Vehicle-mounted interaction control method and device, vehicle, program product and storage medium

CN122818403APending Publication Date: 2026-09-25CHERY AUTOMOBILE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610940034.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-26
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

在实际应用中,云端方案还存在大语言模型幻觉可能生成危险指令的情况

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122818403A_ABST
    Figure CN122818403A_ABST
Patent Text Reader

Abstract

The present disclosure provides a vehicle-mounted interaction control method and device, a vehicle, a program product and a storage medium, relates to the technical field of vehicle control, and can accurately complete a voice or interaction instruction under the premise of guaranteeing user privacy security. The method comprises the following steps: replacing a privacy entity in request information of a user to obtain desensitization information and a first mapping relationship; sending the desensitization information to a semantic analysis end, and receiving a processing result returned by the semantic analysis end; restoring a replacement identifier in the processing result to the privacy entity according to the first mapping relationship; and controlling the vehicle to perform a corresponding operation according to the restored processing result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of vehicle control technology, and in particular to in-vehicle interactive control methods, devices, vehicles, program products, and storage media. Background Technology

[0002] With the development of generative intelligent agents, in-vehicle voice assistants are evolving towards large-model generative interaction. Current mainstream architectures are divided into fully cloud-based processing and fully local processing: fully cloud-based processing requires voice data to be uploaded to the cloud, while fully local processing is limited by computing power and only supports fixed commands. In practical applications, cloud-based solutions also suffer from the risk of generating dangerous commands due to the illusion of a large language model.

[0003] Therefore, how to achieve intelligent in-vehicle voice assistant interaction has become an urgent problem to be solved. Summary of the Invention

[0004] The in-vehicle interactive control method, device, vehicle, program product, and storage medium provided in this disclosure can accurately complete voice or interactive commands while ensuring user privacy and security.

[0005] In a first aspect, this application provides an in-vehicle interactive control method, comprising: replacing a privacy entity in a user's request information to obtain desensitized information and a first mapping relationship, wherein the privacy entity is an information entity of a preset privacy type, the desensitized information contains a substitution identifier, the substitution identifier and the privacy entity have the same syntactic attributes in the request information, and the first mapping relationship represents the correspondence between the privacy entity and the substitution identifier; sending the desensitized information to a semantic parsing terminal and receiving a processing result returned by the semantic parsing terminal, the processing result containing the substitution identifier; restoring the substitution identifier in the processing result to a privacy entity according to the first mapping relationship; and controlling the vehicle to perform corresponding operations according to the restored processing result.

[0006] The in-vehicle interactive control method provided in this application can ensure the accuracy of semantic parsing and the complete execution of vehicle control while protecting user privacy. The method first replaces privacy entities such as name, address, and contact information in the request information with alternative identifiers that have the same syntactic attributes. This prevents the anonymized information from failing to be parsed due to format or contextual anomalies after transmission to the semantic parsing end, thus ensuring the availability of cloud-based parsing without exposing sensitive data to the vehicle. Since the correspondence between privacy entities and alternative identifiers is stored only in the local first mapping relationship, sending anonymized information avoids the risk of privacy leakage and allows the semantic parsing end to return a processing result containing alternative identifiers without accessing the actual data. Then, based on the first mapping relationship, the alternative identifiers in the returned result are restored to the actual privacy entities, ensuring that subsequent execution commands accurately target the specific object or content in the user's intent. Finally, the vehicle is controlled to perform corresponding operations based on the restored complete processing result, achieving complete protection of sensitive information from external systems and ensuring uninterrupted vehicle service response.

[0007] In some possible implementations, replacing privacy entities in the user's request information to obtain de-identified information and a first mapping relationship includes: identifying privacy entities in the user's request information; replacing the privacy entities with corresponding alternative identifiers according to the entity type of the privacy entities to obtain de-identified information; and determining the first mapping relationship according to the correspondence between privacy entities and alternative identifiers.

[0008] In some possible implementations, replacing the privacy entities in the user's request information to obtain desensitized information and a first mapping relationship further includes: identifying the privacy entities in the user's request information; converting the privacy entities into semantic vectors and adding perturbation noise to the semantic vectors as replacement identifiers to obtain desensitized information; and determining the first mapping relationship based on the correspondence between the privacy entities and the replacement identifiers.

[0009] In some possible implementations, replacing the privacy entities in the user's request information to obtain desensitized information and a first mapping relationship further includes: identifying the privacy entities in the user's request information; encrypting the privacy entities and using the encrypted ciphertext fragment as a replacement identifier to obtain desensitized information; and determining the first mapping relationship based on the correspondence between the privacy entities and the replacement identifier.

[0010] In some possible implementations, before replacing the privacy entities in the user's request information to obtain desensitized information and the first mapping relationship, the method further includes: obtaining the semantic features corresponding to the user's request information; determining the processing method of the request information based on the matching result of the semantic features and a preset instruction set; when the processing method is local processing, the vehicle directly executes the vehicle control operation corresponding to the request information; when the processing method is privacy entity replacement processing, the step of replacing the privacy entities in the user's request information is performed.

[0011] In some possible implementations, the processing method of the request information is determined based on the matching result of semantic features and a preset instruction set, including: determining the similarity between the semantic features and each instruction feature in the preset instruction set; if the maximum similarity is greater than or equal to a preset threshold, determining the processing method as local processing; if the maximum similarity is less than the preset threshold, determining the processing method as privacy entity replacement processing.

