Intelligent connected vehicle adaptive fault-tolerant and intrusion control method based on dynamic watermark
By constructing an adaptive neural network fault-tolerant controller and embedding dynamic watermark signals in intelligent connected vehicles, the problem of coupling between hardware failures and network attacks is solved, and unified control of high reliability and security of intelligent connected vehicles is achieved.
Patent Information
- Application Number
- CN202511754553.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-26
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2045-11-26
AI Technical Summary
When hardware failures and cyberattacks are coupled in the spatiotemporal dimensions in intelligent connected vehicles, traditional methods struggle to distinguish and coordinate their handling, making it difficult to balance security and reliability.
The adaptive fault-tolerant and attack-tolerant control method for intelligent connected vehicles based on dynamic watermarking is proposed. By constructing an adaptive neural network fault-tolerant controller, embedding dynamic watermark signals, and combining Kalman filters and evaluation functions, it achieves unified detection and processing of hardware faults and network attacks.
It significantly improves the security and reliability of intelligent connected vehicle control systems, can accurately identify covert replay attacks, improves the overall security margin of the system, and can eliminate damaged signals without interrupting the control process after an attack is detected.
Smart Images

Figure CN121454948B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intelligent driving technology for intelligent connected vehicles, specifically to an adaptive fault-tolerant and intrusion-tolerant control method for intelligent connected vehicles based on dynamic watermarking. Background Technology
[0002] With the deep integration of electric, intelligent, and connected vehicle technologies, intelligent connected vehicles have become a core direction of global automotive industry transformation. Vehicles, by incorporating numerous electronic actuators and relying on high-speed information interaction between the vehicle and its surroundings, achieve complex motion control, significantly improving driving performance and traffic efficiency. However, the deep coupling between the physical system and the cyberspace also presents vehicles with unprecedented safety challenges: on the one hand, the increased scale of electronic actuators directly leads to a higher probability of hardware failure; failure of key actuators such as steering and braking will cause control performance degradation or even trigger safety accidents; on the other hand, the open in-vehicle network environment makes vehicles vulnerable to cyberattacks, allowing attackers to interfere with normal vehicle operation by tampering with control commands or sensor data.
[0003] Safety control is the fundamental guarantee for the large-scale deployment of intelligent connected vehicle technology, and it has received widespread attention from academia and industry in recent years. At the vehicle motion control level, path tracking accuracy depends on the coordinated adjustment of the steering system and yaw moment. Once the steering actuator malfunctions, the system will struggle to maintain the expected trajectory, directly threatening driving safety. Meanwhile, the stealth and destructiveness of cyberattacks are increasing, especially replay attacks—which do not require knowledge of internal system parameters but only need to record and repeatedly send historical data to simultaneously tamper with system status feedback and control error signals, causing controller failure. Even more serious is that replay attacks exploit the statistical similarity of control system data at different times, possessing extremely high stealth capabilities, making them difficult to effectively identify using traditional threshold-based detection mechanisms. When hardware failures and cyberattacks occur coupled in the spatiotemporal dimension, their cumulative effect will further amplify system risks, significantly increasing the complexity of security defenses.
[0004] Existing technologies typically treat fault-tolerant control and intrusion-tolerant control as independent problems. Fault-tolerant control is mostly based on fault diagnosis and isolation mechanisms, maintaining system functionality through hardware redundancy or control reconfiguration; intrusion-tolerant control relies on intrusion detection systems to identify abnormal behavior and trigger defense strategies. However, hardware failures and network attacks ultimately manifest similarly in vehicle systems, both resulting in trajectory deviations and control biases. The differences in their generation mechanisms and impact pathways are difficult to effectively distinguish during the detection phase. Traditional methods lack a unified analytical framework and coordination mechanism, making it difficult to balance reliability and security, and failing to achieve coordinated processing of fault compensation and attack suppression within a single control system.
[0005] To address this, the present invention proposes an adaptive fault-tolerant and intrusion-tolerant control method for intelligent connected vehicles based on dynamic watermarking. Summary of the Invention
[0006] The purpose of this invention is to provide an adaptive fault-tolerant and invasion-tolerant control method for intelligent connected vehicles based on dynamic watermarking. It constructs a covert replay attack detection method based on dynamic watermarking, realizes fault-tolerant and invasion-tolerant control under the same control framework, and improves the reliability and security of the intelligent connected vehicle control system.
