefits and urgency. Indicates message Urgency score based on residual margin or default risk normalization;

[0136] Coding and protection aspects Perform monotonic mapping to configure the semantic compression bitrate and redundancy level, taking:

[0137] ;

[0138] in Indicates message The target code rate or quantization precision of semantic compression or joint source-channel coding. Indicates message Redundancy or protection levels, such as erasure coding redundancy or retransmission window size, and Representing messages respectively Allowed minimum and maximum bitrate bounds, Indicates message The smallest redundancy level, This represents the scaling factor that maps priority to the redundancy scale;

[0139] In millisecond scheduling cycles Within this framework, deterministic and priority-based joint scheduling is performed with link availability budget as a constraint, which simplifies to the following selection model:

[0140] s. t. ;

[0141] in Indicates the period Is a scheduling message available? Zero-one decision variables Represents the set of candidate messages. This indicates the message under the current configuration. The consumption of link bandwidth budget includes overhead such as payload plus coding and redundancy. Indicates period The available bandwidth or time slot budget for this link;

[0142] When congestion or insufficient budget is detected, a congestion factor is calculated, and low-priority flows are downgraded and rolled back to ensure the arrival of high-yield flows. The factor is:

[0143] ;

[0144] in Indicates period The congestion scaling factor. and These respectively represent the message The new bitrate and new redundancy level after the downgrade, along with scaling and lower bounds, are used together to ensure that critical streams maintain the necessary protection.

[0145] On the Ethernet side When messages are mapped to reserved time slots or when gating is triggered in a time-sensitive network, deterministic transmission is ensured. On the CAN side, this means... The data is converted into arbitration identifiers to form priority scheduling, and is periodically adjusted based on actual changes in time-of-arrival feedback, bit error and packet loss statistics, and consistency differential spectrum. and The calculated factors are fine-tuned in a closed loop and updated in the next cycle. It is estimated that, under constrained conditions, link resources will be prioritized for communication flows that contribute more to consistency convergence and to improve overall timeliness and bandwidth efficiency.

[0146] In this embodiment, the specific implementation of step S5 is as follows:

[0147] The system first generates a candidate set from four types of actions—parameter backfeeding, message injection, task beat perturbation, and environmental stimulus injection—based on the consistency difference spectrum and confidence level obtained in step S2, and then limits the action parameter space. It then uses components and channels with higher contribution to filter credible targets and form a candidate action set. Subsequently, a scoring system was constructed based on "improved expected consistency - risk - resource consumption" and used for ranking and admission. The definition is as follows:

[0148] ;

[0149] in Indicates candidate actions The overall score, This represents the weighting coefficient for the benefit item. Indicates action The fusion results of the confidence levels of the channels involved Indicates the execution of an action The expected reduction in system-level consistency metrics in the current cycle. This represents the weighting coefficient for the risk item. Indicates action Risk measures within the short forecast time domain, such as worst-case deviation or normalized indicators of constraint margin depletion. This represents the weighting coefficient for resource usage. Indicates action Metrics for the consumption of computing and link resources;

[0150] To suppress intervention intensity and satisfy boundary conditions at low confidence levels, confidence gating and amplitude / rate limiting are applied to the action amplitude, let:

[0151] ;

[0152] in Indicates action The actual execution amplitude, This indicates that the input is subjected to a range test. Limiting operators, and These represent actions derived from the safety invariant set. The minimum and maximum allowable amplitude, Indicates action The amplitude scaling factor, Indicates action Reference amplitude under unconstrained conditions;

[0153] For security verification, the system uses digital twins in the short prediction time domain. Perform look-ahead simulation to calculate the constraint violation probability and set an admission threshold, taking:

[0154] ;

[0155] in Indicates action The constraint violates probability. Represents a probability operator. Indicates the first A security barrier function whose value is greater than zero indicates that it is located inside the security invariant set. Indicates the current moment Apply action Time for future moments System state prediction, This represents the time variable within the prediction time domain. This indicates the maximum allowed violation probability threshold. If the threshold is not met, the action level is reduced or the action is rejected. The action can be retried by amplitude compression, duration reduction, or change of the point of action.