[0012] In some possible implementations, before controlling the vehicle to perform the corresponding operation based on the restored processing result, the method further includes: obtaining the vehicle's current driving state parameters; performing a safety verification on the restored processing result based on the current driving state parameters; if the safety verification passes, controlling the vehicle to perform the corresponding operation based on the restored processing result; if the safety verification fails, correcting the target control parameters indicated by the restored processing result based on the current driving state parameters to control the vehicle to perform the corresponding operation.

[0013] Secondly, this application provides an in-vehicle interactive control device, including: an information desensitization module, a communication module, an information restoration module, and an execution module. The information desensitization module is used to replace privacy entities in a user's request information to obtain desensitized information and a first mapping relationship. The privacy entity is an information entity of a preset privacy type. The desensitized information includes a substitution identifier, which has the same syntactic attributes as the privacy entity in the request information. The first mapping relationship represents the correspondence between the privacy entity and the substitution identifier. The communication module is used to send the desensitized information to a semantic parsing terminal and receive the processing result returned by the semantic parsing terminal. The processing result includes the substitution identifier. The information restoration module is used to restore the substitution identifier in the processing result to a privacy entity according to the first mapping relationship. The execution module is used to control the vehicle to perform corresponding operations based on the restored processing result.

[0014] In some possible implementations, the information desensitization module is specifically used for: identifying privacy entities in the user's request information; replacing the privacy entity with a corresponding alternative identifier according to the entity type of the privacy entity to obtain desensitized information; and determining a first mapping relationship based on the correspondence between the privacy entity and the alternative identifier.

[0015] In some possible implementations, the information desensitization module is further configured to: identify privacy entities in the user's request information; convert the privacy entities into semantic vectors and add perturbation noise to the semantic vectors as alternative identifiers to obtain desensitized information; and determine a first mapping relationship based on the correspondence between privacy entities and alternative identifiers.

[0016] In some possible implementations, the information desensitization module is further configured to: identify privacy entities in the user's request information; encrypt the privacy entities and use the encrypted ciphertext fragment as a replacement identifier to obtain desensitized information; and determine a first mapping relationship based on the correspondence between the privacy entities and the replacement identifier.

[0017] In some possible implementations, the device further includes an instruction recognition module, used to: acquire semantic features corresponding to the user's request information; determine the processing method of the request information based on the matching result of the semantic features and a preset instruction set; when the processing method is local processing, the vehicle directly executes the vehicle control operation corresponding to the request information; when the processing method is privacy entity replacement processing, the step of replacing the privacy entity in the user's request information is performed.

[0018] In some possible implementations, the instruction recognition module is specifically used to: determine the similarity between semantic features and each instruction feature in a preset instruction set; if the maximum similarity is greater than or equal to a preset threshold, determine that the processing method is local processing; if the maximum similarity is less than the preset threshold, determine that the processing method is privacy entity replacement processing.

[0019] In some possible implementations, the device further includes a safety verification module for: acquiring the current driving state parameters of the vehicle; performing a safety verification on the restored processing result based on the current driving state parameters; controlling the vehicle to perform corresponding operations based on the restored processing result when the safety verification passes; and correcting the target control parameters indicated by the restored processing result based on the current driving state parameters when the safety verification fails, so as to control the vehicle to perform corresponding operations.

[0020] Thirdly, this application provides a control device, including: a memory and a processor; the memory and the processor are coupled; the memory is used to store a computer program; the processor executes the computer program to implement the vehicle interactive control method of any of the above embodiments.

[0021] Fourthly, this application provides a computer-readable storage medium storing computer program instructions that, when executed by a processor, implement the vehicle interactive control method of any of the above embodiments.

[0022] Fifthly, this application provides a computer program product including computer program instructions that, when executed by a processor, implement the in-vehicle interactive control method described in any of the above embodiments.

[0023] Sixthly, this application provides a vehicle including the control device of any of the preceding embodiments; or the computer-readable storage medium of any of the preceding embodiments; or the computer program product of any of the preceding embodiments. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in this disclosure, the accompanying drawings used in some embodiments of this disclosure will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings.

[0025] Figure 1 A schematic diagram of the architecture of an in-vehicle interactive control system provided for some embodiments of this disclosure; Figure 2 A flowchart illustrating an in-vehicle interactive control method provided in some embodiments of this disclosure; Figure 3 This is a schematic diagram of the structure of an in-vehicle interactive control device provided in some embodiments of this disclosure; Figure 4 This is a schematic diagram of the structure of a control device provided in some embodiments of this disclosure. Detailed Implementation

[0026] The technical solutions of this disclosure will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0027] It should be noted that, in this disclosure, the terms "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in this disclosure should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0028] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature.

[0029] In the description of this disclosure, unless otherwise stated, " / " means "or," for example, A / B can mean A or B. "And / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. Furthermore, "at least one" means one or more, and "more than one" means two or more.

[0030] As described in the background section, the processing architecture of in-vehicle voice assistants mainly includes the following two categories.

[0031] One type is the fully cloud-based processing architecture. In this approach, the in-vehicle terminal acts only as a front-end device for audio acquisition and playback, uploading all collected user voice data to a cloud server. A massively parameterized model deployed in the cloud then performs automatic speech recognition, natural language understanding, and natural language generation, ultimately sending control commands or voice responses back to the vehicle. This method leverages the powerful inference capabilities of the cloud-based, large-scale model to achieve complex semantic understanding and generative interaction. However, this method requires transmitting every sentence of the user's voice data in plaintext out of the vehicle. If the cloud interface is hijacked or the database is leaked, it can lead to a mass leak of core user privacy. Furthermore, vehicle hardware control has extremely high requirements for real-time performance and reliability. The fully cloud-based solution introduces uncontrollable network round-trip latency, typically resulting in response times exceeding 1.5 seconds, causing a sense of operational lag. In environments with weak or no network connectivity, such as tunnels, underground parking garages, or remote mountainous areas, a cloud link interruption can cause the core control functions to completely fail.