[0007] According to a first aspect of the present invention, in order to achieve the above-mentioned objective, the present invention provides the following technical solution: an adaptive fault-tolerant and intrusion-tolerant control method for intelligent connected vehicles based on dynamic watermarking, comprising the following steps: An adaptive neural network fault-tolerant controller is constructed based on a vehicle dynamics model, a radial basis function neural network, and a nonlinear disturbance observer. The radial basis function neural network is used to fit the vehicle system fault, and the nonlinear disturbance observer is used to compensate for unknown disturbances and approximation errors. The adaptive neural network fault-tolerant controller generates a fault-compensated fault-tolerant control signal based on the fitting results of the radial basis function neural network and the observation results of the nonlinear disturbance observer. A dynamic watermark signal is embedded in the fault-tolerant control signal to generate a watermarked control signal and apply it to the vehicle system. At the same time, based on the output measurement value of the vehicle system, a Kalman filter is used to estimate the system state and obtain the system state estimate value. Based on the state estimation results of the Kalman filter and the actual output of the system, the system residual is calculated. Based on the statistical characteristics of the system residual and the dynamic watermark signal, an evaluation function is constructed and an attack detection function is further defined. Based on the calculation results of the evaluation function and the attack detection function, it is determined whether the vehicle system has been attacked. If an attack is detected, an intrusion tolerance control strategy is executed. The attacked signal is removed from the system output signal, and Kalman filtering is used to estimate it. The estimated signal is used to replace the attacked signal to generate the intrusion tolerance system state signal. The system state signal after the intrusion is tolerated is fed back to the adaptive neural network fault-tolerant controller to generate a new control signal and achieve closed-loop control.
[0008] Furthermore, an adaptive neural network fault-tolerant controller is constructed based on the vehicle dynamics model, radial basis function neural network, and nonlinear disturbance observer, as detailed below: (21) The systematic error is A and B are parameters in the dynamics model. The vehicle dynamics model is as follows: In the formula, External disturbances to the vehicle. To measure noise, and Bounded and The vehicle state matrix is centroid side slip angle The vehicle's yaw rate is , For the steering angle of the vehicle's front wheels and For direct yaw moment, For the overall vehicle weight; and These are the lateral stiffness of the front and rear tires, respectively. For vehicles to bypass Moment of inertia of the axis; and These are the distances from the center of mass to the front and rear axles, respectively. in: , In the formula, For vehicle quality, For the longitudinal speed of the vehicle, and These are the lateral stiffness of the front and rear tires, respectively. For vehicles to bypass Moment of inertia of the axis; and These are the distances from the center of mass to the front and rear axles, respectively. (22) In the case of a vehicle actuator failure, the dynamic equation is: In the formula, Multiplicative fault coefficient and , It is an additive fault; This serves as the system control input after a fault. definition: (23) Using a radial basis function neural network to fit the faults that occur in the system, defined as: In the formula, the radial basis function is: Update weights to , for Transpose of the weight matrix This represents the fitting error of the neural network. Choose the Gaussian function as the radial basis function: in and Describe the center of the receptive field and the width of the Gaussian function, respectively; To minimize the approximation error, the optimal weights are found through an update process. , Make it as small as possible, until it approaches 0; (24) In order to account for the existence of fitting error and unknown external disturbances Define a new composite function: Using a nonlinear perturbation observer to estimate composite perturbations: In the formula, As an intermediate variable, For the design of positive constants, yes The observed values, for The observed values have a systematic error of . , yes Reference value; (25) Adaptive neural network fault-tolerant controller, specifically represented as follows: in It is a positive parameter of the design, and .
[0009] Furthermore, the dynamic watermark signal is a random Gaussian noise signal with a variance of 0.02.
[0010] Furthermore, a dynamic watermark signal is embedded into the fault-tolerant control signal to generate a watermarked control signal, which is then applied to the vehicle system. Simultaneously, based on the output measurement values of the vehicle system, a Kalman filter is used to estimate the system state, resulting in the system state estimate, as follows: (41) In the discrete time domain: Where T is the sampling period, the vehicle dynamics model is obtained by sampling the variables in the continuous-time system at a time step. ,Right now When, rewritten in discrete time form as: in ; The state estimate is obtained by using a Kalman filter, with the following control input after disturbance and error compensation used during the estimation process: After adding a dynamic watermark: in, To produce a dynamic watermark signal that conforms to a Gaussian distribution, (42) The specific steps of Kalman filtering are as follows: in, Indicates time State estimates, For a moment The prior state estimate, For Kalman filtering at time 1 The gain matrix, For a moment The prior error covariance matrix, For a moment The posterior error covariance matrix; matrix These represent the process noise covariance matrix and the measurement noise covariance matrix, respectively.