[0156] For actions that pass the security check, the system calculates the control weights of the digital twin and the physical side based on the consistency difference spectrum and confidence level, and uses smoothing filtering and dwell time strategies to achieve soft handover, letting:

[0157] ;

[0158] in and They represent the first With the The digital twin side controls the weights in each loop. Indicates physical side control weights and their relationship with Complementary This indicates that the input will be truncated to a range. The operator, This represents the smoothing coefficient for weight updates. and The coefficient is a non-negative fusion coefficient. This indicates the aggregate confidence level of the currently intervened channel or subsystem. This indicates the actual improvement in consistency measured in the previous period to encourage effective intervention;

[0159] When multiple candidate actions exist, the system performs lightweight scheduling using a selection variable within the current period to balance score and resource budget, taking the following approach:

[0160] s. t. ;

[0161] in Indicates whether to execute an action in this cycle. Zero-one variables, This indicates the available resource budget for the current period, such as the available bus and computing quota. If there are conflicts among the candidates, mutually exclusive combinations are eliminated before solving, or high-scoring and low-conflict actions are heuristically prioritized.

[0162] During execution, the system continuously monitors changes in key constraints and consistency difference spectrum and immediately backs down, cancels, or downgrades when out-of-bounds or negative divergence occurs. At the same time, it records "action-response" samples for subsequent adaptive updates and retraining of thresholds and strategies. Thus, under the premise of satisfying the safety invariant set, it realizes the generation, screening, amplitude limiting, and stable injection of debugging actions through confidence gating and soft switching mechanisms.

[0163] In this embodiment, the specific implementation of step S6 is as follows:

[0164] The system employs a tiered degradation mechanism with hysteresis and dwell time, and integrates coordinated degradation and gradual recovery between the control and communication sides. First, a degradation trigger indicator is constructed based on system-level confidence, safety margin, and short-term predicted risk.

[0165] ;

[0166] in Indicates the first An indicator of whether a cycle triggers a degradation. Indicates an indicator function, Indicates the first The system-level confidence level obtained by fusion of multiple cycles This indicates the lower threshold for triggering a downgrade. Indicates the first The minimum safety margin of each cycle and This indicates approaching or entering an unsafe zone. This represents the probability of constraint violation in short-term forecasting. This represents the maximum permissible probability threshold.

[0167] To avoid frequent switching and reflect hysteresis and dwell time constraints, an incremental level update rule is adopted:

[0168] ;

[0169] in Downgrade level This means truncating the input to a range. The operator, Indicates the increment of level. This indicates the cumulative time spent in the area since the last class change. Indicates the minimum dwell time threshold. The upper threshold for recovery is indicated by the symbol "". "Indicates logical AND;

[0170] when During the ascent, the system freezes or rolls back ongoing debugging actions and gates new actions. The control side attenuates the digital twin control authority according to its level and, if necessary, switches back to the physical side without impact. Its weights are normalized using a level function.

[0171] ;

[0172] Perform a smooth update as follows:

[0173] ;

[0174] in and They represent the first With the A cyclic digital twin side control weight, Indicates the physical side control weights and is related to Complementary This represents the weight decay coefficient. This means truncating the input to a range. The operator, Indicates the level normalization scale;

[0175] The communication layer's reduction of bit rate and redundancy for non-critical flows, and its preservation or enhancement of protection and tightening of retransmission windows for critical flows, can be uniformly expressed using a level-based scaling law as follows:

[0176] ;

[0177] in and Representing messages respectively The new bitrate and new redundancy level under the downgrade and Indicates message Current bitrate and redundancy, and Representing messages respectively Minimum allowed bit rate and minimum redundancy, Indicates message Is it a critical flow? This represents the non-critical stream bitrate scaling factor. and These represent the coefficients for reducing redundancy in non-critical flows and enhancing redundancy in critical flows, respectively. Same as the definition above;

[0178] The synchronization and estimation layer reduces computational load to ensure basic alignment. At higher levels, it widens the integration step size, shortens the sliding window, and can pause fast micro-alignment to avoid timeouts.

[0179] When the recovery criterion is met, i.e. and After maintaining the dwell time, the system gradually recovers to the target setting using a uniform rate-limited smoothing law:

[0180] ;

[0181] in and Indicates the first With the The parameters to be recovered in each cycle (which can be specified) or wait), This represents the target value under normal operating conditions. Indicates the recovery step size coefficient. Indicates the maximum permissible recovery rate;

[0182] when Enter watch-only mode and The system is compressed to zero while retaining the minimum necessary protection and recording functions in communication. Throughout the process, the system continuously records degradation and recovery events and key parameters for adaptive updates of thresholds and coefficients.