[0032] Another type is the fully local processing architecture. This approach is limited by the memory bandwidth and power consumption of the vehicle's infotainment chip. It deploys only an offline model with a very small number of parameters (usually less than 1 byte) or a command word engine based on a finite state machine locally. It achieves low-latency response without relying on the network, and voice data does not need to be transmitted out of the vehicle, fundamentally avoiding the risk of privacy leaks. However, this approach is limited to a few hundred preset fixed commands (such as "turn on the air conditioner" or "play music"), and cannot handle complex logic or generalized tasks, making it difficult to meet users' needs for natural language interaction and broad cognitive abilities.

[0033] To address the aforementioned technical issues, this disclosure provides a vehicle-mounted interactive control method. The method's approach involves first replacing privacy entities such as name, address, and contact information in the request information with alternative identifiers that share the same syntactic attributes. This ensures that the anonymized information does not fail to be parsed due to format or contextual errors after transmission to the semantic parsing end, thus guaranteeing the availability of cloud-based parsing without exposing sensitive data to the vehicle. Since the correspondence between privacy entities and alternative identifiers is stored only in a local first mapping relationship, sending anonymized information avoids the risk of privacy leakage and allows the semantic parsing end to return a processing result containing the alternative identifiers without accessing the actual data. Then, based on the first mapping relationship, the alternative identifiers in the returned result are restored to the actual privacy entities, ensuring that subsequent execution commands accurately target the specific object or content intended by the user. Finally, the vehicle is controlled to perform corresponding operations based on the restored complete processing result, achieving complete protection of sensitive information from external systems and ensuring uninterrupted vehicle service response.

[0034] The in-vehicle interactive control method provided in the embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0035] In this embodiment of the disclosure, the in-vehicle interactive control method can be applied by deploying an in-vehicle interactive control system in a vehicle. See also Figure 1 This is a schematic diagram of the architecture of an in-vehicle interactive control system provided in an embodiment of this disclosure. Figure 1 As shown, the in-vehicle interactive control system includes a vehicle-side terminal and a semantic parsing terminal. The vehicle-side terminal, acting as the security domain, provides anonymized service requests to the semantic parsing terminal. The semantic parsing terminal, acting as the inference domain, infers service instructions based on the anonymized service requests and feeds them back to the vehicle-side terminal.

[0036] In some possible examples, the semantic parsing end can be a large model inference cluster in the cloud, a large language model server deployed on an edge computing node (e.g., a mobile terminal device), or a lightweight large model inference engine deployed locally on the vehicle. This disclosure does not limit the specific form of the semantic parsing end.

[0037] In some possible examples, the in-vehicle interactive control method provided in this disclosure can be applied to the cockpit domain controller of intelligent connected vehicles to process user requests involving personal privacy information. For example, if a user issues a voice command containing a contact's name, specific address, contact information, or voiceprint characteristics, the in-vehicle interactive control system can complete semantic parsing and execution of services such as schedule creation, navigation route planning, and communication, while protecting the aforementioned privacy information from being disclosed.

[0038] In some possible examples, the in-vehicle interaction control method provided in this disclosure can also be applied to in-vehicle interaction scenarios in environments with weak network coverage or no network coverage. For example, when a vehicle enters an underground garage, tunnel, or remote mountainous area, the in-vehicle interaction control system can switch to offline working mode to ensure the normal response and availability of high-frequency vehicle control functions without relying on the reasoning capabilities of the semantic parsing end.

[0039] In some possible examples, the in-vehicle interactive control method provided in this disclosure can also be applied to scenarios with high requirements for vehicle driving safety. For example, when the vehicle is traveling at high speed, the in-vehicle interactive control system can combine real-time sensor signals such as vehicle speed, rainfall, and light intensity to make a reasonable judgment on the rationality of the control command to be executed, so as to avoid physical-level misoperation caused by semantic parsing deviation.

[0040] It is understood that the application scenarios of the embodiments of this disclosure are not limited. The system architecture and business scenarios described in the embodiments of this disclosure are for the purpose of more clearly illustrating the technical solutions of the embodiments of this disclosure, and do not constitute a limitation on the technical solutions provided by the embodiments of this disclosure. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of this disclosure are also applicable to similar technical problems.

[0041] This disclosure provides an in-vehicle interactive control method, such as Figure 2 As shown, the method includes the following steps S201-S204: S201. Replace the privacy entities in the user's request information to obtain de-identified information and the first mapping relationship.

[0042] Among them, the privacy entity is an information entity of a preset privacy type. The de-identified information contains a substitute identifier. The substitute identifier and the privacy entity have the same syntactic attributes in the request information. The first mapping relationship represents the correspondence between the privacy entity and the substitute identifier.

[0043] In this embodiment, the request information refers to a message containing a specific operational intent sent by the user to the vehicle-mounted interactive control system via voice, text, or other input methods. The privacy entity refers to the specific information content in the request information that involves the user's personal privacy or sensitive vehicle data. Direct transmission of this content to external systems without processing may pose a privacy leakage risk. The alternative identifier is a symbolic mark used to occupy the original position of the privacy entity in the de-identified information while maintaining its syntactic function. This mark itself does not contain any real information that can identify the user or point to a specific object. The first mapping relationship refers to a data structure maintained locally on the vehicle end, recording the one-to-one correspondence between privacy entities and alternative identifiers. This mapping relationship is stored and managed only in the trusted environment on the vehicle end and is not sent to external systems along with the de-identified information.

