Intrusion data discrimination method and device, electronic equipment, storage medium and vehicle
By constructing a feature matrix of running data and dynamically adjusting the confidence level, the problem of high false alarm rate in vehicle intrusion detection system was solved, achieving more accurate intrusion data identification and reducing the false alarm rate, thus ensuring the real-time performance and reliability of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-05
- Publication Date
- 2026-03-10
AI Technical Summary
Existing vehicle intrusion detection systems have a high false alarm rate, resulting in a large number of false alarms and reducing the reliability and effectiveness of the security system.
By constructing a feature matrix of operational data, combining vehicle operational context information and data from multiple vehicles of the same type, the confidence level is dynamically adjusted to identify intrusion data and reduce the false alarm rate.
Significantly reduces false alarm rate, improves accuracy of intrusion data identification, and ensures system real-time performance and reliability.
Smart Images

Figure CN121644179A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of vehicle information security, and in particular to an intrusion data discrimination method, an intrusion data discrimination device, an electronic device, a storage medium and a vehicle. BACKGROUND
[0002] With the rapid popularization of intelligent networked vehicles and the profound changes in automotive electronic architecture, vehicle information security has become a key issue of industry concern. Modern intelligent networked vehicles usually contain 50-100 electronic control units (ECUs), which form a complex heterogeneous network architecture through various network buses (such as CAN, LIN, FlexRay, vehicle Ethernet, etc.), and are connected to external networks through T-Box, gateway and other devices. This highly interconnected architecture not only brings intelligent functions to vehicles, but also greatly expands the attack interface, making vehicles face serious information security threats.
[0003] Current vehicle intrusion detection systems mainly use rule-based detection methods, including signature-based detection, statistical anomaly-based detection and protocol specification-based detection. Signature-based detection methods identify threats by matching known attack patterns, such as abnormal frequency detection of specific CAN IDs, message content feature matching, etc.; statistical anomaly detection methods identify abnormal behavior by establishing a normal behavior baseline. Protocol specification detection methods identify anomalies by verifying communication protocol compliance. However, in practical applications, it is found that these methods all have high false positive rates.
[0004] In actual vehicle operating environments, false positives are particularly prominent. For example, significant increases in brake message frequency under intense driving conditions, sensor data anomalies under special road conditions, and ECU behavior differences caused by different driving styles, etc. normal phenomena may be misjudged as attack behavior by traditional detection methods. Such high false positive rates not only result in a large number of false alarms, which overwhelm real threats, but also cause driver safety alert fatigue, severely reducing the credibility and effectiveness of safety systems. According to statistics, in related technologies, the false positive rate of vehicle intrusion detection systems is generally as high as 30%-50%, which greatly restricts the actual application effect of related technologies. SUMMARY
[0005] The purpose of the present application is to provide an intrusion data discrimination method, an intrusion data discrimination device, an electronic device, a storage medium and a vehicle, which at least solve one of the technical problems of how to reduce the false positive rate of intrusion data and how to improve the accuracy of identifying intrusion data.
[0006] The present application provides the following solutions:
[0007] According to one aspect of the present application, there is provided an intrusion data discrimination method, comprising:
[0008] By a preset discrimination model, multi-dimensional operation data features are extracted from the collected first vehicle operation data of a vehicle, and an operation data feature matrix is constructed;
[0009] Based on context information in the vehicle operation process, a confidence of the operation data feature matrix is determined;
[0010] According to second vehicle operation data of a plurality of vehicles of the same type, the operation data features are discriminated in combination with the confidence, and an intrusion data discrimination result is determined.
[0011] Further, the multi-dimensional operation data features are extracted from the collected vehicle operation data, and the operation data feature matrix is constructed, comprising:
[0012] According to a plurality of preset feature dimensions, corresponding operation data features are extracted from the first vehicle operation data;
[0013] According to data timestamps, data source identifiers, data types, and data contents, the operation data features are standardized processed;
[0014] According to a preset feature selection mechanism, dynamic operation data features in the standardized processed operation data features are adjusted, and the operation data feature matrix is constructed.
