Intelligent networked vehicle adaptive fault-tolerant intrusion-tolerant control method based on dynamic watermark

By constructing an adaptive neural network fault-tolerant controller and embedding dynamic watermark signals in intelligent connected vehicles, the problem of distinguishing between hardware failures and network attacks is solved, realizing unified control of high reliability and security for intelligent connected vehicles, and improving the system's security and detection accuracy.

CN121454948APending Publication Date: 2026-02-03SOUTHEAST UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511754553.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-26
Publication Date
2026-02-03

AI Technical Summary

Technical Problem

Hardware failures and cyberattacks are difficult to distinguish in the detection process of intelligent connected vehicles. Traditional methods cannot achieve coordinated processing of fault compensation and attack suppression within a single control system, making it difficult to balance reliability and security.

Method used

The adaptive fault-tolerant and attack-tolerant control method for intelligent connected vehicles based on dynamic watermarking constructs an adaptive neural network fault-tolerant controller, embeds dynamic watermark signals, and uses a Kalman filter for state estimation. Combined with evaluation functions and attack detection functions, it achieves unified detection and processing of hardware faults and network attacks.

Benefits of technology

It significantly improves the reliability and security of intelligent connected vehicle control systems, can accurately identify covert replay attacks, increases the security margin against the coupled threats of physical layer faults and information layer attacks, and prevents control performance degradation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121454948A_ABST
    Figure CN121454948A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent network connection vehicle adaptive fault-tolerant intrusion-tolerant control method based on a dynamic watermark, and relates to the technical field of intelligent driving of intelligent network connection vehicles. The method comprises the following steps: constructing an adaptive neural network fault-tolerant controller based on a vehicle dynamics model, a radial basis function neural network and a nonlinear disturbance observer; a dynamic watermark signal is embedded in the fault-tolerant control signal, and a control signal containing a watermark is generated and acts on a vehicle system; based on the statistical characteristics of the system residual error and the dynamic watermark signal, constructing an evaluation function and further defining an attack check function; according to the method, fault-tolerant control for hardware faults and intrusion tolerance control for network attacks are creatively unified under the same self-adaptive control framework, detection and intrusion tolerance for hidden network attacks are achieved, and the integrated design fundamentally overcomes the defect that fault processing and attack processing are separated from each other in a traditional scheme; and a unified and comprehensive safety control solution is provided for the intelligent network connection vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of intelligent networked vehicle intelligent driving technology, in particular to an intelligent networked vehicle adaptive fault-tolerant and intrusion-tolerant control method based on dynamic watermarking. BACKGROUND

[0002] With the deep integration of electricization, intelligentization and networking technology of automobiles, intelligent networked vehicles have become the core direction of global automobile industry revolution. Vehicles realize complex motion control by carrying a large number of electronic actuators and relying on high-speed information interaction inside and outside the vehicle, which significantly improves the driving performance and traffic efficiency. However, the deep coupling of physical system and information space also brings unprecedented safety challenges to vehicles: on the one hand, the increase in the scale of electronic actuators directly leads to an increase in the probability of hardware failure, and the failure of key actuators such as steering and braking will cause control performance degradation or even cause safety accidents; on the other hand, the open vehicle network environment makes vehicles vulnerable to network attacks, and attackers can interfere with the normal operation of vehicles by tampering with control commands or sensor data.

[0003] Safety control is the fundamental guarantee for the large-scale landing of intelligent networked vehicle technology, and has received widespread attention from academia and industry in recent years. At the level of vehicle motion control, the accuracy of path tracking depends on the coordinated adjustment of the steering system and the yaw moment. Once the steering actuator fails, the system will be difficult to maintain the expected trajectory, directly threatening the safety of driving. At the same time, network attacks are increasingly covert and destructive, especially replay attacks, which do not need to know the internal parameters of the system, but only need to record and resend historical data to tamper with system state feedback and control error signals, causing the controller to fail. More seriously, replay attacks use the statistical similarity of control system data in different time periods, which have strong concealment, and traditional threshold-based detection mechanisms are difficult to effectively identify. When hardware failure and network attack are coupled in time and space, their superimposed effect will further amplify the system risk, significantly increasing the complexity of security defense.

[0004] Existing technologies usually study fault-tolerant control and intrusion-tolerant control as independent problems. Fault-tolerant control is based on fault diagnosis and isolation mechanisms to maintain system functionality through hardware redundancy or control reconstruction; intrusion-tolerant control relies on intrusion detection systems to identify abnormal behavior and trigger defense strategies. However, hardware failure and network attack have similar manifestations in vehicle systems, both of which show trajectory deviation and control deviation, and the differences in their generation mechanisms and influence paths are difficult to effectively distinguish in the detection link. Traditional methods lack a unified analysis framework and coordination mechanism, making it difficult to balance reliability and security, and unable to achieve coordinated processing of fault compensation and attack suppression in a single control system.

