Vehicle privacy protection system and method with linkage of vehicle window dimming and sound field

By linking the environmental perception and occupant status recognition modules with the privacy decision engine, the electrochromic windows and directional acoustic speakers are automatically adjusted, solving the problems of single protection and manual dependence in existing vehicle privacy protection systems, and realizing coordinated protection and intelligent control of vision and hearing.

CN121893883APending Publication Date: 2026-04-21BEI DOU ZHI LIAN KE JI YOU XIAN GONG SI
View PDF 0 Cites 1 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEI DOU ZHI LIAN KE JI YOU XIAN GONG SI
Filing Date
2025-12-10
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing vehicle privacy protection systems cannot achieve coordinated protection of vision and hearing, rely on manual operation and lack occupant status awareness, resulting in delayed response or false triggering, and cannot meet diverse and high-level privacy protection needs.

Method used

By employing the coordinated operation of an environmental perception module, an occupant status recognition module, a privacy decision engine, and an actuator group, the vehicle acquires information on its location, environment, and occupant status through components such as GPS, cameras, and microphone arrays. This automatically adjusts the electrochromic windows and directional acoustic speakers to achieve a dual privacy barrier of both sight and sound.

Benefits of technology

It achieves automated and precise privacy protection in various scenarios, enhances the vehicle's privacy protection capabilities, balances visibility and lighting, improves user experience and security, and reduces power consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121893883A_ABST
    Figure CN121893883A_ABST
Patent Text Reader

Abstract

The invention provides a vehicle window dimming and sound field linkage vehicle privacy protection system and method.The system comprises environment perception, passenger state recognition, a privacy decision engine, an actuator set and a user interaction interface, and the perception data output end of an environment perception and passenger state recognition module is connected to the input end of the privacy decision engine; the control instruction output end of the privacy decision engine is connected with the actuator group, and the user interaction interface is in two-way communication with the privacy decision engine; the environment sensing module obtains the position and the external environment of a vehicle, the passenger state recognition module monitors the state of persons and audio in the vehicle, and the privacy decision engine outputs an instruction according to the state and drives the actuator set to achieve vehicle window partition dimming, directional acoustic masking and in-vehicle volume adjustment. The problems that a traditional vehicle privacy protection system operates independently, depends on manual operation and is incomplete in protection can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle intelligent privacy protection technology, and in particular to a vehicle privacy protection system and method that links window dimming with sound field. Background Technology

[0002] With the continuous improvement of automotive intelligence and comfort, vehicle privacy protection has gradually become one of the core needs of drivers and passengers. Currently, vehicle privacy protection technologies in the industry are mainly divided into two major directions: physical electronic masking and sound privacy protection. In the field of physical electronic masking, traditional vehicles mostly use manual sunshades or dark privacy films to achieve privacy protection. However, these solutions cannot dynamically adjust the light transmittance, which seriously affects the interior lighting and driving visibility while ensuring privacy. Some high-end models are equipped with electrochromic glass, which can control the light transmittance of the windows through physical buttons. However, its adjustment logic is relatively fixed, only supporting unified dimming of the whole vehicle or manual zone dimming, and cannot automatically trigger adjustment based on information such as the vehicle's environment and the status of the occupants. In the field of sound privacy protection, most models are equipped with active noise cancellation systems that only suppress external interference such as road noise and tire noise, and do not have the ability to directionally block the leakage of in-vehicle voices. A few research solutions attempt to use ultrasonic directional speakers to build a sound barrier outside the vehicle, but this technology does not establish linkage with contextual information such as window dimming status, occupant identity, and vehicle geographical location, and can only achieve sound protection in a single scenario, with strong application limitations.

[0003] While existing technologies have made initial progress in vehicle privacy protection, they still suffer from numerous undeniable shortcomings, failing to meet diverse and high-level privacy protection needs. On one hand, current dimming and acoustic protection systems operate independently, making it difficult to collaboratively construct a dual privacy barrier encompassing both visual and auditory senses. This often results in situations where only the view is blocked, but conversations inside the vehicle are easily eavesdropped on, or where sound is blocked but the windows remain transparent. This makes them unsuitable for high-privacy scenarios such as business meetings or the storage of valuables. On the other hand, existing solutions generally rely on manual user intervention, leading to response delays, accidental triggering, and a lack of occupant awareness. They cannot identify situations such as children alone in the vehicle or video calls, resulting in a one-size-fits-all approach to privacy protection, which degrades the driving experience and fails to guarantee the safety of children and other vulnerable groups. Therefore, developing a dynamic privacy protection system that integrates multi-dimensional perception and enables multi-modal actuator linkage has become an urgent need for the development of intelligent cockpit technology. Summary of the Invention

[0004] In view of this, the embodiments of this application provide a vehicle privacy protection system and method that links window dimming with sound field, which can solve the problems of traditional vehicle privacy protection systems operating independently, relying on manual operation, and having incomplete protection.