[0015] Further, the confidence of the operation data feature matrix is determined based on the context information in the vehicle operation process, comprising:
[0016] The operation data feature matrix is feature screened, abnormal data features are determined, and an initial confidence of the abnormal data features is determined;
[0017] The vehicle operation state is determined in the first vehicle operation data, and the abnormal data features are associated according to the context information and the vehicle operation state, and an association degree between the abnormal data features is determined;
[0018] The initial confidence is dynamically adjusted according to the association degree, and the confidence of the abnormal data features is determined.
[0019] Further, the operation data features are discriminated in combination with the confidence according to the second vehicle operation data of a plurality of vehicles of the same type, and an intrusion data discrimination result is determined, comprising:
[0020] The abnormal data features are compared and analyzed according to the second vehicle operation data;
[0021] In response to the fact that the second vehicle operation data has the same operation data characteristics as the abnormal data characteristics, the abnormal data characteristics are determined to be intrusion data characteristics;
[0022] Based on the confidence level, the characteristics of the intrusion data are determined, and the intrusion data identification result is determined.
[0023] Furthermore, after determining the intrusion data identification result, the method further includes:
[0024] In response to the intrusion data identification result indicating the presence of intrusion data, a data intrusion warning is executed.
[0025] Furthermore, the method also includes:
[0026] The performance of the discriminant model is tested;
[0027] In response to the performance falling below a preset performance threshold, model optimization parameters are obtained;
[0028] The discrimination model is optimized according to the model optimization parameters, and the vehicle operation data is discriminated based on the optimized discrimination model.
[0029] According to a second aspect of the present invention, an intrusion data identification device is provided, comprising:
[0030] The feature extraction module is used to extract multi-dimensional operation data features from the first vehicle operation data of the target vehicle through a preset discrimination model, and construct an operation data feature matrix.
[0031] The confidence determination module is used to determine the confidence level of the operation data feature matrix based on contextual information during vehicle operation.
[0032] The intrusion determination module is used to determine the intrusion data determination result by judging the characteristics of the operating data based on the operating data of multiple second vehicles of the same type as the target vehicle and in combination with the confidence level.
[0033] According to three aspects of the present invention, an electronic device is provided, comprising: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;
[0034] The memory stores a computer program, which, when executed by the processor, causes the processor to perform the steps of the intrusion data detection method.
[0035] According to four aspects of the present invention, a computer-readable storage medium is provided, comprising: storing a computer program executable by an electronic device, wherein when the computer program is run on the electronic device, the electronic device performs the steps of an intrusion data identification method.
[0036] According to five aspects of the present invention, a vehicle is provided, comprising:
[0037] Electronic equipment used to implement intrusion data detection methods;
[0038] The processor runs a program, and when the program runs, it executes the steps of the intrusion data identification method based on the data output from the electronic device.
[0039] Storage medium used to store programs that, when running, execute intrusion data detection methods on data output from electronic devices.
[0040] The above solution achieves the following beneficial technical effects:
[0041] This application extracts multi-dimensional operational data features, constructs an operational data feature matrix, and realizes multi-source data fusion analysis. It fully considers the characteristics of vehicles as mobile physical entities, effectively distinguishes between real attacks and normal behavioral variations, and reduces the false alarm rate.
[0042] This application uses vehicle operating context and confidence level to perform multi-level discrimination of operating data features. It can comprehensively consider operating data features and effectively identify normal behavior variations caused by driving behavior, environmental factors, etc., thereby significantly reducing the false alarm rate, improving the accuracy of security threat identification, and ensuring the real-time performance and reliability of the system. Attached Figure Description
[0043] Figure 1 This is a flowchart of an intrusion data identification method provided by one or more embodiments of the present invention.
[0044] Figure 2 This is a schematic diagram of vehicle operation data collection provided in a specific embodiment of the present invention.
[0045] Figure 3 This is a schematic diagram of feature processing provided in a specific embodiment of the present invention.
[0046] Figure 4 This is a schematic diagram of intrusion data discrimination provided in a specific embodiment of the present invention.