[0183] In this embodiment, the specific implementation of step S7 is as follows:

[0184] The system organizes a closed-loop process with a fixed cycle at the millisecond level, employing a sliding window and double buffering to ensure timeliness and injection atomicity. Within each cycle, S2 to S5 are executed in a pipelined manner while the triggering conditions of S6 are monitored in parallel to form a prediction-verification-injection-feedback-adaptive loop. Let the global time series be... And the fixed period is The periodic update law is:

[0185] ;

[0186] in Indicates the first Global timestamps for each loop This indicates the fixed cycle period set by the system. Indicates a circular index;

[0187] Before injection, the candidate debugging actions and scheduling instructions obtained from S2 to S5 undergo final security checks and short-term predictions. Secure access and atomic injection are achieved using gating variables. Let the candidate injection vector be denoted as... The actual injection vector is Safety gate control indication is Then we have:

[0188] ;

[0189] in Indicates the first A combination vector of periodically injected debugging actions and scheduling instructions. This indicates that after security verification, on the [number]th [day]... The combined vector actually injected in the periodic period, Indicator quantity indicating whether security access is met. Indicates an indicator function, Indicates the first The minimum safety margin of the period (e.g., the minimum value of the safety barrier function). This represents the probability of constraint violation within the short prediction time domain. This indicates a violation of the probability interval;

[0190] To ensure the atomicity of the injection, a double-buffered commit is used, denoted as the preparation buffer and the activation buffer, respectively. and A one-time handover will be conducted after security clearance is granted.

[0191] ;

[0192] in Indicates the first The set of instructions and actions that have completed security checks and are ready for injection at the end of the cycle. Indicates the first The set to be executed at the start of the cycle;

[0193] The communication side performs deterministic transmission via Ethernet or CAN according to the scheduling result of S4 and records the timestamp and feedback. Let the message... In the The periodic global timestamps for sending and receiving are respectively and Confirmation signal is Then the success indication and the measured delay are defined as follows:

[0194] ;

[0195] in Indicates message In the The amount of data indicating whether the period was successfully delivered. Indicates message In the Periodic end-to-end network latency, and All are timestamps based on a unified time standard;

[0196] New physical observations are fed back at a unified timescale to drive closed-loop updates of digital twins and state estimates, and are integrated with... and Together they are used for error attribution and model self-correction;

[0197] Lightweight adaptive optimization of cross-layer parameters is performed based on the trend of the consistency difference spectrum and the system-level confidence level. Let the system-level consistency index be at the [missing information - likely a specific value or index]. The scalar metric of the period is System-level confidence level is The vector that needs to be tuned is (This can include weights, step size, window, bitrate, and redundancy, etc.), define the convergence trend quantity and adaptive step size, and perform convex combination fine-tuning:

[0198] ;

[0199] in This represents the increment of the system-level consistency metric. Indicates the first The step size of the period for parameter adjustment. This represents the step size sensitivity coefficient. Indicates the upper bound of the step size. This indicates a conservative configuration prioritizing safety and timeliness.

[0200] To ensure the critical path completes on time, the system monitors computational and bandwidth reserves in real time and implements minor degradation for timeout risks. The relative timeout risk is defined as:

[0201] ;

[0202] in Indicates the first The relative timeout risk of the cycle, Indicates the first Calculate the actual usage time within the period. Indicates the first Estimation of network transmission and reception time within a period;

[0203] Sum and The ratio is used to determine whether to reduce the bit rate, frequency, or temporarily silence low-priority tasks and non-critical flows. If consistency divergence or approximation constraints are detected, the S6 degradation process is triggered in advance. Throughout the process, the data for each cycle is continuously recorded. The latency compensation parameters and execution feedback of key channels are used to trace and update thresholds and parameters offline and online to drive the gradual convergence of the consistency difference spectrum.