[0005] The technical solution of this application embodiment is implemented as follows: In a first aspect, embodiments of this application provide a vehicle privacy protection system that links window dimming with sound field, including: An environmental perception module, comprising a GPS positioning unit, a high-precision map interface, and front / side cameras, is used to acquire the vehicle's real-time geographical location, identify privacy-sensitive areas, and capture images of the vehicle's external environment. The occupant status recognition module includes a DMS camera, an in-cabin infrared camera, and a microphone array, which are used to monitor the driver's status, identify the number and attributes of rear-seat occupants, and detect in-vehicle voice activity. The privacy decision engine, deployed in the vehicle domain controller, is used to execute privacy protection decision logic and output control commands; The actuator assembly, which includes electrochromic windows, directional acoustic speakers, and a vehicle audio system, is used to adjust the light transmittance of the windows, mask the acoustics outside the vehicle, and adjust the volume inside the vehicle. The user interaction interface, including the central control screen and voice assistant, is used to enable users to interact with the system by giving commands and feedback on their status. The perception data output terminals of the environmental perception module and the occupant status recognition module are both connected to the perception data input terminal of the privacy decision engine. The control command output terminal of the privacy decision engine is connected to the control command input terminal of the actuator group. The user interaction interface is bidirectionally connected to the privacy decision engine, which can transmit user commands to the privacy decision engine and receive system status information fed back by the privacy decision engine.

[0006] Secondly, embodiments of this application also provide a vehicle privacy protection method that links window dimming with sound field, comprising the following steps: The vehicle's location is obtained through GPS positioning unit and high-precision map interface. It is determined whether the vehicle has entered the preset privacy-sensitive area. If so, the next step is carried out directly; otherwise, the step is executed repeatedly. The number, location, and activity status of occupants are identified through in-cabin cameras and AI models. The microphone array is used to detect whether there are voice calls or sensitive audio playback inside the vehicle. The privacy decision engine determines whether to activate privacy mode by comprehensively considering vehicle status, regional attributes, and in-vehicle triggering conditions. Control the corresponding zone's electrochromic window dimming, activate the directional acoustic speakers, and adjust the in-vehicle audio volume; When the vehicle leaves the sensitive area or the user manually turns off privacy mode, all actuators are restored to their default state.

[0007] Thirdly, embodiments of this application also provide an electronic device, including: a processor, a storage medium, and a bus, wherein the storage medium stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor communicates with the storage medium via the bus, and the processor executes the machine-readable instructions to perform the vehicle privacy protection method of window dimming and sound field linkage as described in any of the first aspects.

[0008] Fourthly, embodiments of this application also provide a computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, performs the vehicle privacy protection method of window dimming and sound field linkage as described in any one of the first aspects.

[0009] The embodiments of this application have the following beneficial effects: By integrating geographical location and external scene data from the environmental perception module, occupant status recognition module data on in-vehicle occupants and audio activity, and vehicle driving status data, a multi-source contextual perception system is constructed. This system can automatically activate privacy protection mode when privacy-sensitive areas such as schools and hospitals are in a stationary or low-speed state, when a child is alone in the vehicle, or when there are privacy-triggered conditions such as voice calls. This completely solves the problem of delayed response or false triggering caused by manual operation in traditional technologies. Simultaneously, the system innovatively achieves the linkage control of electrochromic window dimming and directional acoustic speaker sound wave masking, creating a dual privacy barrier of vision and hearing. This effectively compensates for the shortcomings of existing technologies that only protect vision or sound and lack complete privacy protection, fully meeting the high privacy requirements of scenarios such as business meetings and storage of valuables. Furthermore, the system... The system employs a zoned privacy enforcement strategy, performing privacy operations only on windows facing public areas and corresponding side speakers, while non-risk sides remain in normal mode. This achieves a balance between privacy protection and in-vehicle lighting and visibility, avoiding the drawbacks of traditional one-size-fits-all adjustments. For special scenarios where only children are in the car, the system can automatically upgrade the privacy level and remotely notify the owner, significantly improving the safety of family users. Furthermore, the system's core hardware, electrochromic glass, only consumes power when switching states, and the directional speakers have a power consumption of less than 5W, offering advantages of low power consumption and high reliability without placing an additional burden on the vehicle's electrical system. Combined with a two-way human-machine interface of the central control screen and voice assistant, it balances intelligent system control with ease of operation, comprehensively improving the overall performance of vehicle privacy protection and the user experience. Attached Figure Description

[0010] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0011] Figure 1 This is a system architecture diagram provided in the embodiments of this application; Figure 2 This is a flowchart illustrating steps S101-S106 provided in the embodiments of this application. Detailed Implementation

[0012] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the accompanying drawings in this application are for illustrative and descriptive purposes only and are not intended to limit the scope of protection of this application. Furthermore, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate operations implemented according to some embodiments of this application. It should be understood that the operations in the flowcharts may not be implemented in sequence, and steps without logical contextual relationships may be reversed or implemented simultaneously. In addition, those skilled in the art, guided by the content of this application, may add one or more other operations to the flowcharts, or remove one or more operations from the flowcharts.