[0044] In some embodiments, the preset privacy type of a privacy entity can cover multiple categories of sensitive entity information, such as name, address, contact information, ID number, vehicle identification number, instant messaging content, and biometric information.

[0045] For example, a name can include the names of contacts in the user's address book, the user's own name, or other personal names that can identify a specific natural person. An address can include frequently used addresses set by the user, such as home and work addresses, as well as detailed location information of specific points of interest mentioned in the request, such as hospitals or shopping malls. Contact information can include mobile phone numbers, landline numbers, email addresses, and other communication information that can be used to contact a specific individual. Identification numbers can include ID card numbers, passport numbers, driver's license numbers, and other document-type numerical or coded information that can uniquely identify an individual. A vehicle identification number (VIN) is a unique identifier for a vehicle, used to identify a specific vehicle when related services are involved. Instant messaging content refers to the text content of instant messages sent or received by the user through the in-vehicle system. Biometric information can include physiological or behavioral characteristic data that can be used to identify an individual, such as the user's voiceprint and facial features.

[0046] In some embodiments, the in-vehicle interactive control system can acquire the user's voice commands through an in-vehicle microphone array and convert them into text-formatted request information via an automatic speech recognition engine. Alternatively, the in-vehicle interactive control system can also acquire request information directly entered by the user in text form through input devices such as an in-vehicle touchscreen or center console panel.

[0047] In some embodiments, the in-vehicle interactive control system may also store the first mapping relationship in a trusted execution environment on the vehicle side. This trusted execution environment is built based on the security isolation technology built into the vehicle system chip and is isolated from the conventional operating system environment. The first mapping relationship is only valid within the current session period. In response to the end of the session or a vehicle shutdown event, the in-vehicle interactive control system may immediately perform a data erasure operation on the storage area storing the first mapping relationship.

[0048] In one possible implementation, the vehicle-mounted interactive control system can first identify the privacy entity in the user's request information, and replace the privacy entity with the corresponding alternative identifier according to the entity type of the privacy entity to obtain de-identified information. Then, based on the correspondence between the privacy entity and the alternative identifier, the first mapping relationship is determined.

[0049] For example, the in-vehicle interactive control system can use named entity recognition algorithms to perform sequence labeling on request information. When a person's name is identified in the text, it is replaced with a substitute identifier indicating the contact type. When an address is identified, it is replaced with a substitute identifier indicating the point of interest type. Each entity type corresponds to a different prefix or format of the substitute identifier. The in-vehicle interactive control system also establishes and saves mapping entries between each privacy entity and its replaced substitute identifier locally to form a primary mapping relationship.

[0050] It should be understood that by generating a corresponding type of alternative identifier based on the entity type of the privacy entity, the alternative identifier in the de-identified information not only retains the syntactic attributes but also carries entity category information. When processing, the semantic parsing end can accurately understand the semantic role corresponding to the position based on the type prefix of the alternative identifier, thereby improving the accuracy of semantic parsing and the correctness of slot filling.

[0051] In another possible implementation, the vehicle interaction control system can first identify the privacy entities in the user's request information, convert the privacy entities into semantic vectors, add perturbation noise to the semantic vectors as alternative identifiers to obtain desensitized information, and then determine the first mapping relationship based on the correspondence between the privacy entities and the alternative identifiers.

[0052] For example, the in-vehicle interactive control system can map identified privacy entities into semantic vectors in a high-dimensional space using a semantic embedding model. A differential privacy algorithm is then used to superimpose Gaussian noise, ensuring differential privacy, onto these semantic vectors. This noisy vector is then embedded as a substitute identifier within the desensitized information. While the noisy vector retains the approximate location of the privacy entity in the semantic space, it cannot be reversed to reconstruct the original privacy entity text. The in-vehicle interactive control system locally stores the correspondence between the original privacy entity text and the noisy vector as the first mapping relationship.

[0053] It should be understood that by converting privacy entities into semantic vectors and adding perturbation noise as a substitute identifier, it is possible to protect the specific content of privacy entities from being disclosed while ensuring that the substitute identifiers in the desensitized information still carry the semantic location information of the privacy entities. The semantic parsing end can directly perform intent understanding and semantic reasoning in the vector space without having to restore the vectors to text before processing. This eliminates the text serialization and deserialization steps between the vehicle end and the semantic parsing end, reduces the overall processing latency, and also eliminates the storage overhead and lifecycle management burden caused by maintaining the text mapping table.

[0054] In another possible implementation, the vehicle-mounted interactive control system can first identify the privacy entity in the user's request information, encrypt the privacy entity, and use the encrypted ciphertext fragment as a substitute identifier to obtain desensitized information. Then, based on the correspondence between the privacy entity and the substitute identifier, the first mapping relationship is determined.

[0055] For example, the in-vehicle interactive control system uses a homomorphic encryption algorithm to encrypt identified privacy entities, embedding the encrypted ciphertext data as a substitute identifier within the de-identified information. This ciphertext fragment can participate in calculations at the semantic parsing end without decryption, but the semantic parsing end cannot read the original text content of the privacy entity from it. The in-vehicle interactive control system locally stores the association between the original text of the privacy entity and the corresponding ciphertext data as the first mapping relationship.