[0047] Figure 5 This is a schematic diagram of a feedback training process provided in a specific embodiment of the present invention.
[0048] Figure 6 This is a schematic diagram of the overall framework for intrusion data discrimination provided in a specific embodiment of the present invention.
[0049] Figure 7 This is a structural diagram of an intrusion data discrimination device provided in one or more embodiments of the present invention.
[0050] Figure 8 This is a block diagram of an electronic device structure for an intrusion data discrimination method provided in one or more embodiments of the present invention. Detailed Implementation
[0051] The technical solution of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0052] Figure 1 This is a flowchart of an intrusion data identification method provided by one or more embodiments of the present invention.
[0053] like Figure 1 The intrusion data identification methods shown include:
[0054] Step S1: Using a preset discrimination model, extract multi-dimensional operation data features from the first vehicle operation data of the target vehicle and construct an operation data feature matrix.
[0055] The discrimination model is trained in the cloud based on historical intrusion data. The cloud then downloads the discrimination model to the vehicle via Over-the-Air (OTA) technology. The vehicle installs the discrimination model and performs the intrusion data discrimination process.
[0056] Figure 2 This is a schematic diagram illustrating vehicle operation data collection according to a specific embodiment of the present invention. Figure 2 As shown, a comprehensive data acquisition system can be established by systematically collecting multi-dimensional data during vehicle operation through the vehicle-side data acquisition layer. For example, a distributed acquisition architecture can be adopted, deploying multiple data acquisition agents within the vehicle, including network monitoring agents, status monitoring agents, behavior recording agents, and environmental awareness agents. Each agent operates independently, exchanging data through a shared memory mechanism and employing circular buffer technology to resolve data storage conflicts, ensuring the integrity and real-time performance of the data acquisition. It should be noted that all data acquisition agents use a unified time synchronization protocol to ensure the consistency of data timestamps. By establishing a complete vehicle operation status data system, rich contextual information is provided for subsequent analysis. The first and second vehicle operation data share the same dimensions; this is merely to distinguish the vehicle operation data corresponding to different vehicles.
[0057] Furthermore, the dimensions for collecting vehicle operation data can include network traffic data collection, vehicle status data collection, ECU behavior data collection, and external environment data collection.
[0058] The network traffic data acquisition refers to the acquisition of CAN, CAN FD, and vehicle Ethernet communication messages with a time accuracy of 1ms through the vehicle network gateway, and the recording of complete communication sequences and timing characteristics.
[0059] The vehicle status data acquisition refers to collecting vehicle operating parameters such as vehicle speed, gear position, turn signal status, accelerator and brake opening, and steering wheel angle at a sampling period of 10ms, and establishing a time series database of vehicle operating status.
[0060] The electronic control unit (ECU) behavior data acquisition collects runtime indicators such as process status, memory usage, CPU load, and abnormal restart records of key ECUs through diagnostic interfaces and system monitoring modules.
[0061] The external environment data is collected by obtaining vehicle location information through a GPS module, obtaining high-precision timestamps through a time server, and obtaining environmental condition data through a meteorological interface.
[0062] Based on the aforementioned dimensions of vehicle operation data collection, multi-dimensional operation data features can be extracted by using an edge computing layer deployed on the vehicle domain controller, thereby constructing a corresponding operation data feature matrix based on the extracted operation data features.
[0063] Step S2: Determine the confidence level of the operation data feature matrix based on the context information during vehicle operation.
[0064] In this embodiment, a deep analysis of the contextual information during vehicle operation is performed to establish a driving behavior recognition system and determine the confidence level of the operational data feature matrix. For example, operational data features indicating near-intrusion behavior correspond to high confidence, while operational data features indicating normal behavior correspond to low confidence.
[0065] Step S3: Based on the second vehicle operation data of multiple vehicles of the same type, and combined with the confidence level, the operation data characteristics are judged to determine the intrusion data judgment result.
[0066] In this embodiment, second vehicle operation data of multiple vehicles of the same type as the vehicle can be obtained. By comparing and analyzing the operation data features with the confidence levels corresponding to the determined first operation data features, abnormal data caused by user driving behavior habits can be filtered out, thereby generating intrusion data discrimination results to reduce the error rate of intrusion data discrimination.