[0011] Furthermore, based on the state estimation results of the Kalman filter and the actual output of the system, the system residuals are calculated. Based on the statistical characteristics of the system residuals and the dynamic watermark signal, an evaluation function is constructed and an attack detection function is further defined, as follows: (51) Define the system residual as: The statistical properties of residuals with dynamic watermarks are expressed as follows: In the formula, The vehicle model parameter matrix is in discrete form. For dynamic watermark signals, These are the mean and variance of the residual distribution of a dynamic watermarking system that conforms to a normal distribution. The difference between the rows of the system residual distribution under normal conditions, where k is the current time; (52) Based on A chi-square test method was designed with an evaluation function. This is used to measure the degree of deviation between the actual residual signal of the system and its expected statistical distribution, where i represents which signal channel, 1 and 2 represent the centroid sideslip angle and yaw rate channels, respectively, and j represents the discrete time scale. in, This indicates the length of the time window for the evaluation function. , The variance of the dynamic watermark added to the i-th channel. Let represent the system residual, residual mean, and residual variance of the i-th channel at time j, respectively. Based on this, the attack detection function is defined as follows: in, and They represent the first Evaluation and testing functions for each channel.
[0012] Furthermore, the determination of whether the vehicle system has been attacked is based on the calculation results of the evaluation function and the attack detection function, as follows: The obtained attack detection function value is input into the attack detection and intrusion control strategy algorithm. The attack detection and intrusion control strategy algorithm determines whether an attack has occurred by continuously monitoring the output value of the attack verification function, and uses a counter mechanism to avoid false alarms caused by momentary interference. Only when the number of consecutive or continuous exceedances of the threshold reaches a preset value will it be finally determined that an attack has occurred.
[0013] Furthermore, the specific steps of the attack detection and intrusion control strategy algorithm are as follows: (71) Receive the test function result It also initializes two persistent variables: a counter `count` and a trigger flag `triggered`. (72) Update the counter: When the test function value of a certain channel is greater than the threshold, the count is incremented; otherwise, it is cleared to zero. (73) When count≥10 and triggered is false, set triggered to true and output the attack flag; (74) When the attack flag is true, remove the damaged signal from the current measurement output, replace it with the Kalman filter estimate, and re-execute the Kalman filter update; (75) Output attack detection results and system status ,in This indicates that the system has been attacked. This indicates that the system is functioning normally.
[0014] Furthermore, the compromised system state signal is fed back to the adaptive neural network fault-tolerant controller to generate new control signals and achieve closed-loop control, as detailed below: After performing discrete-time state estimation based on Kalman filtering, the estimation results are remapped back to the continuous-time system through the same sampling process, enabling the controller to operate in the continuous-time frame. Therefore, the system state matrix is redefined as... The fault-tolerant and invasion-tolerant integrated control algorithm based on adaptive neural networks is restated as follows: in .
[0015] According to a second aspect of the present invention, the present invention provides an adaptive fault-tolerant and intrusion-tolerant control system for intelligent connected vehicles based on dynamic watermarking, for implementing the adaptive fault-tolerant and intrusion-tolerant control method for intelligent connected vehicles based on dynamic watermarking described in the first aspect, comprising: The module is used to build an adaptive neural network fault-tolerant controller based on a vehicle dynamics model, a radial basis function neural network, and a nonlinear disturbance observer. The radial basis function neural network is used to fit vehicle system faults, and the nonlinear disturbance observer is used to compensate for unknown disturbances and approximation errors. The fault-tolerant control signal generation module is used by the adaptive neural network fault-tolerant controller to generate fault-compensated fault-tolerant control signals based on the fitting results of the radial basis function neural network and the observation results of the nonlinear disturbance observer. The dynamic watermark signal embedding module is used to embed dynamic watermark signals into fault-tolerant control signals, generate watermarked control signals and apply them to the vehicle system. At the same time, based on the output measurement values of the vehicle system, the system state is estimated using a Kalman filter to obtain the system state estimate. The computation module is used to calculate the system residuals based on the state estimation results of the Kalman filter and the actual output of the system. Based on the statistical characteristics of the system residuals and the dynamic watermark signal, the evaluation function is constructed and the attack detection function is further defined. The judgment module is used to determine whether the vehicle system has been attacked based on the calculation results of the evaluation function and the attack detection function. If an attack is detected, the intrusion tolerance control strategy is executed, the attacked signal is removed from the system output signal, and Kalman filtering is used to estimate it. The estimated signal is used to replace the attacked signal to generate the intrusion tolerance system state signal. The closed-loop control module is used to feed back the system state signal after intrusion tolerance to the adaptive neural network fault-tolerant controller to generate new control signals and realize closed-loop control.
[0016] The present invention has at least the following beneficial effects: 1. This invention uses a radial basis function neural network (RBFNN) to fit actuator faults online, and uses a nonlinear disturbance observer (NDO) to compensate for unknown disturbances and neural network approximation errors to construct an adaptive fault-tolerant controller. On this basis, a dynamic watermark signal is embedded, and an attack evaluation function is constructed based on chi-square detection to accurately identify hidden replay attacks. It can simultaneously cope with the coupled threat of physical layer faults and information layer attacks, and significantly improve the overall safety margin of the intelligent connected vehicle control system.