[0013] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0014] Furthermore, the described embodiments are merely some, not all, of the embodiments of this application. The components of the embodiments of this application described and illustrated herein can typically be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0015] In the following description, the terms "first, second, third" are used merely to distinguish similar objects and do not represent a specific ordering of objects. It is understood that "first, second, third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0016] It should be noted that the term "comprising" will be used in the embodiments of this application to indicate the presence of the features declared thereafter, but does not exclude the addition of other features.

[0017] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application and is not intended to limit the scope of this application.

[0018] See Figure 1 , Figure 1 This is a system architecture diagram provided in the embodiments of this application, such as... Figure 1 As shown, the vehicle privacy protection system that links window dimming with sound field includes: An environmental perception module, comprising a GPS positioning unit, a high-precision map interface, and front / side cameras, is used to acquire the vehicle's real-time geographical location, identify privacy-sensitive areas, and capture images of the vehicle's external environment. The occupant status recognition module includes a DMS camera, an in-cabin infrared camera, and a microphone array, which are used to monitor the driver's status, identify the number and attributes of rear-seat occupants, and detect in-vehicle voice activity. The privacy decision engine, deployed in the vehicle domain controller, is used to execute privacy protection decision logic and output control commands; The actuator assembly, which includes electrochromic windows, directional acoustic speakers, and a vehicle audio system, is used to adjust the light transmittance of the windows, mask the acoustics outside the vehicle, and adjust the volume inside the vehicle. The user interaction interface, including the central control screen and voice assistant, is used to enable users to interact with the system by giving commands and feedback on their status. The perception data output terminals of the environmental perception module and the occupant status recognition module are both connected to the perception data input terminal of the privacy decision engine. The control command output terminal of the privacy decision engine is connected to the control command input terminal of the actuator group. The user interaction interface is bidirectionally connected to the privacy decision engine, which can transmit user commands to the privacy decision engine and receive system status information fed back by the privacy decision engine.

[0019] This application embodiment comprises five core modules, the functions and compositions of which are as follows: The environmental perception module, as the external information acquisition layer of the system, integrates a GPS positioning unit, a high-precision map interface, and a front-side camera, respectively undertaking the functions of vehicle location acquisition, sensitive area identification, and external environment image capture; The occupant status recognition module, as the in-vehicle information perception layer, is equipped with a DMS camera, an in-cabin infrared camera, and a microphone array, used to realize driver status monitoring, rear-seat occupant feature recognition, and in-vehicle voice activity detection; The privacy decision engine is the core control center of the system, deployed in the vehicle domain controller, responsible for integrating various perception data and outputting precise control commands; The actuator group is the functional execution layer of the system, including electrochromic windows, directional acoustic speakers, and an in-vehicle audio system, used to implement specific privacy protection actions; The user interaction interface is the core carrier of human-computer interaction, consisting of a central control screen and a voice assistant, responsible for realizing user command transmission and system status feedback.

[0020] The specific connections between the modules are as follows: the perception data output terminals of both the environmental perception module and the occupant status recognition module establish a unidirectional data transmission link with the perception data input terminal of the privacy decision engine, ensuring that both types of perception data can be transmitted to the decision center in real time and stably; the control command output terminal of the privacy decision engine establishes a unidirectional command transmission link with the control command input terminal of the actuator group, ensuring that control commands can be accurately issued to each execution component; the user interaction interface establishes a bidirectional communication link with the privacy decision engine, which can both transmit the user's manual operation or voice command to the privacy decision engine and receive system operation status information fed back by the privacy decision engine, thus forming a complete information interaction closed loop. This connection architecture enables the technical effects of centralized processing of perception data, accurate issuance of control commands, and timely response of human-computer interaction, providing stable hardware and link support for the implementation of subsequent privacy protection strategies.

[0021] In some embodiments, the electrochromic window is made of WO3-based thin film material, and the electrochromic window is divided into four independent control zones: left front, right front, left rear, and right rear, for the purpose of achieving zoned dimming; the directional acoustic speaker adopts ultrasonic carrier modulation technology with a beam angle of <30°, and the directional acoustic speaker is installed on the outside of the A / B pillars of the vehicle for directional emission of masking sound waves out of the vehicle.

[0022] Here, for the electrochromic windows, WO3-based film is used as the core dimming material. This material has the technical advantages of low driving voltage and fast response. The driving voltage of ±1.5V can be adapted to the vehicle's low-voltage electrical system without causing additional load on the vehicle's power supply network. At the same time, the response time of less than 30 seconds enables the rapid triggering and deactivation of privacy mode, avoiding privacy leaks due to dimming delays. To achieve precise zoned protection, the electrochromic windows are divided into four independent control zones: left front, right front, left rear, and right rear. Each zone can independently receive dimming commands and adjust its light transmittance, enabling localized window dimming based on actual privacy needs, avoiding the waste of vision caused by uniform dimming throughout the vehicle.

[0023] For directional acoustic speakers, ultrasonic carrier modulation technology is employed. This technology enables directional propagation of sound waves, controlling the sound beam angle to within a range of less than 30 degrees. This ensures that the masking sound waves concentrate on covering a specific area outside the car window, preventing indiscriminate sound wave diffusion and unnecessary interference to the surrounding environment. Furthermore, installing the directional acoustic speakers on the outer sides of the vehicle's A-pillars and B-pillars allows the sound wave emission direction to precisely correspond to the outer area of ​​the car window, maximizing the effectiveness of external voice masking and ensuring that internal voice communication does not leak out of the vehicle.