[0005] Therefore, the present application proposes an intelligent networked vehicle adaptive fault-tolerant and intrusion-tolerant control method based on dynamic watermarking. SUMMARY

[0006] The application aims to provide a dynamic watermark-based intelligent networked vehicle adaptive fault-tolerant intrusion control method, construct a covert replay attack detection based on dynamic watermark, realize fault-tolerant intrusion control in the same control framework, and improve the reliability and safety of the intelligent networked vehicle control system.

[0007] According to the first aspect of the application, to achieve the above-mentioned purpose, the application provides the following technical scheme: a dynamic watermark-based intelligent networked vehicle adaptive fault-tolerant intrusion control method, comprising the following steps: An adaptive neural network fault-tolerant controller is constructed based on a vehicle dynamics model, a radial basis function neural network, and a nonlinear disturbance observer, wherein the radial basis function neural network is used to fit vehicle system faults, and the nonlinear disturbance observer is used to compensate for unknown disturbances and approximation errors; The adaptive neural network fault-tolerant controller generates a fault-compensated fault-tolerant control signal based on the fitting results of the radial basis function neural network and the observation results of the nonlinear disturbance observer; A dynamic watermark signal is embedded in the fault-tolerant control signal to generate a watermark-containing control signal and act on the vehicle system, and at the same time, based on the output measurement value of the vehicle system, a Kalman filter is used to estimate the system state to obtain a system state estimation value; Based on the state estimation results of the Kalman filter and the actual output of the system, the system residual error is calculated, and based on the system residual error and the statistical characteristics of the dynamic watermark signal, an evaluation function is constructed and an attack test function is further defined; Based on the calculation results of the evaluation function and the attack test function, it is judged whether the vehicle system is attacked, if the attack is detected, the intrusion control strategy is executed, the attacked signal is removed from the system output signal, and the Kalman filter is used for estimation, the estimated signal is used to replace the attacked signal, and the intrusion system state signal is generated; The intrusion system state signal is fed back to the adaptive neural network fault-tolerant controller to generate a new control signal, realizing closed-loop control.

[0008] Further, the adaptive neural network fault-tolerant controller is constructed based on the vehicle dynamics model, the radial basis function neural network, and the nonlinear disturbance observer, specifically as follows: (21) The system error is , A and B are parameters in the dynamics model, and the vehicle dynamics model is: In the formula, is the vehicle external disturbance, is the measurement noise, and are bounded and , vehicle state matrix is , vehicle side slip angle is , vehicle yaw rate is , vehicle front wheel steering angle is and direct yaw moment is vehicle mass is and front and rear tire cornering stiffness are respectively; vehicle moment of inertia about axis is and distance from center of mass to front and rear axles are respectively; wherein: , in the formula, vehicle mass is vehicle longitudinal velocity is and front and rear tire cornering stiffness are respectively; vehicle moment of inertia about axis is and distance from center of mass to front and rear axles are respectively; (22) in the case of vehicle actuator fault, the dynamic equation is: in the formula, multiplicative fault coefficient is and , additive fault is; system control input after fault is; definition: (23) using a radial basis neural network to fit the fault occurring in the system, definition: in the formula, the radial basis function is , the updated weight is , transpose of weight matrix is fitting error of the neural network is; select a Gaussian function as the radial basis function: wherein and Describe the center of the receptive field and the width of the Gaussian function, respectively; To minimize the approximation error, the optimal weights are found through an update process. , Make it as small as possible, until it approaches 0; (24) In order to account for the existence of fitting error and unknown external disturbances Define a new composite function: Using a nonlinear perturbation observer to estimate composite perturbations: In the formula, As an intermediate variable, For the design of positive constants, yes The observed values, for The observed values ​​have a systematic error of , yes Reference value; (25) Adaptive neural network fault-tolerant controller, specifically represented as follows: in It is a positive parameter of the design, and .

[0009] Furthermore, the dynamic watermark signal is a random Gaussian noise signal with a variance of 0.02.

[0010] Furthermore, a dynamic watermark signal is embedded into the fault-tolerant control signal to generate a watermarked control signal, which is then applied to the vehicle system. Simultaneously, based on the output measurement values ​​of the vehicle system, a Kalman filter is used to estimate the system state, resulting in the system state estimate, as follows: (41) In the discrete time domain: Where T is the sampling period, the vehicle dynamics model is obtained by sampling the variables in the continuous-time system at a time step. ,Right now When, rewritten in discrete time form as: in ; The state estimate is obtained by using a Kalman filter, with the following control input after disturbance and error compensation used during the estimation process: After adding a dynamic watermark: in, To produce a dynamic watermark signal that conforms to a Gaussian distribution, (42) The specific steps of Kalman filtering are as follows: in, Indicates time State estimates, For a moment The prior state estimate, For Kalman filtering at time 1 The gain matrix, For a moment The prior error covariance matrix, For a moment The posterior error covariance matrix; matrix These represent the process noise covariance matrix and the measurement noise covariance matrix, respectively.