[0017] 2. This invention uses a dynamic watermark signal as a random Gaussian noise injection control input that is independent of the system state, forming a predictable and unique imprint with time-varying variance on the residual statistical characteristics. Once an attacker replays historical data, the statistical correlation between the watermark signal and the residual will be destroyed, and the evaluation function value will significantly exceed the expected distribution range. Compared with traditional passive detection methods, this invention greatly improves the detection sensitivity and recognition accuracy of covert replay attacks.
[0018] 3. This invention designs a detection and judgment logic based on a continuous counting mechanism, such as triggering an alarm only after exceeding the threshold 10 times consecutively. This effectively filters false alarms caused by transient disturbances. Once an attack is confirmed, the system immediately removes the damaged measurement signal and enables Kalman filter estimation for closed-loop feedback, without interrupting the control process or switching to a backup controller.
[0019] Of course, any product implementing this invention does not necessarily need to achieve all of the advantages described above at the same time. Attached Figure Description
[0020] Figure 1 This is a flowchart illustrating the method described in this invention; Figure 2 This is a schematic diagram of the vehicle dynamics model in this invention; Figure 3 This is a schematic diagram illustrating the framework principle of the method described in this invention; Figure 4 This is a schematic diagram of the yaw angle simulation results in the fault-tolerant control simulation experiment of this invention; Figure 5 This is a schematic diagram of the detection results of replay attacks in this invention; Figure 6 This is a schematic diagram of the fault tolerance and intrusion control results in this invention. Detailed Implementation
[0021] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.
[0022] Example 1: Please see Figures 1-6 This invention provides a technical solution: an adaptive fault-tolerant and invasion-tolerant control method for intelligent connected vehicles based on dynamic watermarking, comprising the following steps: S1. An adaptive neural network fault-tolerant controller is constructed based on a vehicle dynamics model, a radial basis function neural network, and a nonlinear disturbance observer. The radial basis function neural network is used to fit the vehicle system fault, and the nonlinear disturbance observer is used to compensate for unknown disturbances and approximation errors. The adaptive neural network fault-tolerant controller generates a fault-compensated fault-tolerant control signal based on the fitting results of the radial basis function neural network and the observation results of the nonlinear disturbance observer. An adaptive neural network fault-tolerant controller is constructed based on a vehicle dynamics model, a radial basis function neural network, and a nonlinear disturbance observer, as detailed below: (S11) The systematic error is A and B are parameters in the dynamics model. The vehicle dynamics model is as follows: In the formula, External disturbances to the vehicle. To measure noise, and Bounded and The vehicle state matrix is centroid side slip angle The vehicle's yaw rate is , For the steering angle of the vehicle's front wheels and For direct yaw moment, For the overall vehicle weight; and These are the lateral stiffness of the front and rear tires, respectively. For vehicles to bypass Moment of inertia of the axis; and These are the distances from the center of mass to the front and rear axles, respectively. in: , In the formula, For vehicle quality, For the longitudinal speed of the vehicle, and These are the lateral stiffness of the front and rear tires, respectively. For vehicles to bypass Moment of inertia of the axis; and These are the distances from the center of mass to the front and rear axles, respectively. (S12) In the case of a vehicle actuator failure, the dynamic equation is: In the formula, Multiplicative fault coefficient and , It is an additive fault; This serves as the system control input after a fault. definition: The above dynamic equations are then: (S13) Use a radial basis function neural network to fit the faults that occur in the system, defined as: , In the formula, the radial basis function is: Update weights to , for Transpose of the weight matrix This represents the fitting error of the neural network. Choose the Gaussian function as the radial basis function: in and The center of the receptive field and the width of the Gaussian function are described respectively; to minimize the approximation error, the optimal weights are found through an update process. , Make it as small as possible, until it approaches 0; (S14) In order to account for the existence of fitting error and unknown external disturbances Define a new composite function: Using a nonlinear perturbation observer to estimate composite perturbations: In the formula, As an intermediate variable, For the design of positive constants, yes The observed values, for The observed values have a systematic error of . , yes Reference value; (S15) Adaptive neural network fault-tolerant controller, specifically represented as follows: in It is a positive parameter of the design, and ; S2. A random Gaussian noise signal with a variance of 0.02 is embedded into the fault-tolerant control signal as a dynamic watermark signal to generate a watermarked control signal, which is then applied to the vehicle system. Simultaneously, based on the output measurement value of the vehicle system (vehicle yaw rate)... and centroid side slip angle The system state is estimated using a Kalman filter, as shown below: In the discrete time domain: Where T is the sampling period, the vehicle dynamics model can be obtained by sampling the variables in the continuous-time system (7) at time steps. (Right now Rewritten in discrete-time form as: in In this work, the state estimate is obtained using a Kalman filter. Due to system faults and external disturbances, the control input does not represent the actual input applied to the system actuators. By utilizing the fault and disturbance compensation provided by the previously described neural network and disturbance observer, the impact of faults and disturbances on the Kalman