[0024] In some embodiments, the GPS positioning unit of the environmental perception module is used to output the real-time latitude and longitude coordinates of the vehicle, the high-precision map interface is used to output the boundary information of privacy-sensitive areas, and the front / side camera is used to output the external environment image data of the vehicle. The output ends of the three are all integrated with the environmental data receiving port of the privacy decision engine.

[0025] Here, the GPS positioning unit within the environmental perception module can accurately collect and output the vehicle's real-time latitude and longitude coordinates, providing basic data support for the initial judgment of the vehicle's location; the high-precision map interface can retrieve preset geographic information data and output boundary information of privacy-sensitive areas such as schools, hospitals, and residential areas, providing a basis for judging the attributes of the area where the vehicle is located; the front side camera can capture environmental image data in front of and to the side of the vehicle in real time, which can help verify whether the vehicle has actually entered a sensitive area, making up for the limitations of relying solely on positioning data for judgment.

[0026] To improve data processing efficiency, the data output ends of the three components are integrated into the same environmental data receiving port of the privacy decision engine. This integrated access method can reduce the number of data transmission links, reduce the risk of data loss during transmission, and enable the privacy decision engine to complete the aggregation and analysis of various environmental data on the same port, thereby improving the overall response speed of environmental perception and ensuring that the system can identify the external environmental status of the vehicle in a timely manner.

[0027] In some embodiments, the DMS camera output, cabin infrared camera output, and microphone array output of the occupant status recognition module are all connected to the occupant status data receiving port of the privacy decision engine. The DMS camera is used to transmit driver status data, the cabin infrared camera is used to transmit the number, location, and attribute data of rear occupants, and the microphone array is used to transmit in-vehicle voice activity data.

[0028] Here, the DMS camera in the occupant status recognition module can monitor the driver's facial features and body movements in real time, and output data on whether the driver is on a call, fatigued, etc.; the in-cabin infrared camera has the ability to penetrate light obstruction and can accurately identify the number of rear passengers, their specific seating positions, and passenger attributes, such as distinguishing between children and adults; the microphone array can collect audio signals in the vehicle and analyze audio characteristics to determine whether there are voice calls, sensitive audio playback, or other activities in the vehicle, supplementing the status information of the in-vehicle audio dimension.

[0029] By unifying the data outputs of these three entities and connecting them to the occupant status data receiving port of the privacy decision engine, the privacy decision engine can simultaneously acquire three types of data: occupant behavior status, location distribution, and audio activity. Through cross-validation of multi-dimensional data, the accuracy of occupant status identification can be effectively improved, avoiding misjudgments caused by a single data source, and providing a comprehensive and reliable basis for the formulation of subsequent privacy decisions.

[0030] In some embodiments, the activation conditions for the privacy protection decision logic of the privacy decision engine are: the vehicle is stationary or at low speed, the vehicle is located within a privacy-sensitive area, and a privacy protection trigger condition exists in the vehicle. The privacy protection trigger condition includes at least one of the following: identifying a child, detecting a voice call, and the user marking valuable items. Furthermore, the control command output terminal of the privacy decision engine is connected to the dimming command receiving terminal of the electrochromic window, the start command receiving terminal of the directional acoustic speaker, and the volume adjustment command receiving terminal of the in-vehicle audio system, respectively.

[0031] Here, the privacy decision engine sets up three activation conditions for privacy mode. The system will only activate the privacy protection strategy when all three conditions are met simultaneously. The first condition is that the vehicle is stationary or traveling at low speed, specifically less than 5 kilometers per hour. This condition ensures that privacy mode is only triggered in low-risk scenarios where the vehicle is not traveling at high speed, avoiding the driver's visibility being affected by window dimming. The second condition is that the vehicle is located within a privacy-sensitive area. This condition is a prerequisite for privacy protection and enables targeted protection within sensitive areas. The third condition is that there are privacy protection trigger conditions within the vehicle, including various scenarios such as recognizing children, detecting voice calls, and users marking valuable items. This allows for personalized adaptation of the privacy strategy, covering different high-privacy scenarios. The setting of these three conditions effectively avoids the accidental triggering of privacy mode and improves the rationality of system operation.

[0032] Meanwhile, the control command output of the privacy decision engine establishes a one-to-one independent command transmission link with the dimming command receiver of the electrochromic window, the start command receiver of the directional acoustic speaker, and the volume adjustment command receiver of the in-vehicle audio system. This link design enables precise and independent control of each actuator, ensuring that the action of each actuator strictly matches the policy requirements of the privacy decision engine, and guaranteeing the accurate implementation of privacy protection functions.

[0033] In some embodiments, the central control screen and voice assistant of the user interaction interface communicate bidirectionally with the privacy decision engine. The manual setting command output terminal of the central control screen and the voice command output terminal of the voice assistant are both connected to the user command receiving port of the privacy decision engine. The system status feedback output terminal of the privacy decision engine is connected to the status display receiving port of the central control screen and the voice prompt receiving port of the voice assistant.