[0067] The intrusion data discrimination method provided in this embodiment integrates and analyzes multi-source data, fully considers the characteristics of vehicles as mobile physical entities, optimizes the vehicle network architecture and operating characteristics, and can effectively identify normal behavior variations caused by driving behavior, environmental factors, etc., thereby significantly reducing the false alarm rate.
[0068] As in the above embodiment, the vehicle operation data is collected from multiple sources of vehicle data. The implementation method for extracting multi-dimensional operation data features from the multiple sources of data and constructing an operation data feature matrix is as follows.
[0069] Figure 3 This is a schematic diagram of feature processing provided in a specific embodiment of the present invention. For example... Figure 3 As shown, based on multiple preset feature dimensions, corresponding operational data features are extracted from the first vehicle operational data. These multi-dimensional operational data features include extracted network traffic data features, extracted vehicle status data features, extracted ECU behavior data features, and extracted external environment data features.
[0070] For example, features extracted from network traffic data include feature vectors representing dimensions such as packet frequency statistics, sequence pattern features, and content distribution features. Features extracted from vehicle status data include feature vectors representing dimensions such as operating mode features, driving behavior features, and operating condition classification features. Features extracted from ECU behavior data include feature vectors representing dimensions such as resource usage patterns, abnormal behavior features, and performance index features.
[0071] Furthermore, the operational data features are standardized based on data timestamps, data source identifiers, data types, and data content. Simultaneously, according to a preset feature selection mechanism, the dynamic operational data features within the standardized operational data features are adjusted to construct an operational data feature matrix.
[0072] One of the standardization methods is Z-score standardization.
[0073] Operational data characteristics include static operational data characteristics and dynamic operational data characteristics. Static operational data characteristics can be determined by the frequency of their use.
[0074] The feature selection mechanism can be determined based on mutual information and chi-square test to identify the dynamic operating data features of the current vehicle. These dynamic features can be selected according to different operating scenarios of the current vehicle. For example, different dynamic features can be selected based on operating scenarios such as the decline in vehicle condition due to vehicle age or the impact of winter seasons on driving.
[0075] The feature selection mechanism can be configured via remote OTA upgrade or determined based on the vehicle's own data.
[0076] For example, after all runtime data features are standardized using Z-score, they can form a multi-dimensional unified runtime data feature matrix.
[0077] In this embodiment, the stability of feature distribution can be monitored in real time according to the established feature quality monitoring system. When a significant drift occurs, the feature reconstruction process is automatically triggered to re-extract the running data features and construct the running data feature matrix to ensure the effectiveness and adaptability of the features.
[0078] After determining the feature matrix of the running data, the intrusion data of the running data features is identified through a multi-level judgment method, and the implementation method is as follows.
[0079] Figure 4 This is a schematic diagram illustrating intrusion data discrimination according to a specific embodiment of the present invention. For example... Figure 4 As shown, the Bloom filter technique can be used to filter the features of the running data feature matrix, identify abnormal data features, generate millisecond-level primary alarms, and determine the initial confidence level of abnormal data features.
[0080] The vehicle's operating status is determined from the initial vehicle operation data. Based on contextual information and the vehicle's operating status, anomalous data features are correlated to determine the correlation degree between these features. The vehicle operating status includes information such as vehicle operation pattern recognition, driving behavior analysis, and environmental context understanding. The initial confidence level is dynamically adjusted based on the correlation degree to determine the confidence level of the anomalous data features.
[0081] Furthermore, dynamically adjusting the initial confidence level based on the correlation includes increasing the confidence level corresponding to abnormal data features that are closer to intrusion behavior and decreasing the confidence level corresponding to abnormal data features that are closer to normal behavior, thereby determining the confidence level of each abnormal data feature.
[0082] This embodiment utilizes a threat verification mechanism based on swarm intelligence. A distributed consensus algorithm is used to compare and analyze abnormal data features against the second vehicle's operational data. If the second vehicle's operational data exhibits the same operational data features as the abnormal data, the abnormal data features are identified as intrusion data features. Based on the confidence level, the intrusion data features are determined, and the intrusion data identification result is confirmed, ensuring the reliability of the identification result.