filter-based state estimate can be effectively mitigated. Therefore, the following compensated control input should be used in the estimation process: After adding a dynamic watermark: in, To produce a dynamic watermark signal that conforms to a Gaussian distribution, The specific steps of Kalman filtering are as follows: (1) (2) in, Indicates time State estimates, For a moment The prior state estimate, For Kalman filtering at time 1 The gain matrix, For a moment The prior error covariance matrix, For a moment The posterior error covariance matrix; matrix Let these represent the process noise covariance matrix and the measurement noise covariance matrix, respectively. S3. Based on the state estimation results of the Kalman filter and the actual output of the system, calculate the system residuals. Based on the statistical characteristics of the system residuals and the dynamic watermark signal, construct an evaluation function and further define an attack detection function, as follows: (S31) Define the system residual as: The statistical properties of residuals with dynamic watermarks are expressed as follows: In the formula, The vehicle model parameter matrix is in discrete form. For dynamic watermark signals, These are the mean and variance of the residual distribution of a dynamic watermarking system that conforms to a normal distribution. The difference between the rows of the system residual distribution under normal conditions, where k is the current time; (S32) Based on A chi-square test method was designed with an evaluation function. This is used to measure the degree of deviation between the actual residual signal of the system and its expected statistical distribution, where i represents which signal channel, 1 and 2 represent the centroid sideslip angle and yaw rate channels, respectively, and j represents the discrete time scale. in, This indicates the length of the time window for the evaluation function. , The variance of the dynamic watermark added to the i-th channel. Let represent the system residual, residual mean, and residual variance of the i-th channel at time j, respectively. Based on this, the attack detection function is defined as follows: in, and They represent the first Evaluation and test functions for each channel; S4. Based on the calculation results of the evaluation function and the attack detection function, determine whether the vehicle system has been attacked. If an attack is detected, execute the invasion-tolerant control strategy, remove the attacked signal from the system output signal, use Kalman filtering for estimation, and replace the attacked signal with the estimated signal to generate the invasion-tolerant system state signal, as follows: The obtained attack detection function value is input into the attack detection and intrusion control strategy algorithm. The attack detection and intrusion control strategy algorithm determines whether an attack has occurred by continuously monitoring the output value of the attack verification function, and uses a counter mechanism to avoid false alarms caused by momentary interference. Only when the number of consecutive or continuous exceedances of the threshold reaches a preset value will it be finally determined that an attack has occurred. As shown in Table 1, the integrated attack detection and intrusion control strategy algorithm is used to determine whether the system has been attacked, and to execute corresponding intrusion control measures when an intrusion is detected, as follows: Table 1. Integrated Strategy for Attack Detection and Intrusion Prevention S5. Feedback the compromised system state signal to the adaptive neural network fault-tolerant controller to generate a new control signal and achieve closed-loop control, as detailed below: After performing discrete-time state estimation based on Kalman filtering, the estimation results are remapped back to the continuous-time system through the same sampling process, enabling the controller to operate in the continuous-time frame. Therefore, the system state matrix is redefined as... The fault-tolerant and invasion-tolerant integrated control algorithm based on adaptive neural networks is restated as follows: in .
[0023] like Figure 2 As shown, the vehicle is a four-wheel independent drive, and a vehicle dynamics model was established based on mechanical relationships.
[0024] like Figure 3 As shown, the control design combines an NDO for real-time compensation of external disturbances and an RBFNN for handling actuator faults. A dynamic watermark is embedded in the controller, and replay attacks are detected in real-time using a designed evaluation function and attack detection strategy. Additionally, a switching mechanism is introduced so that when a replay attack is detected, the system replaces the damaged signal with an estimate generated by a Kalman filter, thereby achieving intrusion-tolerant control.
[0025] like Figure 4The diagram shows the simulation results of the yaw angle in the fault-tolerant control simulation experiment. The comparison algorithm is the basic algorithm without RBFNN and NDO, i.e. The system experienced actuator failures during the 2–4 s and 12–13 s time periods, with a multiplicative fault coefficient set to 0.5. Test results show that during the fault periods, the tracking accuracy of the controller without neural network significantly decreased, and actuator failures severely weakened the vehicle's trajectory tracking performance and reduced handling stability. In contrast, the fault-tolerant control algorithm based on adaptive neural networks proposed in this paper can effectively compensate for the impact of faults while maintaining good trajectory tracking accuracy. like Figure 5 The diagram illustrates the detection process of replay attacks. Due to the stealth nature of these attacks, traditional detectors without dynamic watermarks struggle to identify them in a timely manner (see...). Figure 5 a). When dynamic watermarking is introduced, the system output contains a non-replicable watermark signal, disrupting the statistical consistency of the residual distribution in replay attacks. Combined with the statistical characteristics of the detector, the evaluation function rises rapidly after the attack occurs (see...). Figure 5 (b) Attack detection can be completed within 0.1 seconds. The detection threshold is set to 0.005, and its location is marked by the red line in the figure.