[0204] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. A debugging and simulation system for an on-board electrical control unit based on digital twins, characterized in that, include: The data aggregation and time reference module is used to collect data from the physical side and the digital twin side, establish a unified time reference, and estimate the channel-level end-to-end latency. The consistency assessment module is used to align and calculate consistency indices and their confidence levels that include amplitude, time series, event and derivative components under a unified time base. The synchronization and correction module is used to calculate channel-level delay compensation based on the consistency index and delay parameters, and to perform event-level alignment when event misalignment is detected, and output a consistent state. The semantic communication and scheduling module is used to perform semantic encoding configuration and implement deterministic and / or priority scheduling based on the expected reduction amount, confidence level and deadline of the consistency index. The arbitration and security debugging module is used to generate, filter, and limit debugging actions, and implement soft handover and gating of control rights based on the security invariant set and confidence level; The cross-layer adaptive degradation module is used to perform tiered degradation when the confidence level is low or a security constraint is triggered. The execution and iteration module is used to perform closed-loop execution at predetermined cycles and inject debugging actions into the physical system, while simultaneously feeding back new observations to update the digital twin.

2. A debugging and simulation method for an on-board electrical control unit based on digital twins, applied to the debugging and simulation system for an on-board electrical control unit based on digital twins as described in claim 1, characterized in that, include: S1. Collect bus messages, pin-level input / output signals and sensor quantities, task execution traces and interrupt traces and diagnostic information from the physical side, and collect the predicted status and events from the digital twin side, establish a unified time reference, and estimate the end-to-end transmission delay and processing delay of each acquisition channel. S2. Under a unified time reference, time-align the state of the digital twin side with the observation of the physical side, calculate the multi-component consistency difference spectrum composed of amplitude difference, timing deviation, event misalignment and derivative difference, and output the corresponding confidence level based on uncertainty assessment. S3. Based on the consistency difference spectrum and delay estimation, the delay compensation amount of each channel is calculated using a time-series prediction model. The consistency state is obtained by combining continuous time state estimation and adaptive filtering. When an event misalignment is detected, the event-level micro-alignment is triggered. The event offset is obtained by dynamically time-warping the edge sequence of the interruption or message, and the delay compensation amount is corrected accordingly. S4. Using the reduction of the consistency differential spectrum as the benefit index, and combining the confidence level and the deadline of each message, calculate the semantic benefits and priorities of signals and messages, perform semantic compression and joint source channel coding, redundancy configuration and retransmission window allocation, and implement deterministic scheduling and priority scheduling on the vehicle network to prioritize the communication flow that contributes to consistency convergence when bandwidth is limited or congested. S5. Generate debugging action candidates based on consistency difference spectrum and confidence level, select debugging actions using a hierarchical strategy, and filter and limit the debugging action candidates through safety barrier constraints and prediction tests to obtain the actual execution actions that satisfy the safety invariant set. Calculate the soft handover weight of control authority based on consistency difference spectrum and confidence level, and perform gating and smooth handover of control intervention on the digital twin side and physical side. S6. When the confidence level is lower than the threshold or a security constraint is triggered, an adaptive degradation strategy is executed. S7. Repeat S2 to S6 in a millisecond-level loop, and inject the safety-constrained debugging actions into the physical vehicle electrical control unit or its test environment in real time. At the same time, feed back new observations from the physical side to the digital twin side so that the consistency differential spectrum gradually converges, thereby realizing real-time, bidirectional, and collaborative debugging between the digital twin and the physical vehicle electrical control unit.

3. The debugging and simulation method for an on-board electrical control unit based on digital twins according to claim 2, characterized in that: The establishment of a unified time reference and estimation of end-to-end transmission and processing delays for each acquisition channel are specifically as follows: a master clock is selected as the global time reference and distributed to each acquisition terminal; the offset and frequency deviation between the local and global clocks are estimated using time-stamped synchronization signals or common events; a local-to-global time mapping is established; bus messages, pin and sensor signals, and task and interrupt traces are uniformly time-stamped and converted into global timestamps; the transmission delay of each channel is estimated through round-trip ranging and event identification; the processing delay is estimated by recording time differences at key software points; recursive filtering is used to fuse the various estimates; and the end-to-end delay, processing delay, jitter, and confidence level of each channel are output, serving as the basis for subsequent time alignment and delay compensation.