[0011] Furthermore, based on the state estimation results of the Kalman filter and the actual output of the system, the system residuals are calculated. Based on the statistical characteristics of the system residuals and the dynamic watermark signal, an evaluation function is constructed and an attack detection function is further defined, as follows: (51) Define the system residual as: The statistical properties of residuals with dynamic watermarks are expressed as follows: In the formula, The vehicle model parameter matrix is ​​in discrete form. For dynamic watermark signals, These are the mean and variance of the residual distribution of a dynamic watermarking system that conforms to a normal distribution. The difference between the rows of the system residual distribution under normal conditions, where k is the current time; (52) Based on A chi-square test method was designed with an evaluation function. This is used to measure the degree of deviation between the actual residual signal of the system and its expected statistical distribution, where i represents which signal channel, 1 and 2 represent the centroid sideslip angle and yaw rate channels, respectively, and j represents the discrete time scale. in, a time window length of the evaluation function, a variance value of the dynamic watermark added to the i-th channel, respectively represent the system residual, the residual mean and the residual variance of the i-th channel at time j, and on this basis, the attack detection function is defined as follows: wherein, and respectively represent the evaluation function and the detection function of the i-th channel.

[0012] Further, based on the calculation results of the evaluation function and the attack detection function, it is judged whether the vehicle system is attacked, specifically as follows: The obtained attack detection function value is input into the attack detection and intrusion tolerance control strategy algorithm, the attack detection and intrusion tolerance control strategy algorithm judges whether the attack occurs by continuously monitoring the output value of the attack detection function, and adopts a counter mechanism to avoid false positives caused by instantaneous interference, and only when the number of continuous or sustained threshold values reaches the preset value, it is finally determined as being attacked.

[0013] Further, the specific steps of the attack detection and intrusion tolerance control strategy algorithm are as follows: (71) receiving the detection function result and initializing two persistent variable counters count and triggered; (72) updating the counter: when the value of the channel detection function is greater than the threshold, count is incremented, otherwise it is cleared; (73) when count≥10 and triggered is false, set triggered to true and output the attack flag; (74) when the attack flag is true, the damaged signal in the current measurement output is removed, the Kalman filter estimation value is used instead, and the Kalman filter update is re-executed; (75) outputting the attack detection result and the system state , wherein represents that the system is attacked, represents that the system is normal.

[0014] Further, the intrusion tolerance system state signal is fed back to the adaptive neural network fault-tolerant controller to generate a new control signal, realizing closed-loop control, specifically as follows: ​​After completing the discrete-time state estimation based on Kalman filtering, the estimation result is remapped back to the continuous-time system through the same sampling process, so that the controller can run in the continuous-time framework, and therefore, the system state matrix is redefined as The fault-tolerant and intrusion-tolerant integrated control algorithm based on adaptive neural network is re-expressed as: Wherein .

[0015] According to the second aspect of the present application, the present application provides a dynamic watermark-based intelligent networked vehicle adaptive fault-tolerant and intrusion-tolerant control system for implementing the dynamic watermark-based intelligent networked vehicle adaptive fault-tolerant and intrusion-tolerant control method described in the first aspect, comprising: A construction module is configured to construct an adaptive neural network fault-tolerant controller based on a vehicle dynamics model, a radial basis function neural network and a nonlinear disturbance observer, wherein the radial basis function neural network is used to fit the vehicle system fault, and the nonlinear disturbance observer is used to compensate for unknown disturbances and approximation errors. A fault-tolerant control signal generation module is configured to generate a fault-compensated fault-tolerant control signal based on the fitting result of the radial basis function neural network and the observation result of the nonlinear disturbance observer. A dynamic watermark signal embedding module is configured to embed a dynamic watermark signal in the fault-tolerant control signal to generate a watermark-containing control signal and act on the vehicle system, and simultaneously based on the output measurement value of the vehicle system, a Kalman filter is used to estimate the system state to obtain a system state estimation value. A calculation module is configured to calculate the system residual based on the state estimation result of the Kalman filter and the actual output of the system, and construct an evaluation function based on the system residual and the statistical characteristics of the dynamic watermark signal and further define an attack detection function. A judgment module is configured to judge whether the vehicle system is attacked based on the calculation results of the evaluation function and the attack detection function, and if an attack is detected, an intrusion control strategy is executed to eliminate the attacked signal in the system output signal, and a Kalman filter is used for estimation to replace the attacked signal with an estimated signal to generate an intrusion-tolerant system state signal. A closed-loop control module is configured to feed back the intrusion-tolerant system state signal to the adaptive neural network fault-tolerant controller to generate a new control signal and realize closed-loop control.

[0016] The present application has at least the following beneficial effects: 1.The present application constructs an adaptive fault-tolerant controller by online fitting the actuator faults with a radial basis function neural network (RBFNN) and compensating unknown disturbances and neural network approximation errors with a nonlinear disturbance observer (NDO), embeds a dynamic watermark signal in the controller, and constructs an attack evaluation function based on the chi-square test to accurately identify covert replay attacks, thus coping with the coupling threat of physical layer faults and information layer attacks and significantly improving the overall safety margin of intelligent connected vehicle control systems.