[0034] Here, both the central control screen and the voice assistant in the user interaction interface establish a two-way communication link with the privacy decision engine. The manual setting command output terminal of the central control screen and the voice command output terminal of the voice assistant are connected to the same user command receiving port of the privacy decision engine. This design can realize the unified reception and processing of different types of user commands, and support users to complete the autonomous control of privacy mode through touch operation or voice interaction, thereby improving the convenience of operation.

[0035] The privacy decision engine's system status feedback output is synchronously connected to the status display receiving port of the central control screen and the voice prompt receiving port of the voice assistant. It can provide users with information such as the start / stop status of privacy mode and the working status of each actuator through both the visual interface of the central control screen and the voice assistant's broadcast. This satisfies the needs of users who prefer visual viewing and also adapts to user scenarios where manual operation is inconvenient, further improving the overall user experience.

[0036] In some embodiments, the occupant status recognition module is further configured with an AI status classification model, which is based on the MobileNetV3 architecture and is used to classify and recognize the activity status of occupants. The activity status includes children being alone in the back seat and drivers making video calls. The recognition result output of the AI ​​status classification model is connected to the occupant behavior data receiving port of the privacy decision engine.

[0037] Here, an AI state classification model based on the MobileNetV3 architecture is configured in the occupant state recognition module. This architecture was chosen because it is a lightweight neural network, which can be adapted to the limited computing resources of the vehicle domain controller, achieving accurate classification of occupant activity states without consuming too much system memory. This AI model can perform deep learning analysis on image data collected by the DMS camera and the in-cabin infrared camera, and can accurately identify typical occupant states with high privacy requirements, such as children alone in the back seat or drivers making video calls.

[0038] By connecting the output of the AI ​​state classification model to the occupant behavior data receiving port of the privacy decision engine, the occupant behavior data identified by the model can be transformed into the core trigger basis for the privacy decision engine to formulate strategies. This enables the system to automatically adjust the privacy protection level according to the real-time activity status of the occupants, avoiding the one-size-fits-all protection mode in traditional technologies and improving the targeting and intelligence of privacy protection.

[0039] In some embodiments, the privacy decision engine is deployed in an in-vehicle Linux or RTOS system, and the output terminals of its built-in rule engine and lightweight neural network are both connected to the integrated judgment module of the privacy decision engine. The integrated judgment module outputs control commands to the actuator group in a unified manner. The light transmittance of the electrochromic window of the actuator group can be reduced to below a certain value, and the directional acoustic speaker emits anti-phase white noise to form an external acoustic masking zone.

[0040] Here, the privacy decision engine is deployed on an in-vehicle Linux or RTOS system. These two types of systems were chosen because they have the technical characteristics of high stability and strong real-time performance, which can adapt to the complex operating conditions of the in-vehicle environment and avoid the problem of untimely execution of privacy policies due to system lag or delay.

[0041] The privacy decision engine incorporates two sets of decision logic: a rule engine and a lightweight neural network. The rule engine enables rapid matching of basic privacy policies, while the lightweight neural network can accurately classify complex occupant states. The results of both operations are fed into a comprehensive judgment module, which integrates multi-dimensional data and outputs unified control commands to the actuator group. This architecture enables rapid response to basic policies and accurate judgment in complex scenarios, improving the comprehensiveness and accuracy of privacy decisions.

[0042] In terms of actuator parameters, the light transmittance of the electrochromic window can be reduced to below 20%. This parameter can ensure the basic lighting needs inside the vehicle while completely blocking the view of people outside the vehicle. The directional acoustic speaker can emit inverse white noise, which can form a stable acoustic masking zone outside the window, effectively reducing the probability of voice leakage from inside the vehicle and realizing the coordinated implementation of visual and auditory privacy protection.

[0043] Please see Figure 2 , Figure 2 This is a flowchart illustrating steps S101-S106 provided in the embodiments of this application. The vehicle privacy protection method that links window dimming with sound field provided in the embodiments of this application can be implemented through steps S101-S106, and will be explained in conjunction with each step.

[0044] In step S101, the vehicle location is obtained through the GPS positioning unit and the high-precision map interface. It is determined whether the vehicle has entered the preset privacy-sensitive area. If so, proceed to the next step; otherwise, repeat the step. This stage is the preliminary scenario determination step before the privacy protection strategy is activated. Its specific implementation relies on the collaborative work of various components within the environmental perception module. The system first collects the vehicle's real-time latitude and longitude coordinates at a frequency of 1Hz via the GPS positioning unit. This coordinate data is transmitted to the privacy decision engine in real time. Simultaneously, the high-precision map interface sends preset privacy-sensitive area boundary information to the privacy decision engine, including the geographical range of areas such as schools, hospitals, and residential areas. The system pre-sets the trigger threshold for sensitive areas to be within a 50-meter radius of the target area. The front-side cameras capture real-time environmental images in front of and to the sides of the vehicle. When the GPS positioning data shows that the vehicle has entered within 50 meters of the sensitive area, the privacy decision engine retrieves the image data from the front-side cameras for auxiliary verification. This verifies that the vehicle is indeed in a densely populated public sensitive scene rather than simply a coordinate shift. If the verification is successful, the next step is initiated. If the vehicle has not entered a sensitive area or the image verification fails, the environmental perception module will continuously perform data collection and judgment operations in a loop with a cycle of 2 seconds to ensure that no potential privacy protection scenarios are missed.