[0083] If the identified abnormal data appears in a specific vehicle, but other vehicles do not exhibit the same abnormal data under the same conditions, then the occurrence of the abnormal data is likely due to the user's driving habits and is not a genuine abnormality.
[0084] Through a multi-level discrimination mechanism, multi-dimensional operational data features can be integrated and fused, and the final discrimination result can be generated by adjusting the confidence level mechanism to ensure the accuracy of the discrimination result.
[0085] In this embodiment, if the intrusion data identification result indicates the presence of intrusion data, a data intrusion warning is issued. The data intrusion warning can be issued as an audible warning or as an indicator light.
[0086] In this embodiment, the performance of the discrimination model can also be detected. If the performance falls below a preset performance threshold, model optimization parameters are obtained. These optimization parameters are determined by a cloud-based computing platform and sent from the cloud to the vehicle for updating the installed discrimination model. This embodiment uses a sampling differential update and canary release method to send the model optimization parameters, ensuring the security and stability of the model update.
[0087] Figure 5 This is a schematic diagram of a feedback training process provided in a specific embodiment of the present invention. For example... Figure 5 As shown, the feedback learning optimization module (i.e., the self-learning optimization system) of the cloud computing platform, based on an established multi-level labeled database, acquires confirmed false alarm samples and threat samples of intrusion data. The sampling incremental learning mechanism periodically updates the machine learning model, using the XGBoost algorithm to achieve high-precision classification. Based on the acquired false alarm samples and threat samples, the discrimination model is retrained at preset time intervals to determine the model optimization parameters. The training process employs cross-validation and grid search to optimize hyperparameters, ensuring optimal model performance. The preset time interval can be 24 hours. By establishing a self-learning optimization mechanism, the system can continuously optimize discrimination accuracy and reduce the false alarm rate as usage time increases. The system stores false alarm samples and threat samples in the labeled database, periodically updates the machine learning model using an incremental learning mechanism, uses confidence calibration methods to ensure the accuracy of probability outputs, and continuously optimizes and updates model parameters through a secure OTA channel.
[0088] After receiving the model optimization parameters, the vehicle-side system optimizes the discrimination model based on the optimization parameters and then uses the optimized discrimination model to make judgments on the vehicle operation data.
[0089] By leveraging vehicle-cloud collaboration, the discrimination model can be updated, ensuring efficient cooperation among all parts of the system. This guarantees real-time local detection while utilizing cloud-based big data to improve detection accuracy. It also enables intelligent resource-aware scheduling, controlling CPU and memory usage to meet the resource constraints of the vehicle system while maintaining detection performance.
[0090] Figure 6This is a schematic diagram of the overall framework for intrusion data discrimination provided in a specific embodiment of the present invention. For example... Figure 6 As shown, the vehicle-side data acquisition layer collects multi-source data, including network traffic data, vehicle status data, and ECU behavior data. The edge computing layer extracts operational data features and standardizes these features. The cloud-based analysis layer uses user-related data to identify intrusion data; this process can also be performed on the vehicle side. The three-level discrimination mechanism includes anomaly data filtering as described above, determining confidence levels based on contextual information, and verification using the first vehicle's operational data from multiple similar vehicles. A feedback optimization layer can also be used for feedback learning and optimization to determine the model optimization parameters for updating the discrimination model.
[0091] Figure 7 This is a structural diagram of an intrusion data discrimination device provided in one or more embodiments of the present invention.
[0092] like Figure 7 The intrusion data discrimination device shown includes: a feature extraction module, a confidence level determination module, and an intrusion determination module;
[0093] The feature extraction module is used to extract multi-dimensional operation data features from the first vehicle operation data of the target vehicle through a preset discrimination model, and construct an operation data feature matrix.
[0094] The confidence determination module is used to determine the confidence level of the feature matrix of the operating data based on the context information during vehicle operation.