[0017] 2.The present application injects a dynamic watermark signal as random Gaussian noise independent of the system state into the control input, forms an expected unique imprint with time-varying variance in the residual statistical characteristics, and once the attacker replays historical data, the statistical correlation between the watermark signal and the residual will be destroyed, the evaluation function value will exceed the expected distribution range, and compared with traditional passive detection methods, the detection sensitivity and identification accuracy of covert replay attacks are greatly improved.

[0018] 3.The present application designs a detection judgment logic based on a continuous counting mechanism, such as triggering an alarm when exceeding the threshold for 10 consecutive times, effectively filters false positives caused by transient disturbances, and once an attack is confirmed, the system immediately excludes the damaged measurement signal and enables Kalman filter estimates for closed-loop feedback without interrupting the control process or switching to a backup controller.

[0019] Of course, any product implementing the present application does not necessarily need to achieve all the advantages described above at the same time. BRIEF DESCRIPTION OF DRAWINGS

[0020] Figure 1 a flowchart of the method described in the present application; Figure 2 a structural schematic diagram of the vehicle dynamics model in the present application; Figure 3 a schematic diagram of the framework principle of the method described in the present application; Figure 4 a simulation result schematic diagram of the yaw angle in the fault-tolerant control simulation experiment of the present application; Figure 5 a detection result schematic diagram of the replay attack in the present application; Figure 6 a fault-tolerant and intrusion control result schematic diagram in the present application. DETAILED DESCRIPTION

[0021] With reference to the drawings of the embodiments of the present disclosure, the technical solutions in the embodiments of the present disclosure will be described clearly and completely. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative work fall within the scope of the present disclosure.