[0045] In step S102, the number, location, and activity status of occupants are identified using in-cabin cameras and AI models; This stage is the core evidence acquisition phase for personalized adaptation of privacy policies, relying on multi-device collaboration and AI model analysis of the occupant status recognition module. The in-cabin DMS camera captures images of the driver's face and upper body at a frequency of 30 frames per second, monitoring the driver's body movements and facial posture; the in-cabin infrared camera captures full-coverage images of the rear area, its infrared imaging characteristics can penetrate obstructions such as interior sunshades, accurately identifying the number and specific seating positions of rear occupants; the image data from both types of cameras are simultaneously transmitted to an AI status classification model based on the MobileNetV3 architecture. This model extracts and analyzes image features, distinguishing occupant attributes, such as determining whether someone is a child based on facial features and height data, and identifying occupant activity status, such as determining whether a driver is making a video call based on the posture of holding a mobile phone and the direction of their face, and determining whether a child in the rear seat is unaccompanied by an adult based on their posture when alone. Finally, the AI ​​model transmits the integrated data on the number, location, attributes, and activity status of occupants to the privacy decision engine, providing core evidence for subsequent decisions regarding the occupant dimension.

[0046] In step S103, the presence of voice calls or sensitive audio playback inside the vehicle is detected by a microphone array; This stage involves collecting supplementary conditions for privacy policy triggering, relying on audio acquisition and feature analysis using a microphone array. The in-vehicle microphone array collects audio signals across the entire vehicle at a sampling rate of 44.1kHz. By locating the audio source through the phase difference of signals from multiple microphones, it extracts features from the audio signals to identify the characteristic frequency bands of voice calls and whether they contain preset sensitive audio keywords. If a voice call lasting more than 3 seconds is detected in the vehicle, or if sensitive audio containing trade secrets or personal privacy information is played, the microphone array transmits the audio activity data and judgment results to the privacy decision engine, supplementing the privacy triggering conditions at the audio level and making the triggering basis of the privacy policy more comprehensive and accurate.

[0047] In step S104, the privacy decision engine determines whether to activate the privacy mode by comprehensively considering the vehicle status, regional attributes, and in-vehicle triggering conditions. This stage is the core decision-making step of the privacy protection strategy, relying on the multi-dimensional data integration and logical operations of the privacy decision engine. The privacy decision engine simultaneously receives environmental status data, occupant status data, audio activity data, and vehicle speed data transmitted via the vehicle's CAN bus, and then performs a comprehensive judgment based on three conditions. The first condition is the vehicle's driving status; only when the vehicle speed is below 5 km / h or the vehicle is stationary can the basic conditions for activating privacy mode be met, avoiding the impact of dimming on driving visibility at high speeds. The second condition is the vehicle's location, confirming that the vehicle is within a preset sensitive area of ​​50 meters. The third condition is the in-vehicle triggering conditions, confirming at least one high-privacy requirement scenario, such as recognizing a child, detecting a voice call, or the user pre-marking valuable items. Only when all three conditions are met simultaneously will the privacy decision engine determine to activate privacy protection mode and proceed to subsequent steps. If any condition is not met, it returns to the first step to continue looping monitoring, or maintains the current non-privacy protection state. If privacy mode has already been activated, a recovery command will be triggered to ensure that privacy mode is only activated in necessary scenarios.

[0048] In step S105, the corresponding zone electrochromic window dimming is controlled, the directional acoustic speaker is activated, and the in-vehicle audio volume is adjusted; This stage is the concrete implementation of privacy protection functions, which is achieved through the issuance of instructions from the privacy decision engine and the precise actions of the executor group. The privacy decision engine first combines image data from the front-facing cameras to determine which side of the vehicle's windows faces a sidewalk, plaza, or other public area. It then sends a dimming command to the corresponding electrochromic window, reducing its light transmittance to below a specific value (20%). The window on the non-public area side maintains its original light transmittance, balancing privacy protection with the driver's field of vision. Simultaneously, the privacy decision engine sends an activation command to the directional acoustic speakers on the public area side, controlling them to emit inverse white noise to create an acoustic masking zone outside the window. The masking zone's coverage area can precisely match the area within 1 meter outside the window, effectively reducing the probability of in-car voice leakage. Furthermore, the privacy decision engine sends a volume adjustment command to the in-car audio system, automatically lowering the in-car entertainment volume to below 50% of its original level, preventing excessively high in-car volume from indirectly causing privacy leaks. While performing these actions, the privacy decision engine simultaneously sends a prompt command to the user interface, informing the user that privacy mode has been activated through a visual pop-up on the central control screen and a voice announcement from the voice assistant.

[0049] In step S106, when the vehicle leaves the sensitive area or the user manually turns off the privacy mode, all actuators are restored to their default state.