[0056] It should be understood that by homomorphically encrypting the privacy entity and using the ciphertext fragment as a substitute identifier, the semantic parsing end, upon receiving the de-identified information, can directly perform semantic computation and logical reasoning on the ciphertext data without decrypting it. After receiving the returned processing result, the vehicle can use its local private key to decrypt and reconstruct the true privacy entity. Throughout the entire transmission and processing process, the privacy data exists in ciphertext form. Even if the communication link or the semantic parsing end is attacked, attackers cannot extract any readable information from the intercepted data, providing reliable technical protection for in-vehicle interaction in high-security scenarios.

[0057] As shown in S201, by replacing the privacy entity in the request information, the de-identified information no longer contains real privacy data. This cuts off the path for privacy information to be transmitted out of the vehicle along with the request information. Simultaneously, because the replacement identifier maintains the same syntactic attributes as the privacy entity in the request information, the de-identified information can still maintain its original semantic structure and logical relationship after being sent to the semantic parsing end. The replacement of key information will not prevent the semantic parsing end from failing to understand the request intent, thus ensuring the availability and accuracy of subsequent semantic parsing while protecting user privacy. The first mapping relationship is maintained only locally on the vehicle, ensuring that the correspondence between the privacy entity and the replacement identifier is always preserved within the security domain. External systems cannot establish this correspondence at any stage, achieving controllable use of privacy data.

[0058] S202. Send de-identification information to the semantic parsing end and receive the processing result returned by the semantic parsing end.

[0059] The processing results include a substitution identifier.

[0060] In this embodiment, the semantic parsing end refers to a computing node used to perform semantic understanding and intent reasoning on the request information from the vehicle interaction control system. The semantic parsing end is equipped with a pre-trained large language model inference engine. This engine, trained on massive corpora, acquires natural language understanding and generation capabilities, and is used to receive request information sent from the vehicle and perform intent recognition, slot filling, and logical reasoning on the request information.

[0061] In some embodiments, the semantic parsing end can be a cloud-based large model inference cluster, a large language model server deployed on an edge computing node, or a lightweight large model inference engine deployed locally on the vehicle.

[0062] In some embodiments, the specific content of the processing result may vary depending on the type of requested information. For example, for a request to create a schedule, the processing result may include an intent identifier indicating the creation of a schedule, as well as parameter fields containing information such as time, location, and event title. For a request to plan a navigation route, the processing result may include an intent identifier indicating the planning route, as well as parameter fields containing information such as start point, destination, and waypoints. For a request to query information, the processing result may include an intent identifier indicating a query operation, as well as query condition parameters.

[0063] It should be understood that the values ​​of the parameter fields in the processing results directly use the original text of the alternative identifiers in the de-identified information where privacy entities are involved, so that the processing results themselves do not contain any real privacy data.

[0064] In some embodiments, the in-vehicle interactive control system can send de-identified information through a communication link between the vehicle and the semantic parsing end. When the semantic parsing end is a large language model server on a cloud-based large model inference cluster or an edge computing node, the in-vehicle interactive control system establishes an encrypted communication connection with the semantic parsing end via a mobile communication network through the in-vehicle communication terminal, sends the de-identified information to the semantic parsing end in a structured data format, and continuously monitors the communication link to receive the processing results returned by the semantic parsing end. When the semantic parsing end is a lightweight large model inference engine deployed locally on the vehicle, the in-vehicle interactive control system transmits the de-identified information to the inference engine through an inter-process communication mechanism within the vehicle, and the inference engine returns the processing results.

[0065] In some embodiments, the in-vehicle interactive control system can also detect the current network connection status before sending de-identified information. When the network signal strength is detected to be lower than a preset strength threshold or the heartbeat packet loss rate exceeds a preset loss rate threshold, it is determined that the current network environment is weak. In this case, sending de-identified information to the semantic parsing end (a computing end that requires network connection communication, such as a cloud-based large model inference cluster or edge computing node) will face a high risk of transmission delay or failure. At this time, the in-vehicle interactive control system will trigger an offline degradation processing procedure, in which the offline command word engine deployed locally on the vehicle processes the request information. Although this offline command word engine does not have the same generalized inference capability as the semantic parsing end, it can identify standardized high-frequency vehicle control commands to ensure the availability of core vehicle control functions in weak network or no network environments.

[0066] In some embodiments, the vehicle-mounted interactive control system may also start a response waiting timer after sending de-identified information. If the processing result returned by the semantic parsing terminal is not received within a preset timeout period, a retransmission mechanism or timeout processing procedure will be triggered.

[0067] In one possible implementation, the in-vehicle interactive control system can send de-identified information via a communication link between the vehicle and the semantic parsing end. When the semantic parsing end is a cloud-based large-model inference cluster or an edge computing node, the in-vehicle interactive control system can establish an encrypted communication connection with the semantic parsing end through the in-vehicle mobile communication network, encode the de-identified information into a structured data format and send it to the semantic parsing end, while maintaining a listening state on the communication link to receive the structured processing results returned by the semantic parsing end, and parse out the parameter fields containing the substitution identifier from the processing results. When the semantic parsing end is a lightweight large-model inference engine deployed locally on the vehicle, the in-vehicle interactive control system sends the de-identified information to the processing queue of the local inference engine through inter-process communication and obtains the processing results returned by the inference engine.