[0022] Embodiment one: Please refer to Figures 1-6 The present disclosure provides a technical solution: an intelligent networked vehicle adaptive fault-tolerant and intrusion control method based on dynamic watermark, comprising the following steps: S1. An adaptive neural network fault-tolerant controller is constructed based on a vehicle dynamics model, a radial basis function neural network, and a nonlinear disturbance observer, wherein the radial basis function neural network is used to fit vehicle system faults, and the nonlinear disturbance observer is used to compensate for unknown disturbances and approximation errors; the adaptive neural network fault-tolerant controller generates a fault-compensated fault-tolerant control signal based on the fitting results of the radial basis function neural network and the observation results of the nonlinear disturbance observer; An adaptive neural network fault-tolerant controller is constructed based on a vehicle dynamics model, a radial basis function neural network, and a nonlinear disturbance observer, specifically as follows: (S11) The system error is , A and B are parameters in the dynamics model, and the vehicle dynamics model is: In the formula, is the external disturbance of the vehicle, is the measurement noise, and are bounded and , the vehicle state matrix is , the centroid side slip angle is , the vehicle yaw rate is , is the front wheel steering angle and is the direct yaw moment, is the mass of the vehicle; and are the side stiffness of the front and rear tires, respectively; is the moment of inertia of the vehicle around the axis; and are the distances from the mass center to the front and rear axles, respectively; wherein: , In the formula, is the mass of the vehicle, For the longitudinal speed of the vehicle, and These are the lateral stiffness of the front and rear tires, respectively. For vehicles to bypass Moment of inertia of the axis; and These are the distances from the center of mass to the front and rear axles, respectively. (S12) In the case of a vehicle actuator failure, the dynamic equation is: In the formula, Multiplicative fault coefficient and , It is an additive fault; This serves as the system control input after a fault. definition: The above dynamic equations are then: (S13) Use a radial basis function neural network to fit the faults that occur in the system, defined as: , In the formula, the radial basis function is: Update weights to , for Transpose of the weight matrix This represents the fitting error of the neural network. Choose the Gaussian function as the radial basis function: in and The center of the receptive field and the width of the Gaussian function are described respectively; to minimize the approximation error, the optimal weights are found through an update process. , Make it as small as possible, until it approaches 0; (S14) In order to account for the existence of fitting error and unknown external disturbances Define a new composite function: Using a nonlinear perturbation observer to estimate composite perturbations: In the formula, As an intermediate variable, For the design of positive constants, yes the observation value of is the observation value of , is the reference value of (S15) the adaptive neural network fault-tolerant controller, which is specifically represented as follows: wherein is a positive parameter designed, and ; S2. A random Gaussian noise signal with a variance of 0.02 is embedded in the fault-tolerant control signal as a dynamic watermark signal to generate a watermark-containing control signal and act on the vehicle system, while based on the output measurement values (vehicle yaw rate and center side slip angle ) of the vehicle system, the system state estimation is carried out by using a Kalman filter to obtain the system state estimation value, which is specifically as follows: In the discrete time domain: wherein T is a sampling period, by sampling the variables in the continuous-time system (7), the vehicle dynamics model can be rewritten in discrete time form at a time step (that is, ): wherein In this work, the state estimation value is obtained by using a Kalman filter, and due to the influence of system faults and external disturbances, the control input does not represent the actual input applied to the system actuator; by using the fault and disturbance compensation provided by the neural network and disturbance observer described earlier, the influence of faults and disturbances on the state estimation based on the Kalman filter can be effectively reduced; therefore, the following compensated control input should be used in the estimation process: After adding the dynamic watermark: wherein is a dynamic watermark signal subject to a Gaussian distribution, The specific steps of the Kalman filter are as follows: (1) (2) wherein represents the time State estimates, For a moment The prior state estimate, For Kalman filtering at time 1 The gain matrix, For a moment The prior error covariance matrix, For a moment The posterior error covariance matrix; matrix Let these represent the process noise covariance matrix and the measurement noise covariance matrix, respectively. S3. Based on the state estimation results of the Kalman filter and the actual output of the system, calculate the system residuals. Based on the statistical characteristics of the system residuals and the dynamic watermark signal, construct an evaluation function and further define an attack detection function, as follows: (S31) Define the system residual as: The statistical properties of residuals with dynamic watermarks are expressed as follows: In the formula, The vehicle model parameter matrix is ​​in discrete form. For dynamic watermark signals, These are the mean and variance of the residual distribution of a dynamic watermarking system that conforms to a normal distribution. The difference between the rows of the system residual distribution under normal conditions, where k is the current time; (S32) Based on A chi-square test method was designed with an evaluation function. This is used to measure the degree of deviation between the actual residual signal of the system and its expected statistical distribution, where i represents which signal channel, 1 and 2 represent the centroid sideslip angle and yaw rate channels, respectively, and j represents the discrete time scale. in, This indicates the length of the time window for the evaluation function. , The variance of the dynamic watermark added to the i-th channel. Let represent the system residual, residual mean, and residual variance of the i-th channel at time j, respectively. Based on this, the attack detection function is defined as follows: in, and They represent the first Evaluation and test functions for each channel; S4. Determine whether the vehicle system is attacked based on the evaluation function and the calculation results of the attack detection function. If an attack is detected, perform the intrusion tolerance control strategy, eliminate the attacked signal in the system output signal, and use Kalman filtering to estimate and replace the attacked signal with the estimated signal to generate the system state signal after intrusion tolerance, as follows: The attack detection function value obtained is input into the attack detection and intrusion tolerance control strategy algorithm. The attack detection and intrusion tolerance control strategy algorithm determines whether an attack occurs by continuously monitoring the output value of the attack detection function, and uses a counter mechanism to avoid false positives caused by transient interference. Only when the number of continuous or sustained attacks exceeds the threshold value reaches the preset value, it is finally determined that an attack has occurred. As shown in Table 1, the integrated attack detection and intrusion tolerance control strategy algorithm is used to determine whether the system is attacked, and corresponding intrusion tolerance control measures are performed when an intrusion is detected, as follows: Table 1 Attack detection and intrusion tolerance control integrated strategy S5. The system state signal after intrusion tolerance is fed back to the adaptive neural network fault-tolerant controller to generate a new control signal, realizing closed-loop control, as follows: After completing the discrete-time state estimation based on Kalman filtering, the estimation result is remapped back to the continuous-time system through the same sampling process, so that the controller can operate in the continuous-time framework. Therefore, the system state matrix is redefined as The fault-tolerant intrusion integrated control algorithm based on adaptive neural network is re-expressed as: Where .

[0023] As shown in Figure 2 , the vehicle is four-wheel independent drive, and the vehicle dynamics model is established through the mechanical relationship.

[0024] As shown in Figure 3 , the control design combines NDO for real-time compensation of external disturbances and RBFNN for handling actuator faults. Dynamic watermark is embedded in the controller, and replay attacks are detected in real time through the designed evaluation function and attack detection strategy. In addition, a switching mechanism is introduced to replace the damaged signal with the estimated value generated by the Kalman filter when a replay attack is detected, thereby realizing intrusion tolerance control.

[0025] As shown in Figure 4The diagram shows the simulation results of the yaw angle in the fault-tolerant control simulation experiment. The comparison algorithm is the basic algorithm without RBFNN and NDO, i.e. The system experienced actuator failures during the 2–4 s and 12–13 s time periods, with a multiplicative fault coefficient set to 0.5. Test results show that during the fault periods, the tracking accuracy of the controller without neural network significantly decreased, and actuator failures severely weakened the vehicle's trajectory tracking performance and reduced handling stability. In contrast, the fault-tolerant control algorithm based on adaptive neural networks proposed in this paper can effectively compensate for the impact of faults while maintaining good trajectory tracking accuracy. like Figure 5 The diagram illustrates the detection process of replay attacks. Due to the stealth nature of these attacks, traditional detectors without dynamic watermarks struggle to identify them in a timely manner (see...). Figure 5 a). When dynamic watermarking is introduced, the system output contains a non-replicable watermark signal, disrupting the statistical consistency of the residual distribution in replay attacks. Combined with the statistical characteristics of the detector, the evaluation function rises rapidly after the attack occurs (see...). Figure 5 (b) Attack detection can be completed within 0.1 seconds. The detection threshold is set to 0.005, and its location is marked by the red line in the figure.