4. The debugging and simulation method for an on-board electrical control unit based on digital twins according to claim 2, characterized in that: The consistency difference spectrum is specifically defined as follows: based on the unified time base and delay parameters obtained in step S1, the corresponding signals of the digital twin side and the physical side are aligned, denoised, normalized, and resampled at multiple rates within a sliding window. Subsequently, the amplitude difference, timing deviation, event misalignment, and derivative difference are calculated respectively. The amplitude difference is characterized by absolute error and mean square error. The timing deviation is characterized by residual delay and jitter obtained based on cross-correlation or phase offset. The event misalignment is characterized by time offset, missed detection statistics, and false alarm statistics obtained after matching events such as message edges, task switching, and interrupt triggers. The derivative difference is obtained by measuring the difference between the first and second derivatives of the smoothed signal. The signals are then weighted and aggregated according to signal importance and dimension normalization coefficients to form the consistency difference spectrum at the channel level and system level. The confidence level corresponding to the uncertainty assessment output is specifically as follows: the confidence level of the integrated sensor and link noise level, the uncertainty of the model or filter prediction, the alignment quality index and the out-of-distribution detection results are standardized and weighted to obtain the component level, channel level and system level confidence level. Based on this, the consistency difference spectrum is weighted and gated to output the difference spectrum and confidence level results for subsequent use.

5. The debugging and simulation method for an on-board electrical control unit based on digital twins according to claim 2, characterized in that: The unified state is a state vector obtained under a unified time reference after time delay compensation and filtering; The delay compensation amount is specifically calculated as follows: based on the channel delay and timing deviation components, a coarse estimate of the residual delay is calculated for each channel within a sliding window. The coarse estimate of the residual delay is determined by at least one of the cross-correlation peak position, the hysteresis of the filter innovation, and the phase drift. The residual delay of the next cycle is predicted using a time series prediction model feedforward. The two are then fused through adaptive filtering to obtain the channel-level baseline delay compensation amount. Based on this, time mapping and resampling are performed on the observation or prediction, driving the continuous-time state estimator to output a consistent state. Subsequently, for discrete events, edge sequences such as messages, interrupts, and task switching are matched, and dynamic time warping is used to obtain the event. The time offset is calculated by taking the median or confidence-weighted average of the event time offsets as the event offset amount. This offset is then used as a correction term and added to the corresponding channel's delay compensation amount or replacing the fast component, forming a combined compensation that combines baseline delay compensation and event time correction. To suppress jitter, step size and rate of change constraints are set for the compensation update, and group-level constraints are applied. The group-level constraints stipulate that each channel within the same bus group shares a common baseline compensation, and each signal is only adjusted at the channel level within a preset fine-tuning range. When the confidence level is low, the update is frozen or updated in small steps. Finally, the updated channel-level delay compensation parameters are output for time alignment and state estimation in the next cycle.

6. The debugging and simulation method for an on-board electrical control unit based on digital twins according to claim 2, characterized in that: The implementation of deterministic and priority scheduling specifically involves: based on the real-time link status and the deadlines of each flow, combined with the expected reduction in the consistency differential spectrum and its confidence level, calculating the semantic gain and urgency of each signal and message, and determining its priority. The real-time link status is characterized by bandwidth utilization, latency jitter, and packet loss rate. Accordingly, the code rate and protection level of semantic compression and joint source channel coding are adaptively configured. Higher precision and preset redundancy are allocated to high-priority flows, and a retransmission window is set. Deterministic or priority scheduling is implemented in the vehicular Ethernet and controller area network to ensure timely delivery of critical flows. When congestion or insufficient budget is detected, a congestion factor is calculated, and low-priority flows are downgraded and backed up to ensure the timely arrival of high-gain flows. Priority, code rate, redundancy, and scheduling parameters are updated in a closed loop at millisecond intervals based on actual arrival time, bit error rate, packet loss, and differential spectrum changes to maximize consistency convergence under limited bandwidth.