[0026] like Figure 6 As shown, the state estimation results of the Kalman filter are presented after the invasion-tolerant control strategy is activated. Figure 6 As can be seen, after a replay attack, the tracking accuracy and estimation accuracy of the system both decreased due to the isolation of the contaminated signal; however, overall, the system can still complete the tracking task with high reliability. Figure 6 b further demonstrates that actuator failure will not interfere with or mislead the attack detection process. When an attack occurs, the evaluation function value rises rapidly and exceeds a preset threshold, triggering the intrusion tolerance control strategy. At this point, the evaluation function value will return to its normal value, falling below the trigger threshold. Thanks to this strategy design, once an attack is detected, the system will continuously maintain an intrusion tolerance control state, avoiding frequent switching between "intrusion tolerance" and "non-intrusion tolerance" modes due to changes in the evaluation function, which would otherwise lead to control performance degradation. Figure 6 As shown in c, once the system detects an attack, the intrusion prevention control policy remains active throughout the entire task execution process until the task is completed or the system terminates.
[0027] In summary, this invention creatively unifies fault-tolerant control for hardware failures and intrusion-tolerant control for network attacks within the same adaptive control framework. Through the integrated design of radial basis function neural networks (RBFNN) and nonlinear disturbance observers (NDO), it achieves real-time fitting and compensation for system failures and external disturbances, realizing highly reliable fault-tolerant control. On this basis, dynamic watermarking technology is introduced to construct an active security defense layer, realizing the detection and intrusion tolerance of covert network attacks. This integrated design fundamentally overcomes the shortcomings of traditional solutions where fault and attack handling are separated, providing a unified and comprehensive security control solution for intelligent connected vehicles.
[0028] Example 2: This embodiment provides an adaptive fault-tolerant and invasion-tolerant control system for intelligent connected vehicles based on dynamic watermarking, used to implement the adaptive fault-tolerant and invasion-tolerant control method for intelligent connected vehicles based on dynamic watermarking described in Embodiment 1, including: The module is used to build an adaptive neural network fault-tolerant controller based on a vehicle dynamics model, a radial basis function neural network, and a nonlinear disturbance observer. The radial basis function neural network is used to fit vehicle system faults, and the nonlinear disturbance observer is used to compensate for unknown disturbances and approximation errors. The fault-tolerant control signal generation module is used by the adaptive neural network fault-tolerant controller to generate fault-compensated fault-tolerant control signals based on the fitting results of the radial basis function neural network and the observation results of the nonlinear disturbance observer. The dynamic watermark signal embedding module is used to embed dynamic watermark signals into fault-tolerant control signals, generate watermarked control signals and apply them to the vehicle system. At the same time, based on the output measurement values of the vehicle system, the system state is estimated using a Kalman filter to obtain the system state estimate. The computation module is used to calculate the system residuals based on the state estimation results of the Kalman filter and the actual output of the system. Based on the statistical characteristics of the system residuals and the dynamic watermark signal, the evaluation function is constructed and the attack detection function is further defined. The judgment module is used to determine whether the vehicle system has been attacked based on the calculation results of the evaluation function and the attack detection function. If an attack is detected, the intrusion tolerance control strategy is executed, the attacked signal is removed from the system output signal, and Kalman filtering is used to estimate it. The estimated signal is used to replace the attacked signal to generate the intrusion tolerance system state signal. The closed-loop control module is used to feed back the system state signal after intrusion tolerance to the adaptive neural network fault-tolerant controller to generate new control signals and realize closed-loop control.
[0029] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0030] For those skilled in the art, the specific meaning of the above terms in this invention can be understood according to the specific circumstances. When an element is referred to as being "assembled on," "mounted on," "fixed to," or "set on" another element, it may be directly on the other element or there may be an intermediate element present. When an element is considered to be "connected to" another element, it may be directly connected to the other element or there may be an intermediate element present. The terms "vertical," "horizontal," "upper," "lower," "left," "right," and similar expressions used herein are for illustrative purposes only and do not represent the only possible embodiments.