[0026] like Figure 6 As shown, the state estimation results of the Kalman filter are presented after the invasion-tolerant control strategy is activated. Figure 6 As can be seen, after a replay attack, the tracking accuracy and estimation accuracy of the system both decreased due to the isolation of the contaminated signal; however, overall, the system can still complete the tracking task with high reliability. Figure 6 b further demonstrates that actuator failure will not interfere with or mislead the attack detection process. When an attack occurs, the evaluation function value rises rapidly and exceeds a preset threshold, triggering the intrusion tolerance control strategy. At this point, the evaluation function value will return to its normal value, falling below the trigger threshold. Thanks to this strategy design, once an attack is detected, the system will continuously maintain an intrusion tolerance control state, avoiding frequent switching between "intrusion tolerance" and "non-intrusion tolerance" modes due to changes in the evaluation function, which would otherwise lead to control performance degradation. Figure 6 As shown in c, once the system detects an attack, the intrusion prevention control policy remains active throughout the entire task execution process until the task is completed or the system terminates.

[0027] In summary, the application creatively unifies the fault-tolerant control for hardware failure and the intrusion-tolerant control for network attack in the same adaptive control framework, realizes real-time fitting and compensation of system failure and external disturbance through the integrated design of the radial basis function neural network (RBFNN) and the nonlinear disturbance observer (NDO), and realizes high-reliability fault-tolerant control, on the basis of which, the dynamic watermark technology is introduced to construct an active security defense layer, and detection and intrusion tolerance of the covert network attack are realized. This integrated design fundamentally overcomes the defect that fault and attack processing are mutually separated in the traditional scheme, and provides a unified and comprehensive security control solution for intelligent networked vehicles.

[0028] Embodiment two: The embodiment provides an intelligent networked vehicle adaptive fault-tolerant intrusion-tolerant control system based on dynamic watermark, which is used for realizing the intelligent networked vehicle adaptive fault-tolerant intrusion-tolerant control method based on dynamic watermark described in embodiment one, and comprises: A construction module is configured to construct an adaptive neural network fault-tolerant controller based on a vehicle dynamics model, a radial basis function neural network and a nonlinear disturbance observer, wherein the radial basis function neural network is used for fitting vehicle system failure, and the nonlinear disturbance observer is used for compensating unknown disturbance and approximation error. A fault-tolerant control signal generation module is configured to generate a fault-compensated fault-tolerant control signal based on the fitting result of the radial basis function neural network and the observation result of the nonlinear disturbance observer by the adaptive neural network fault-tolerant controller. A dynamic watermark signal embedding module is configured to embed a dynamic watermark signal in the fault-tolerant control signal, generate a watermark-containing control signal and act on the vehicle system, and simultaneously estimate the system state by using a Kalman filter based on the output measurement value of the vehicle system to obtain a system state estimation value. A calculation module is configured to calculate system residual based on the state estimation result of the Kalman filter and the actual output of the system, construct an evaluation function based on the system residual and the statistical characteristics of the dynamic watermark signal, and further define an attack test function. A judgment module is configured to judge whether the vehicle system is attacked based on the calculation results of the evaluation function and the attack test function, and if an attack is detected, execute an intrusion-tolerant control strategy, eliminate the attacked signal in the system output signal, and use the estimation signal to replace the attacked signal by using the Kalman filter for estimation to generate an intrusion-tolerant system state signal. A closed-loop control module is configured to feed back the intrusion-tolerant system state signal to the adaptive neural network fault-tolerant controller to generate a new control signal and realize closed-loop control.

[0029] It is to be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting; it is not intended that the scope of the application be limited to the detailed description contained herein or the specific examples given herein, but rather that the scope of the application be determined by the appended claims, and their equivalents.

[0030] To those skilled in the art, the above-mentioned terms can be understood in the specific meaning in the present application according to the specific circumstances. When an element is referred to as being "assembled to", "attached to", "fixed to" or "disposed to" another element, it can be directly on the other element or there can be an intervening element. When an element is referred to as being "connected to" another element, it can be directly connected to the other element or there can be an intervening element. The terms "vertical", "horizontal", "upper", "lower", "left", "right", and similar expressions used herein are for illustrative purposes only and are not intended to be limiting.

[0031] Although the embodiments of the present application have been shown and described, it is to be understood that various modifications, substitutions, replacements and changes can be made to the embodiments without departing from the principles and spirit of the present application, and the scope of the present application is defined by the appended claims and their equivalents.

[0032] In the description of the specification, the description referring to the terms "one embodiment", "an example", "a specific example" and the like means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present disclosure. Illustrative expressions of the above-mentioned terms in the specification do not necessarily refer to the same embodiment or example. Also, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in an appropriate manner.