[0095] The intrusion detection module is used to determine the intrusion data detection result by judging the characteristics of multiple second vehicles of the same type as the target vehicle and combining the confidence level.
[0096] The feature extraction module is used to extract corresponding operation data features from the first vehicle operation data based on multiple preset feature dimensions; to standardize the operation data features according to data timestamp, data source identifier, data type and data content; and to adjust the dynamic operation data features in the standardized operation data features according to a preset feature selection mechanism to construct an operation data feature matrix.
[0097] The confidence level determination module is used to perform feature filtering on the feature matrix of the running data, identify abnormal data features, and determine the initial confidence level of the abnormal data features; determine the vehicle running status in the first vehicle running data, and associate the abnormal data features with the context information and the vehicle running status to determine the correlation between the abnormal data features; dynamically adjust the initial confidence level according to the correlation level to determine the confidence level of the abnormal data features.
[0098] The intrusion detection module is used to compare and analyze abnormal data features based on the second vehicle operation data; in response to the second vehicle operation data having the same operation data features as the abnormal data features, the abnormal data features are determined to be intrusion data features; based on the confidence level, the intrusion data features are judged, and the intrusion data judgment result is determined.
[0099] The intrusion detection module is used to issue a data intrusion warning in response to the intrusion data detection result indicating the presence of intrusion data.
[0100] The intrusion detection module is also used to detect the performance of the discrimination model; in response to the performance being lower than a preset performance threshold, it obtains the model optimization parameters; optimizes the discrimination model according to the model optimization parameters, and makes discrimination on vehicle operation data based on the optimized discrimination model.
[0101] Figure 8 This is a block diagram of an electronic device structure for an intrusion data discrimination method provided in one or more embodiments of the present invention.
[0102] like Figure 8 As shown, this application provides an electronic device, including: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;
[0103] The memory stores a computer program that, when executed by a processor, causes the processor to perform steps of an intrusion data detection method.
[0104] This application also provides a computer-readable storage medium storing a computer program executable by an electronic device, which, when run on the electronic device, causes the electronic device to perform the steps of an intrusion data identification method.
[0105] This application also provides a vehicle, including:
[0106] Electronic equipment used to implement steps based on intrusion data discrimination methods;
[0107] The processor runs a program, and when the program runs, it executes the steps of the intrusion data identification method based on the data output from the electronic device.
[0108] Storage medium used to store programs that, when running, execute intrusion data detection methods on data output from electronic devices.
[0109] The communication bus mentioned in the above electronic devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.
[0110] The electronic device comprises a hardware layer, an operating system layer running on top of the hardware layer, and an application layer running on the operating system. The hardware layer includes hardware such as a central processing unit (CPU), a memory management unit (MMU), and memory. The operating system can be any one or more computer operating systems that control the electronic device through processes, such as Linux, Unix, Android, iOS, or Windows. Furthermore, in this embodiment of the invention, the electronic device can be a smartphone, tablet computer, or other handheld device, or a desktop computer, portable computer, or other electronic device; there is no particular limitation in this embodiment.
[0111] In this embodiment of the invention, the executing entity for electronic device control can be an electronic device itself, or a functional module within an electronic device capable of calling and executing a program. The electronic device can obtain the firmware corresponding to the storage medium. This firmware is provided by the supplier, and different storage media may have the same or different firmware; no limitation is made here. After obtaining the firmware corresponding to the storage medium, the electronic device can write this firmware into the storage medium; specifically, it burns the firmware corresponding to the storage medium into the storage medium. The process of burning the firmware into the storage medium can be implemented using existing technology, and will not be elaborated upon in this embodiment of the invention.
[0112] Electronic devices can also obtain reset commands corresponding to the storage media. The reset commands corresponding to the storage media are provided by the supplier. The reset commands corresponding to different storage media can be the same or different, and no restrictions are imposed here.
[0113] At this time, the storage medium of the electronic device is a storage medium on which the corresponding firmware has been written. The electronic device can respond to the reset command corresponding to the storage medium on which the corresponding firmware has been written, thereby resetting the storage medium on which the corresponding firmware has been written according to the reset command. The process of resetting the storage medium according to the reset command can be implemented by existing technology and will not be described in detail in this embodiment of the invention.