[0031] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
[0032] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this disclosure. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
Claims
1. A method for adaptive fault-tolerant and intrusion-tolerant control of intelligent connected vehicles based on dynamic watermarking, characterized in that, Includes the following steps: An adaptive neural network fault-tolerant controller is constructed based on a vehicle dynamics model, a radial basis function neural network, and a nonlinear disturbance observer. The radial basis function neural network is used to fit the vehicle system fault, and the nonlinear disturbance observer is used to compensate for unknown disturbances and approximation errors. The adaptive neural network fault-tolerant controller generates a fault-compensated fault-tolerant control signal based on the fitting results of the radial basis function neural network and the observation results of the nonlinear disturbance observer. A dynamic watermark signal is embedded in the fault-tolerant control signal to generate a watermarked control signal and apply it to the vehicle system. At the same time, based on the output measurement value of the vehicle system, a Kalman filter is used to estimate the system state and obtain the system state estimate value. Based on the state estimation results of the Kalman filter and the actual output of the system, the system residual is calculated. Based on the statistical characteristics of the system residual and the dynamic watermark signal, an evaluation function is constructed and an attack detection function is further defined. Based on the calculation results of the evaluation function and the attack detection function, it is determined whether the vehicle system has been attacked. If an attack is detected, an intrusion tolerance control strategy is executed. The attacked signal is removed from the system output signal, and Kalman filtering is used to estimate it. The estimated signal is used to replace the attacked signal to generate the intrusion tolerance system state signal. The system state signal after the intrusion is tolerated is fed back to the adaptive neural network fault-tolerant controller to generate a new control signal and achieve closed-loop control.
2. The adaptive fault-tolerant and intrusion-tolerant control method for intelligent connected vehicles based on dynamic watermarking according to claim 1, characterized in that: An adaptive neural network fault-tolerant controller is constructed based on a vehicle dynamics model, a radial basis function neural network, and a nonlinear disturbance observer, as detailed below: (21) A and B are the parameter matrices in the dynamic model, and C is the transformation matrix from system state to system output. The vehicle dynamic model is: In the formula, External disturbances to the vehicle. To measure noise, and Bounded and The vehicle state matrix is The centroid sideslip angle is The vehicle's yaw rate is , For the steering angle of the vehicle's front wheels and This is the direct yaw moment; in: , In the formula, For vehicle quality, For the longitudinal speed of the vehicle, and These are the lateral stiffness of the front and rear tires, respectively. For vehicles to bypass Moment of inertia of the axis; and These are the distances from the center of mass to the front and rear axles, respectively. (22) In the case of a vehicle actuator failure, the dynamic equation is: In the formula, Multiplicative fault coefficient and , It is an additive fault; This serves as the system control input after a fault. definition: The above dynamic equations are then: (23) Using a radial basis function neural network to fit the faults that occur in the system, defined as: , In the formula, the radial basis function is: Update weights to , for Transpose of the weight matrix This represents the fitting error of the neural network. Choose the Gaussian function as the radial basis function: in and The center of the receptive field and the width of the Gaussian function are described respectively; to minimize the approximation error, the optimal weights are found through an update process. , Make it as small as possible, until it approaches 0; (24) In order to solve the fitting error and unknown external disturbances Define a new composite function: Using a nonlinear perturbation observer to estimate composite perturbations: In the formula, As an intermediate variable, For the design of positive constants, yes The observed values, for The observed values have a systematic error of . , yes Reference value; (25) Adaptive neural network fault-tolerant controller, specifically represented as follows: in It is a positive parameter of the design, and .
3. The adaptive fault-tolerant and invasion-tolerant control method for intelligent connected vehicles based on dynamic watermarking according to claim 2, characterized in that: The dynamic watermark signal is a random Gaussian noise signal with a variance of 0.
02.
4. The adaptive fault-tolerant and intrusion-tolerant control method for intelligent connected vehicles based on dynamic watermarking according to claim 3, characterized in that: A dynamic watermark signal is embedded in the fault-tolerant control signal to generate a watermarked control signal, which is then applied to the vehicle system. Simultaneously, based on the output measurements of the vehicle system, a Kalman filter is used to estimate the system state, yielding the system state estimate, as detailed below: (41) In the discrete time domain: Where T is the sampling period, the vehicle dynamics model is obtained by sampling the variables in the continuous-time system at a time step. ,Right now When, rewritten in discrete time form as: in ; The state estimate is obtained by using a Kalman filter, with the following control input after disturbance and error compensation used during the estimation process: After adding a dynamic watermark: in, To produce a dynamic watermark signal that conforms to a Gaussian distribution, (42) The specific steps of Kalman filtering are as follows: in, express time State estimates, For a moment The prior state estimate, For Kalman filtering at time 1 The gain matrix, For a moment The prior error covariance matrix, For a moment The posterior error covariance matrix; matrix These represent the process noise covariance matrix and the measurement noise covariance matrix, respectively.