Claims

1. A method for adaptive fault-tolerant and intrusion-tolerant control of intelligent connected vehicles based on dynamic watermarking, characterized in that, Includes the following steps: An adaptive neural network fault-tolerant controller is constructed based on a vehicle dynamics model, a radial basis function neural network, and a nonlinear disturbance observer. The radial basis function neural network is used to fit the vehicle system fault, and the nonlinear disturbance observer is used to compensate for unknown disturbances and approximation errors. The adaptive neural network fault-tolerant controller generates a fault-compensated fault-tolerant control signal based on the fitting results of the radial basis function neural network and the observation results of the nonlinear disturbance observer. A dynamic watermark signal is embedded in the fault-tolerant control signal to generate a watermarked control signal and apply it to the vehicle system. At the same time, based on the output measurement value of the vehicle system, a Kalman filter is used to estimate the system state and obtain the system state estimate value. Based on the state estimation results of the Kalman filter and the actual output of the system, the system residual is calculated. Based on the statistical characteristics of the system residual and the dynamic watermark signal, an evaluation function is constructed and an attack detection function is further defined. Based on the calculation results of the evaluation function and the attack detection function, it is determined whether the vehicle system has been attacked. If an attack is detected, an intrusion tolerance control strategy is executed. The attacked signal is removed from the system output signal, and Kalman filtering is used to estimate it. The estimated signal is used to replace the attacked signal to generate the intrusion tolerance system state signal. The system state signal after the intrusion is tolerated is fed back to the adaptive neural network fault-tolerant controller to generate a new control signal and achieve closed-loop control.

2. The adaptive fault-tolerant and invasion-tolerant control method for intelligent connected vehicles based on dynamic watermarking according to claim 1, characterized in that: An adaptive neural network fault-tolerant controller is constructed based on a vehicle dynamics model, a radial basis function neural network, and a nonlinear disturbance observer, as detailed below: (21) A and B are the parameter matrices in the dynamic model, and C is the transformation matrix from system state to system output. The vehicle dynamic model is: In the formula, External disturbances to the vehicle. To measure noise, and Bounded and The vehicle state matrix is The centroid sideslip angle is The vehicle's yaw rate is , For the steering angle of the vehicle's front wheels and This is the direct yaw moment; in: , In the formula, For vehicle quality, For the longitudinal speed of the vehicle, and These are the lateral stiffness of the front and rear tires, respectively. For vehicles to bypass Moment of inertia of the axis; and These are the distances from the center of mass to the front and rear axles, respectively. (22) In the case of a vehicle actuator failure, the dynamic equation is: In the formula, Multiplicative fault coefficient and , It is an additive fault; This serves as the system control input after a fault. definition: The above dynamic equations are then: (23) Using a radial basis function neural network to fit the faults that occur in the system, defined as: , In the formula, the radial basis function is: Update weights to , for Transpose of the weight matrix This represents the fitting error of the neural network. Choose the Gaussian function as the radial basis function: in and The center of the receptive field and the width of the Gaussian function are described respectively; to minimize the approximation error, the optimal weights are found through an update process. , Make it as small as possible, until it approaches 0; (24) In order to solve the fitting error and unknown external disturbances Define a new composite function: Using a nonlinear perturbation observer to estimate composite perturbations: In the formula, As an intermediate variable, For the design of positive constants, yes The observed values, for The observed values ​​have a systematic error of , yes Reference value; (25) Adaptive neural network fault-tolerant controller, specifically represented as follows: in It is a positive parameter of the design, and .

3. The adaptive fault-tolerant and invasion-tolerant control method for intelligent connected vehicles based on dynamic watermarking according to claim 2, characterized in that: The dynamic watermark signal is a random Gaussian noise signal with a variance of 0.

02.

4. The adaptive fault-tolerant and intrusion-tolerant control method for intelligent connected vehicles based on dynamic watermarking according to claim 3, characterized in that: A dynamic watermark signal is embedded in the fault-tolerant control signal to generate a watermarked control signal, which is then applied to the vehicle system. Simultaneously, based on the output measurements of the vehicle system, a Kalman filter is used to estimate the system state, yielding the system state estimate, as detailed below: (41) In the discrete time domain: Where T is the sampling period, the vehicle dynamics model is obtained by sampling the variables in the continuous-time system at a time step. ,Right now When, rewritten in discrete time form as: in ; The state estimate is obtained by using a Kalman filter, with the following control input after disturbance and error compensation used during the estimation process: After adding a dynamic watermark: in, To produce a dynamic watermark signal that conforms to a Gaussian distribution, (42) The specific steps of Kalman filtering are as follows: in, Indicates time State estimates, For a moment The prior state estimate, For Kalman filtering at time 1 The gain matrix, For a moment The prior error covariance matrix, For a moment The posterior error covariance matrix; matrix These represent the process noise covariance matrix and the measurement noise covariance matrix, respectively.