[0050] This stage is the final closed-loop stage of the privacy protection process, achieved through continuous system monitoring and command retrieval. The privacy decision engine continuously monitors the deactivation conditions once per second. The first type of deactivation condition is when the vehicle leaves the sensitive area. When GPS positioning data shows that the vehicle has left the sensitive area by more than 50 meters and the front-facing camera image verifies that there are no public or densely populated areas nearby, the area-based deactivation condition is determined to be met. The second type of deactivation condition is when the user intervenes manually. When the user issues a command to turn off the privacy mode via a manual button on the central control screen or a voice command from the voice assistant, the manual deactivation condition is determined to be met. Once either deactivation condition is met, the privacy decision engine immediately issues a recovery command to the actuator group, controlling the electrochromic windows to return to the default light transmittance, the directional acoustic speakers to stop emitting masking sound waves, and the in-vehicle audio system to return to its original volume. At the same time, it notifies the user through the user interface that the privacy mode has been deactivated, thus completing the closed-loop control of the entire privacy protection process. In some embodiments, the method further includes: For scenarios where only children are in the car and the vehicle is stationary, the system automatically upgrades the privacy level, performs full-window dimming and omnidirectional sound field shielding, and can also remotely notify the car owner. In addition, the method also includes a directional sound field parameter adaptive adjustment step, which collects the ambient background noise level through an external microphone and dynamically adjusts the frequency and sound pressure level of the masking sound to ensure stable voice leakage suppression effect.

[0051] Here, for the specific scenario where only children are in the vehicle and the vehicle is stationary, the system automatically upgrades the privacy protection level, performing full-window dimming and omnidirectional sound field shielding. This design is because children alone are easily targeted by safety hazards, and comprehensive privacy protection can effectively reduce the risk of children being abducted or harassed. Simultaneously, the system can be linked to the vehicle's remote communication module to remotely notify the owner, allowing parents to monitor the child's status in the vehicle in real time, further enhancing the safety of children traveling in the car.

[0052] The method also adds a step for adaptive adjustment of directional sound field parameters. The system collects the background noise level of the external environment in real time through an external microphone, and obtains core data such as the frequency and sound pressure level of the background noise. Based on this data, the frequency and sound pressure level of the masking sound emitted by the directional acoustic speaker are dynamically adjusted. This can effectively avoid the failure of the masking effect due to changes in environmental noise, ensure that the voice leakage suppression effect inside and outside the vehicle is always at a stable level, and improve the reliability of privacy protection.

[0053] In summary, the embodiments of this application have the following beneficial effects: By integrating geographical location and external scene data from the environmental perception module, occupant status recognition module data on in-vehicle occupants and audio activity, and vehicle driving status data, a multi-source contextual perception system is constructed. This system can automatically activate privacy protection mode when privacy-sensitive areas such as schools and hospitals are in a stationary or low-speed state, when a child is alone in the vehicle, or when there are privacy-triggered conditions such as voice calls. This completely solves the problem of delayed response or false triggering caused by manual operation in traditional technologies. Simultaneously, the system innovatively achieves the linkage control of electrochromic window dimming and directional acoustic speaker sound wave masking, creating a dual privacy barrier of vision and hearing. This effectively compensates for the shortcomings of existing technologies that only protect vision or sound and lack complete privacy protection, fully meeting the high privacy requirements of scenarios such as business meetings and storage of valuables. Furthermore, the system... The system employs a zoned privacy enforcement strategy, performing privacy operations only on windows facing public areas and corresponding side speakers, while non-risk sides remain in normal mode. This achieves a balance between privacy protection and in-vehicle lighting and visibility, avoiding the drawbacks of traditional one-size-fits-all adjustments. For special scenarios where only children are in the car, the system can automatically upgrade the privacy level and remotely notify the owner, significantly improving the safety of family users. Furthermore, the system's core hardware, electrochromic glass, only consumes power when switching states, and the directional speakers have a power consumption of less than 5W, offering advantages of low power consumption and high reliability without placing an additional burden on the vehicle's electrical system. Combined with a two-way human-machine interface of the central control screen and voice assistant, it balances intelligent system control with ease of operation, comprehensively improving the overall performance of vehicle privacy protection and the user experience.

[0054] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems and devices described above can be referred to the corresponding processes in the method embodiments, and will not be repeated here. In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some communication interfaces; the indirect coupling or communication connection of devices or modules can be electrical, mechanical, or other forms.