5. The adaptive fault-tolerant and invasion-tolerant control method for intelligent connected vehicles based on dynamic watermarking according to claim 4, characterized in that: Based on the state estimation results of the Kalman filter and the actual output of the system, the system residuals are calculated. Based on the statistical characteristics of the system residuals and the dynamic watermark signal, an evaluation function is constructed and an attack detection function is further defined, as follows: (51) Define the system residual as: The statistical properties of residuals with dynamic watermarks are expressed as follows: In the formula, The vehicle model parameter matrix is in discrete form. For dynamic watermark signals, These are the mean and variance of the residual distribution of a dynamic watermarking system that conforms to a normal distribution. The difference between the rows of the system residual distribution under normal conditions, where k is the current time; (52) Based on A chi-square test method was designed with an evaluation function. This is used to measure the degree of deviation between the actual residual signal of the system and its expected statistical distribution, where i represents which signal channel, 1 and 2 represent the centroid sideslip angle and yaw rate channels, respectively, and j represents the discrete time scale. in, This indicates the length of the time window for the evaluation function. , The variance of the dynamic watermark added to the i-th channel. Let represent the system residual, residual mean, and residual variance of the i-th channel at time j, respectively. Based on this, the attack detection function is defined as follows: in, and They represent the first Evaluation and testing functions for each channel.
6. The adaptive fault-tolerant and intrusion-tolerant control method for intelligent connected vehicles based on dynamic watermarking according to claim 5, characterized in that: The determination of whether a vehicle system has been attacked is based on the calculation results of the evaluation function and the attack detection function, as follows: The obtained attack detection function value is input into the attack detection and intrusion control strategy algorithm. The attack detection and intrusion control strategy algorithm determines whether an attack has occurred by continuously monitoring the output value of the attack verification function, and uses a counter mechanism to avoid false alarms caused by momentary interference. Only when the number of consecutive or continuous exceedances of the threshold reaches a preset value will it be finally determined that an attack has occurred.
7. The adaptive fault-tolerant and intrusion-tolerant control method for intelligent connected vehicles based on dynamic watermarking according to claim 6, characterized in that: The specific steps of the attack detection and intrusion prevention control strategy algorithm are as follows: (71) Receive the test function result It also initializes two persistent variables: a counter `count` and a trigger flag `triggered`. (72) Update the counter: When the test function value of a certain channel is greater than the threshold, the count is incremented; otherwise, it is cleared to zero. (73) When count≥10 and triggered is false, set triggered to true and output the attack flag; (74) When the attack flag is true, remove the damaged signal from the current measurement output, replace it with the Kalman filter estimate, and re-execute the Kalman filter update; (75) Output attack detection results and system status ,in This indicates that the system has been attacked. This indicates that the system is functioning normally.
8. The adaptive fault-tolerant and intrusion-tolerant control method for intelligent connected vehicles based on dynamic watermarking according to claim 7, characterized in that: The fault-tolerant system state signal after intrusion is fed back to the adaptive neural network fault-tolerant controller to generate a new control signal and achieve closed-loop control, as follows: After performing discrete-time state estimation based on Kalman filtering, the estimation results are remapped back to the continuous-time system through the same sampling process, enabling the controller to operate in the continuous-time frame. Therefore, the system state matrix is redefined as... The fault-tolerant and invasion-tolerant integrated control algorithm based on adaptive neural networks is restated as follows: in .
9. A dynamic watermark-based adaptive fault-tolerant and intrusion-tolerant control system for intelligent connected vehicles, used to implement the dynamic watermark-based adaptive fault-tolerant and intrusion-tolerant control method for intelligent connected vehicles as described in any one of claims 1 to 8, characterized in that, include: The module is used to build an adaptive neural network fault-tolerant controller based on a vehicle dynamics model, a radial basis function neural network, and a nonlinear disturbance observer. The radial basis function neural network is used to fit vehicle system faults, and the nonlinear disturbance observer is used to compensate for unknown disturbances and approximation errors. The fault-tolerant control signal generation module is used by the adaptive neural network fault-tolerant controller to generate fault-compensated fault-tolerant control signals based on the fitting results of the radial basis function neural network and the observation results of the nonlinear disturbance observer. The dynamic watermark signal embedding module is used to embed dynamic watermark signals into fault-tolerant control signals, generate watermarked control signals and apply them to the vehicle system. At the same time, based on the output measurement values of the vehicle system, the system state is estimated using a Kalman filter to obtain the system state estimate. The computation module is used to calculate the system residuals based on the state estimation results of the Kalman filter and the actual output of the system. Based on the statistical characteristics of the system residuals and the dynamic watermark signal, the evaluation function is constructed and the attack detection function is further defined. The judgment module is used to determine whether the vehicle system has been attacked based on the calculation results of the evaluation function and the attack detection function. If an attack is detected, the intrusion tolerance control strategy is executed, the attacked signal is removed from the system output signal, and Kalman filtering is used to estimate it. The estimated signal is used to replace the attacked signal to generate the intrusion tolerance system state signal. The closed-loop control module is used to feed back the system state signal after intrusion tolerance to the adaptive neural network fault-tolerant controller to generate new control signals and realize closed-loop control.
Citation Information
Patent Citations
Fault-tolerant control method for networked automobile control system
CN109981339A
Path tracking control method based on vehicle fault signal isolation
CN112550294A