[0068] As shown in S202, the information sent to the semantic parsing end is the de-identified information after replacement processing, rather than the original request information. This ensures that the privacy entity always exists in the form of a substitute identifier during transmission and delivery. Regardless of where the semantic parsing end is deployed, the privacy entity never leaves the vehicle's security domain, thus cutting off the path for privacy data leakage at the physical architecture level. The processing result returned by the semantic parsing end contains the substitute identifier, not the real privacy entity, so the returned result also does not carry any identifiable privacy information. The semantic parsing end completes semantic parsing without deciphering the real privacy entity, and directly reuses the substitute identifier from the de-identified information in the processing result. This ensures that the vehicle can accurately reconstruct the real privacy entity based on the locally maintained first mapping relationship, achieving a balance between privacy protection and functional availability.

[0069] S203. Based on the first mapping relationship, restore the substitute identifier in the processing result to the privacy entity.

[0070] In some embodiments, the correspondence recorded in the first mapping relationship may be a direct textual correspondence between the original privacy entity text and the alternative identifier, an encrypted correspondence between the original privacy entity text and the alternative identifier, or an index mapping relationship between the original privacy entity text and the alternative identifier.

[0071] In some embodiments, for direct text correspondence, the in-vehicle interactive control system can directly find the alternative identifier in the processing result and replace it with the corresponding original text of the privacy entity.

[0072] In some embodiments, for encrypted correspondences, the in-vehicle interactive control system may first decrypt the substitute identifier in the processing result before filling in the corresponding privacy entity original text.

[0073] In some embodiments, for an index mapping relationship, the vehicle-mounted interactive control system can query the corresponding privacy entity original text in the first mapping relationship based on the index information carried by the replacement identifier and then replace it.

[0074] In some embodiments, the in-vehicle interactive control system can obtain the first mapping relationship by accessing a secure storage area within the vehicle's trusted execution environment. Before sending the de-identified information, the in-vehicle interactive control system stores the first mapping relationship in the trusted execution environment built into the vehicle's system chip. This trusted execution environment is isolated from the conventional operating system environment based on security isolation technology, and ordinary applications cannot access the data within it. When a restoration operation is required, the in-vehicle interactive control system can read the first mapping relationship through the secure application programming interface provided by the trusted execution environment, and complete the lookup and replacement operation between the alternative identifier and the privacy entity within the trusted execution environment.

[0075] In some embodiments, after receiving the processing result returned by the semantic parsing terminal, the in-vehicle interaction control system can also perform an existence check on each substitution identifier in the processing result to determine whether each substitution identifier in the current processing result can be found in the first mapping relationship. When the substitution identifier in the processing result can be found in the first mapping relationship, the in-vehicle interaction control system performs the restoration operation normally. When the substitution identifier in the processing result cannot be found in the first mapping relationship, the in-vehicle interaction control system terminates the current operation process and outputs a restatement prompt to the user.

[0076] In one possible implementation, the in-vehicle interactive control system can send a restore request to the trusted execution environment (TEI) via a secure application programming interface (API). This restore request carries a substitution identifier from the processing result returned by the semantic parsing endpoint. In response to the restore request, the TPI queries a first mapping relationship in a secure storage area, maps the substitution identifier to the corresponding privacy entity plaintext, and returns the restore result to the business processing process of the in-vehicle interactive control system. The business processing process then fills the restored privacy entity into the corresponding parameter field in the processing result, forming complete instruction data.

[0077] As shown in S203, by restoring the substitute identifier in the processing result to a privacy entity according to the first mapping relationship, the real data of the privacy entity is restored and used only within the vehicle-side trusted execution environment. During the restoration process, the privacy entity does not leave the vehicle-side security domain. From the system architecture level, this ensures that the privacy data always flows within the vehicle-side closed loop, achieving complete isolation of sensitive information from the semantic parsing end and transmission link.

[0078] S204. Based on the restored processing results, control the vehicle to perform the corresponding operation.

[0079] In some embodiments, the in-vehicle interactive control system can send control commands to various actuators of the vehicle via the in-vehicle controller area network bus or in-vehicle Ethernet.

[0080] For example, for vehicle body control operations such as windows, sunroof, air conditioning, and lights, the in-vehicle interactive control system can convert the processed results into messages conforming to the Controller Area Network (CAN) bus protocol and send them to the corresponding body controller or air conditioning controller, which then drives the corresponding actuators to complete the operation. For function service operations such as navigation, calendar, and communication, the in-vehicle interactive control system can call the corresponding function service process through the application programming interface (API) of the in-vehicle operating system, and the service process will then execute the specific function. For information output operations such as voice broadcasting, the in-vehicle interactive control system can synthesize the prompt text into a voice signal through the audio output channel and play it through the in-vehicle speakers.

[0081] As shown in S204, by controlling the vehicle to perform corresponding operations based on the restored processing results, the user instructions after privacy entity replacement and semantic parsing are ultimately accurately executed at the vehicle's physical layer, completing a complete interactive loop from user request to vehicle response.

[0082] In this embodiment of the disclosure, before replacing the privacy entity in the user's request information in step S201 to obtain the desensitized information and the first mapping relationship, the vehicle interaction control system can also perform diversion processing on the user's request information to achieve a fast response to preset instructions.

[0083] For example, the in-vehicle interactive control system can first obtain the semantic features corresponding to the user's request information. Then, based on the matching result between the semantic features and a preset set of instructions, it determines the processing method for the request information.

[0084] In the case of local processing, the vehicle directly executes the vehicle control operation corresponding to the requested information. In the case of privacy entity replacement processing, the step of replacing the privacy entity in the user's request information is performed.

[0085] In this embodiment, semantic features refer to high-dimensional vectorized representations used to characterize the semantic content of request information. These semantic features can reflect the operational intent and semantic information contained in the request information. The preset instruction set refers to a reference set stored locally on the vehicle end, containing several standardized vehicle control instruction features. Each instruction feature in this set corresponds to a specific high-frequency vehicle control operation.