[0055] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0056] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A vehicle privacy protection system that links window dimming with sound field, characterized in that, include: An environmental perception module, comprising a GPS positioning unit, a high-precision map interface, and front / side cameras, is used to acquire the vehicle's real-time geographical location, identify privacy-sensitive areas, and capture images of the vehicle's external environment. The occupant status recognition module includes a DMS camera, an in-cabin infrared camera, and a microphone array, which are used to monitor the driver's status, identify the number and attributes of rear-seat occupants, and detect in-vehicle voice activity. The privacy decision engine, deployed in the vehicle domain controller, is used to execute privacy protection decision logic and output control commands; The actuator assembly, which includes electrochromic windows, directional acoustic speakers, and a vehicle audio system, is used to adjust the light transmittance of the windows, mask the acoustics outside the vehicle, and adjust the volume inside the vehicle. The user interaction interface, including the central control screen and voice assistant, is used to enable users to interact with the system by giving commands and feedback on their status. The perception data output terminals of the environmental perception module and the occupant status recognition module are both connected to the perception data input terminal of the privacy decision engine. The control command output terminal of the privacy decision engine is connected to the control command input terminal of the actuator group. The user interaction interface is bidirectionally connected to the privacy decision engine, which can transmit user commands to the privacy decision engine and receive system status information fed back by the privacy decision engine.

2. The system according to claim 1, characterized in that, The electrochromic window is made of WO3-based thin film material and is divided into four independent control zones: front left, front right, rear left, and rear right, for zoned dimming. The directional acoustic speaker uses ultrasonic carrier modulation technology with a beam angle of <30° and is installed on the outside of the A / B pillars of the vehicle to directionally emit masking sound waves out of the vehicle.

3. The system according to claim 1, characterized in that, The GPS positioning unit of the environmental perception module is used to output the real-time latitude and longitude coordinates of the vehicle, the high-precision map interface is used to output the boundary information of privacy-sensitive areas, and the front / side cameras are used to output the external environment image data of the vehicle. The output ends of the three are all integrated with the environmental data receiving port of the privacy decision engine.

4. The system according to claim 1, characterized in that, The DMS camera output, cabin infrared camera output, and microphone array output of the occupant status recognition module are all connected to the occupant status data receiving port of the privacy decision engine. The DMS camera is used to transmit driver status data, the cabin infrared camera is used to transmit the number, location, and attribute data of rear occupants, and the microphone array is used to transmit in-vehicle voice activity data.

5. The system according to claim 1, characterized in that, The activation conditions for the privacy protection decision logic of the privacy decision engine are: the vehicle is stationary or at low speed, the vehicle is located within a privacy-sensitive area, and a privacy protection trigger condition exists inside the vehicle. The privacy protection trigger condition includes at least one of the following: recognizing a child, detecting a voice call, and the user marking valuable items. Furthermore, the control command output terminal of the privacy decision engine is connected to the dimming command receiving terminal of the electrochromic window, the start command receiving terminal of the directional acoustic speaker, and the volume adjustment command receiving terminal of the in-vehicle audio system, respectively.

6. The system according to claim 1, characterized in that, Both the central control screen and the voice assistant of the user interaction interface communicate bidirectionally with the privacy decision engine. The manual setting command output terminal of the central control screen and the voice command output terminal of the voice assistant are connected to the user command receiving port of the privacy decision engine. The system status feedback output terminal of the privacy decision engine is connected to the status display receiving port of the central control screen and the voice prompt receiving port of the voice assistant.

7. The system according to claim 1, characterized in that, The occupant status recognition module is also equipped with an AI status classification model, which is based on the MobileNetV3 architecture and is used to classify and recognize the occupant's activity status, including a child in the back seat being alone and the driver making a video call. Furthermore, the output of the AI ​​state classification model is connected to the occupant behavior data receiving port of the privacy decision engine.

8. The system according to claim 1, characterized in that, The privacy decision engine is deployed in an in-vehicle Linux or RTOS system, and the output terminals of its built-in rule engine and lightweight neural network are all connected to the comprehensive judgment module of the privacy decision engine. The comprehensive judgment module outputs control commands to the actuator group in a unified manner. The light transmittance of the electrochromic window of the actuator group can be reduced to below a certain value, and the directional acoustic speaker emits anti-phase white noise to form an external acoustic masking zone.

9. A method for protecting vehicle privacy by linking window dimming with sound field, characterized in that, Includes the following steps: The vehicle's location is obtained through GPS positioning unit and high-precision map interface. It is determined whether the vehicle has entered the preset privacy-sensitive area. If so, the next step is carried out directly; otherwise, the step is executed repeatedly. The number, location, and activity status of occupants are identified through in-cabin cameras and AI models. The microphone array is used to detect whether there are voice calls or sensitive audio playback inside the vehicle. The privacy decision engine determines whether to activate privacy mode by comprehensively considering vehicle status, regional attributes, and in-vehicle triggering conditions. Control the corresponding zone's electrochromic window dimming, activate the directional acoustic speakers, and adjust the in-vehicle audio volume; When the vehicle leaves the sensitive area or the user manually turns off privacy mode, all actuators are restored to their default state.

10. The method according to claim 9, characterized in that, The method further includes: For scenarios where only children are in the car and the vehicle is stationary, the system automatically upgrades the privacy level, performs full-window dimming and omnidirectional sound field shielding, and can also remotely notify the car owner. In addition, the method also includes a directional sound field parameter adaptive adjustment step, which collects the ambient background noise level through an external microphone and dynamically adjusts the frequency and sound pressure level of the masking sound to ensure stable voice leakage suppression effect.

Citation Information

Cited By

  • Linux PipeWire audio noise reduction method based on CPU instruction set optimization and storage medium

    CN122261517A