5. The adaptive fault-tolerant and invasion-tolerant control method for intelligent connected vehicles based on dynamic watermarking according to claim 4, characterized in that: Based on the state estimation results of the Kalman filter and the actual output of the system, the system residuals are calculated. Based on the statistical characteristics of the system residuals and the dynamic watermark signal, an evaluation function is constructed and an attack detection function is further defined, as follows: (51) Define the system residual as: The statistical properties of residuals with dynamic watermarks are expressed as follows: In the formula, The vehicle model parameter matrix is ​​in discrete form. For dynamic watermark signals, These are the mean and variance of the residual distribution of a dynamic watermarking system that conforms to a normal distribution. The difference between the rows of the system residual distribution under normal conditions, where k is the current time; (52) Based on A chi-square test method was designed with an evaluation function. This is used to measure the degree of deviation between the actual residual signal of the system and its expected statistical distribution, where i represents which signal channel, 1 and 2 represent the centroid sideslip angle and yaw rate channels, respectively, and j represents the discrete time scale. in, This indicates the length of the time window for the evaluation function. , The variance of the dynamic watermark added to the i-th channel. Let represent the system residual, residual mean, and residual variance of the i-th channel at time j, respectively. Based on this, the attack detection function is defined as follows: in, and They represent the first Evaluation and testing functions for each channel.

6. The adaptive fault-tolerant and invasion-tolerant control method for intelligent connected vehicles based on dynamic watermarking according to claim 5, characterized in that: The determination of whether a vehicle system has been attacked is based on the calculation results of the evaluation function and the attack detection function, as follows: The obtained attack detection function value is input into the attack detection and intrusion control strategy algorithm. The attack detection and intrusion control strategy algorithm determines whether an attack has occurred by continuously monitoring the output value of the attack verification function, and uses a counter mechanism to avoid false alarms caused by momentary interference. Only when the number of consecutive or continuous exceedances of the threshold reaches a preset value will it be finally determined that an attack has occurred.

7. The adaptive fault-tolerant and intrusion-tolerant control method for intelligent connected vehicles based on dynamic watermarking according to claim 6, characterized in that: The specific steps of the attack detection and intrusion prevention control strategy algorithm are as follows: (71) Receive the test function result It also initializes two persistent variables: a counter `count` and a trigger flag `triggered`. (72) Update the counter: When the test function value of a certain channel is greater than the threshold, the count is incremented; otherwise, it is cleared to zero. (73) When count≥10 and triggered is false, set triggered to true and output the attack flag; (74) When the attack flag is true, remove the damaged signal from the current measurement output, replace it with the Kalman filter estimate, and re-execute the Kalman filter update; (75) Output attack detection results and system status ,in This indicates that the system has been attacked. This indicates that the system is functioning normally.

8. The adaptive fault-tolerant and invasion-tolerant control method for intelligent connected vehicles based on dynamic watermarking according to claim 7, characterized in that: The compromised system state signal is fed back to the adaptive neural network fault-tolerant controller to generate a new control signal, thereby achieving closed-loop control, as follows: After performing discrete-time state estimation based on Kalman filtering, the estimation results are remapped back to the continuous-time system through the same sampling process, enabling the controller to operate in the continuous-time frame. Therefore, the system state matrix is ​​redefined as... The fault-tolerant and invasion-tolerant integrated control algorithm based on adaptive neural networks is restated as follows: in .

9. A dynamic watermark-based adaptive fault-tolerant and intrusion-tolerant control system for intelligent connected vehicles, used to implement the dynamic watermark-based adaptive fault-tolerant and intrusion-tolerant control method for intelligent connected vehicles as described in any one of claims 1 to 8, characterized in that, include: The module is used to build an adaptive neural network fault-tolerant controller based on a vehicle dynamics model, a radial basis function neural network, and a nonlinear disturbance observer. The radial basis function neural network is used to fit vehicle system faults, and the nonlinear disturbance observer is used to compensate for unknown disturbances and approximation errors. The fault-tolerant control signal generation module is used by the adaptive neural network fault-tolerant controller to generate fault-compensated fault-tolerant control signals based on the fitting results of the radial basis function neural network and the observation results of the nonlinear disturbance observer. The dynamic watermark signal embedding module is used to embed dynamic watermark signals into fault-tolerant control signals, generate watermarked control signals and apply them to the vehicle system. At the same time, based on the output measurement values ​​of the vehicle system, the system state is estimated using a Kalman filter to obtain the system state estimate. The computation module is used to calculate the system residuals based on the state estimation results of the Kalman filter and the actual output of the system. Based on the statistical characteristics of the system residuals and the dynamic watermark signal, the evaluation function is constructed and the attack detection function is further defined. The judgment module is used to determine whether the vehicle system has been attacked based on the calculation results of the evaluation function and the attack detection function. If an attack is detected, the intrusion tolerance control strategy is executed, the attacked signal is removed from the system output signal, and Kalman filtering is used to estimate it. The estimated signal is used to replace the attacked signal to generate the intrusion tolerance system state signal. The closed-loop control module is used to feed back the system state signal after intrusion tolerance to the adaptive neural network fault-tolerant controller to generate new control signals and realize closed-loop control.