[0086] In some embodiments, the preset instruction set may include several instruction features corresponding to high-frequency vehicle control operations. These high-frequency vehicle control operations may include air conditioning temperature adjustment operation, air conditioning air volume adjustment operation, window opening or closing operation, sunroof opening or closing operation, seat heating or ventilation operation, volume adjustment operation, and driving mode switching operation.

[0087] In some embodiments, semantic features may be semantic vectors output by reasoning through a lightweight semantic model deployed locally on the vehicle side, where the request information is input. The lightweight semantic model may be a lightweight pre-trained language model based on a deep learning model architecture with a self-attention mechanism.

[0088] In some embodiments, when the processing method is privacy entity replacement processing, if the user's request information does not contain a privacy entity, the vehicle interaction control system can also directly send the request information to the semantic parsing terminal for semantic understanding and intent inference.

[0089] In some embodiments, the in-vehicle interactive control system can determine the similarity between semantic features and various instruction features in a preset instruction set. Then, if the maximum similarity is greater than or equal to a preset threshold, the processing method is determined to be local processing. If the maximum similarity is less than the preset threshold, the processing method is determined to be privacy entity replacement processing.

[0090] For example, an in-vehicle interactive control system can use a lightweight semantic model deployed locally on the vehicle to reason about request information and obtain semantic features. The system first inputs the request information as a text sequence into the lightweight semantic model running on the vehicle's neural network processor. This model extracts features and encodes semantics from the input text sequence through its encoder layer, outputting corresponding semantic vectors as semantic features. Then, the system calculates the cosine similarity between the semantic features and the features of each instruction in a preset instruction set to determine the matching result.

[0091] In one possible implementation, the in-vehicle interaction control system inputs the request information into a lightweight semantic model deployed locally on the vehicle, obtaining the semantic vector output by the model as semantic features. The in-vehicle interaction control system calculates the cosine similarity between this semantic vector and each instruction feature in a preset instruction set, obtaining multiple similarity values. Then, the in-vehicle interaction control system determines the maximum value among these similarity values ​​and compares this maximum value with a preset threshold. When the maximum value is greater than or equal to the preset threshold, the in-vehicle interaction control system determines that the processing method for the request information is local processing, with the vehicle directly executing the vehicle control operation corresponding to the request information. When the maximum value is less than the preset threshold, the in-vehicle interaction control system determines that the processing method for the request information is privacy entity replacement processing, performing the step of replacing the privacy entity in the request information.

[0092] In this embodiment, by first routing the request information according to the matching results of semantic features and preset instruction sets before the privacy entity replacement process, approximately 60% of the high-frequency vehicle control instructions can be intercepted and executed directly locally. This eliminates network transmission latency and queuing latency at the semantic parsing end, compressing the end-to-end response speed from the industry average of 1.5 seconds to less than 200 milliseconds, thereby improving the real-time performance and smoothness of in-vehicle interaction.

[0093] In this embodiment of the application, before controlling the vehicle to perform the corresponding operation based on the restored processing result in step S204, the vehicle interactive control system can also perform a security verification on the restored processing result to avoid the risk of physical misoperation caused by the semantic parsing end's reasoning illusion.

[0094] For example, the in-vehicle interactive control system can first obtain the current driving status parameters of the vehicle, and then perform a security verification on the restored processing result based on the current driving status parameters.

[0095] When the safety check passes, the vehicle is controlled to perform the corresponding operation based on the restored processing result. When the safety check fails, the target control parameters indicated by the restored processing result are corrected based on the current driving state parameters to control the vehicle to perform the corresponding operation.

[0096] In this embodiment, the current driving state parameter refers to the real-time operating state data of the vehicle at the current moment, which reflects the actual operating environment of the vehicle at the physical level. Safety verification refers to the process by which the in-vehicle interactive control system judges the safety of the target control parameters indicated by the restored processing results based on the current driving state parameter. This process evaluates the physical rationality of the target control parameters based on pre-set deterministic rules to determine whether the control parameters meet the safe execution conditions under the current vehicle operating conditions.

[0097] In some embodiments, the current driving status parameter may include a vehicle speed signal, which reflects the current driving speed of the vehicle and is used to determine the safety of various vehicle operations under different speed conditions.

[0098] In some embodiments, the current driving state parameter may further include a gear position signal, which reflects the current gear position of the vehicle and is used to determine whether the vehicle is in a driving state in which a specific operation can be safely performed.

[0099] In some embodiments, the current driving status parameters may also include a rain sensor signal, which reflects whether the current environment of the vehicle is experiencing rainfall and the intensity of the rainfall, and is used to determine the safety of operations involving the opening of the sunroof or windows.

[0100] In some embodiments, the current driving status parameters may also include a light sensor signal, which reflects the brightness of the current environment in which the vehicle is located, and is used to determine the rationality of operations involving turning the headlights on or off.

[0101] In some embodiments, the current driving status parameters may also include seat occupancy sensor signals, which reflect whether each seat in the vehicle is occupied by a passenger, and are used to determine the target object involved in operations such as seat heating, ventilation, or seat belt reminders.

[0102] In some embodiments, the rules upon which security verification is based may be pre-stored in the vehicle's local storage medium in the form of rule entries. Each rule entry includes a condition part and an action part. The condition part describes the combination of vehicle state conditions that triggers the rule, and the action part describes the type of operation or operation restriction that should be performed when the condition part is met.