7. The method for debugging and simulating a vehicle electrical control unit based on digital twins according to claim 2, characterized in that: The debugging actions include parameter backfeedback, message injection, task tick perturbation, and environmental stimulus injection. Specifically, S5 is defined as: defining the action parameter space for parameter backfeeding, message injection, task tick perturbation and environmental stimulus injection. The action parameter space is limited by the target object, amplitude, step size, duration and frequency, and loaded with a safety invariant set and physical and functional constraints of the actuator, bus and task. Based on the components and channels with the highest contribution in the consistency difference spectrum, and combined with the confidence level to screen credible targets, several candidate actions are generated. The "expected reduction in the difference spectrum" is used as the benefit, and the risk and resource consumption penalties are superimposed to obtain a comprehensive score. The higher layer selects the intervention type and target subsystem, while the lower layer determines the amplitude, duration, injection location, and perturbation phase as specific parameters for the debugging action. Confidence level is used for gating and amplitude scaling. At low confidence levels, only low-amplitude, short-duration, or observational actions are allowed. Safety barrier constraints and boundary conditions are applied to each candidate action. These constraints and boundary conditions are limited by upper limits for speed, torque, current, temperature, voltage, bus load, task duty cycle, and jitter. Actions that do not meet these limits are eliminated and can be retried by amplitude compression, duration reduction, or change of the point of application. In the short prediction time domain, digital twins are used to perform look-ahead simulations to evaluate the probability of constraint violation and the deviation from the worst case under model uncertainty and disturbance. If the threshold is exceeded, the action level is reduced or the action is rejected. If the action passes, it is solidified as an executable action. The weights of the control intervention on the digital twin side and the physical side are calculated based on the consistency differential spectrum and confidence level. Amplitude limiting and gradual filtering are used to achieve shockless switching. Dwell time and rate limits are set. When safety constraints are triggered or confidence level drops sharply, the weights are quickly reduced or the system switches back to the physical side. Actions are scheduled and executed based on scores and conflict relationships. During execution, key constraints and differences in the spectrum are continuously monitored. If out-of-bounds or negative divergence occurs, the action is immediately rolled back, canceled, or downgraded. At the same time, action-response samples are recorded for subsequent adaptive updates of strategies and thresholds.

8. The debugging and simulation method for an on-board electrical control unit based on digital twins according to claim 2, characterized in that: The adaptive degradation strategy includes freezing debugging actions, reducing the coding rate and redundancy of non-critical communication streams, and switching to observation-only mode. Specifically, S6 is as follows: when the confidence level is lower than the threshold or a safety constraint is triggered, a graded degradation is initiated with hysteresis and dwell time: the debugging action being executed is frozen or rolled back and new actions are gated; the communication layer reduces the bit rate and frequency of non-critical flows and tightens retransmissions; critical flows are preserved or protected; the control side attenuates the digital twin control power according to the level and limits the amplitude and speed; when the safety constraint trigger level reaches the preset switching level, the physical side is switched back without impact to maintain safe output; the synchronization and estimation side reduces the computational load to ensure basic alignment by widening the integral step size, shortening the sliding window and pausing fast micro-alignment; and the highest level enters the observation-only mode. Once the recovery criteria are met, the actions, bitrate, and redundancy are gradually restored according to the "trial run - partial recovery - full recovery" process, and a change rate limit is applied to avoid oscillation. At the same time, degradation and recovery events are recorded for threshold and policy adaptive updates. The recovery criteria are that the system-level confidence is higher than the preset recovery upper threshold, the safety margin is positive, and the above states continue to reach the preset dwell time.

9. The debugging and simulation method for an on-board electrical control unit based on digital twins according to claim 2, characterized in that: Specifically, S7 is as follows: it runs a loop with a fixed cycle at the millisecond level and uses a sliding window and double buffer to ensure real-time performance. Each cycle is executed in a pipeline according to S2-S5 and the triggering conditions of S6 are monitored in parallel. The debugging actions and scheduling instructions to be executed are subject to final safety verification and short-term prediction, and then injected through post-atomicization. S4 deterministically transmits and records timestamps and ACKs or timeouts as feedback via Ethernet or CAN, and feeds back new physical observations with unified timestamps to drive the closed-loop update of digital twin and state estimation. Based on the consistency difference spectrum trend and confidence, the weights, step size, window, bit rate, and redundancy are adaptively adjusted, and S6 is triggered in advance when divergence or approximation constraints occur. Real-time monitoring of computation and bandwidth margins; lightweight degradation of timeout risks to ensure critical path arrival; isolation and rollback in case of link or execution anomalies, and switching to observation-only mode; recording of differential spectrum, confidence level, compensation amount and execution results for each cycle for traceability and parameter and threshold updates to promote gradual convergence of the consistency differential spectrum.

Citation Information

Patent Citations

  • Near-physical simulation integrated debugging method and system based on digital twinning

    CN112487668A

  • Multi-modal fusion AGV dynamic path planning and cluster scheduling system

    CN120598460A