[0114] For ease of description, the above devices are described separately by function as various units and modules. Of course, in implementing this application, the functions of each unit and module can be implemented in one or more software and / or hardware.
[0115] It will be understood by those skilled in the art that, unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. It should also be understood that terms such as those defined in general dictionaries should be understood to have the same meaning as in the context of the prior art and should not be interpreted in an idealized or overly formal sense unless specifically defined.
[0116] For the sake of simplicity, the method embodiments are described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.
[0117] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this application.
[0118] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. An intrusion data discrimination method characterized by comprising: The intrusion data discrimination method comprises: Through a preset discrimination model, multi-dimensional operation data features are extracted from first vehicle operation data of a vehicle, and an operation data feature matrix is constructed; Based on context information in a vehicle operation process, a confidence of the operation data feature matrix is determined; According to second vehicle operation data of multiple vehicles of the same type, the operation data features are discriminated in combination with the confidence, and an intrusion data discrimination result is determined.
2. The intrusion data discrimination method according to claim 1, characterized by, The method comprises: According to a plurality of preset feature dimensions, corresponding operation data features are extracted from the first vehicle operation data; According to data timestamps, data source identifiers, data types, and data contents, the operation data features are standardized processed; According to a preset feature selection mechanism, dynamic operation data features in the standardized processed operation data features are adjusted, and an operation data feature matrix is constructed.
3. The intrusion data discrimination method of claim 1, wherein The method comprises: The operation data feature matrix is subjected to feature screening, abnormal data features are determined, and initial confidences of the abnormal data features are determined; A vehicle operation state is determined in the first vehicle operation data, and the abnormal data features are associated according to the context information and the vehicle operation state, and an association degree between the abnormal data features is determined; The initial confidences are dynamically adjusted according to the association degree, and confidences of the abnormal data features are determined.
4. The intrusion data discrimination method according to claim 3, characterized by, The method comprises: The second vehicle operation data is compared with the abnormal data features; In response to the second vehicle operation data having the same operation data features as the abnormal data features, the abnormal data features are determined as intrusion data features; The intrusion data features are discriminated according to the confidences, and an intrusion data discrimination result is determined.
5. The intrusion data discrimination method of claim 4, wherein, After the intrusion data discrimination result is determined, the method further comprises: In response to the intrusion data discrimination result having intrusion data, a data intrusion warning is performed.
6. The intrusion data discrimination method of claim 1, wherein The method further comprises: The performance of the discrimination model is detected; In response to the performance being lower than a preset performance threshold, model optimization parameters are obtained; The discrimination model is optimized according to the model optimization parameters, and vehicle operation data is discriminated based on the optimized discrimination model.
7. An intrusion data discrimination apparatus characterized by comprising: The intrusion data detection device comprises: A feature extraction module is configured to extract multi-dimensional operation data features from first vehicle operation data of a target vehicle through a preset discrimination model, and construct an operation data feature matrix; A confidence determination module is configured to determine a confidence of the operation data feature matrix based on context information in a vehicle operation process; and An intrusion determination module is configured to determine an intrusion data determination result by determining the operation data features according to a plurality of second vehicle operation data of vehicles of the same type as the target vehicle and in combination with the confidence.
8. An electronic device, comprising: The method comprises: A processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory are in communication with each other through the communication bus; The memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the intrusion data determination method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The memory stores a computer program executable by the electronic device, and when the computer program runs on the electronic device, the electronic device executes the steps of the intrusion data determination method according to any one of claims 1 to 6.
10. A vehicle characterized by comprising: The method comprises: An electronic device is configured to execute the steps of the intrusion data determination method according to any one of claims 1 to 6; A processor is configured to execute the steps of the intrusion data determination method according to any one of claims 1 to 6 when a program runs on the processor and data output from the electronic device; A storage medium is configured to store a program, and the program is configured to execute the steps of the intrusion data determination method according to any one of claims 1 to 6 when the program runs on the storage medium and data output from the electronic device.