[0103] In some embodiments, the in-vehicle interactive control system can obtain vehicle speed and gear signals from the chassis domain controller, and rain sensor signals, light sensor signals, and seat occupancy sensor signals from the body domain controller via a service-oriented protocol. The in-vehicle interactive control system can also subscribe to required sensor signals directly from the corresponding physical sensor nodes via the in-vehicle bus. The in-vehicle interactive control system can receive these signals via the controller local area network bus or in-vehicle Ethernet, and continuously update the current driving status parameters at a preset sampling period.

[0104] In some embodiments, the in-vehicle interactive control system may also compare the target control parameters indicated by the restored processing results with the physical boundary values ​​stored in the vehicle hardware parameter library before the safety verification. When the target control parameters exceed the physical limit values ​​allowed by the vehicle hardware, the target control parameters are directly truncated to the range of physical limit values.

[0105] In one possible implementation, the in-vehicle interactive control system can obtain vehicle speed signals from the chassis domain controller and rain sensor signals from the body domain controller via a service-oriented protocol. Then, the in-vehicle interactive control system inputs the target control parameters indicated by the restored processing results and the current driving state parameters into a rule engine stored locally on the vehicle. The rule engine stores deterministic rule entries based on physical safety boundaries. For example, when the vehicle speed is greater than 80 kilometers per hour and the windshield wipers are active, the target sunroof opening degree must not exceed 10%. The in-vehicle interactive control system obtains the safety verification result output by the rule engine after matching the current driving state parameters and the target control parameters. When the safety verification result indicates that the target control parameters meet the conditions of all relevant rules, the in-vehicle interactive control system determines that the safety verification has passed and controls the vehicle to perform the corresponding operation according to the target control parameters. When the safety verification result indicates that the target control parameter violates a certain rule, the vehicle interactive control system determines that the safety verification fails. The rule engine determines the allowable value range of the target control parameter based on the current driving status parameters. The vehicle interactive control system corrects the target control parameter to the allowable value range, controls the vehicle to perform corresponding operations according to the corrected control parameters, and broadcasts the correction prompt information through the vehicle voice synthesis device.

[0106] In this embodiment, by introducing a security check based on the current driving state parameters before controlling the vehicle to perform corresponding operations according to the restored processing results, the control commands generated by the semantic parsing end must undergo a deterministic rule white-box verification independent of artificial intelligence before being sent to the vehicle's physical actuators. This effectively solves the risk of physical-level misoperation caused by the illusion phenomenon inherent in large models. When the security check fails, the target control parameters are corrected instead of simply refusing execution, which ensures driving safety while satisfying the user's operational intentions as much as possible, avoiding the poor user experience caused by complete interception.

[0107] In summary, the in-vehicle interactive control method provided in this disclosure, through a heterogeneous collaborative architecture of vehicle-side anonymization, semantic parsing-side inference, and vehicle-side reconstruction, ensures the accuracy of semantic parsing and the complete execution of vehicle control while protecting user privacy. The technical solution of this application is illustrated below with two specific application scenarios.

[0108] In one specific embodiment, a user can issue a voice command to the in-vehicle interactive control system: "Make an appointment for me to see a dentist at the First People's Hospital at 9:00 AM tomorrow." The in-vehicle interactive control system will collect this voice command through the in-vehicle microphone array and convert it into a text sequence through automatic speech recognition. Then, the in-vehicle interactive control system will input the text sequence into a lightweight model on the device side. This model extracts semantic features through a self-attention mechanism encoder layer and performs sequence labeling, identifying the time entity "9:00 AM tomorrow" and labeling it as a TIME type, identifying the location entity "First People's Hospital" and labeling it as an LOC type with high sensitivity, and identifying the event entity "seeing a dentist" and labeling it as an EVENT type. Subsequently, the vehicle-mounted interactive control system generates placeholders with semantic attributes as replacement identifiers based on the recognition results. TIME_SLOT_1 corresponds to 9:00 AM tomorrow, LOC_POI_1 corresponds to the First People's Hospital, and EVENT_CONTENT_1 corresponds to seeing a dentist. These placeholders replace the corresponding privacy entities in the request information, constructing a de-identified prompt: "Help me make an appointment for [TIME_SLOT_1] to go to [LOC_POI_1] for [EVENT_CONTENT_1]. Please generate a calendar creation command." Simultaneously, the vehicle-mounted interactive control system calls the secure application interface of the vehicle's trusted execution environment to write a first mapping relationship into secure memory. This first mapping relationship records the correspondence between TIME_SLOT_1 and 9:00 AM tomorrow, LOC_POI_1 and the First People's Hospital, and EVENT_CONTENT_1 and seeing a dentist. This secure memory area is invisible to ordinary operating system applications. Then, the vehicle-mounted interactive control system can establish an encrypted communication connection with the semantic parsing end via the vehicle communication terminal and mobile communication network, sending the de-identified prompt to the semantic parsing end. After receiving the anonymized prompt, the semantic parsing end analyzes its semantic intent as creating a calendar and generates a structured processing result based on the prompt requirements. This result directly reuses the replacement identifier from the anonymized information as parameter values. The processing result includes the intent identifier CREATE_CALENDAR and parameter fields: time slot TIME_SLOT_1, location slot LOC_POI_1, and title slot EVENT_CONTENT_1. The semantic parsing end returns the processing result to the in-vehicle interactive control system. The in-vehicle interactive control system can query the first mapping relationship through the secure application interface of the trusted execution environment, restoring TIME_SLOT_1 to the specific timestamp corresponding to 9:00 AM tomorrow, LOC_POI_1 to the First People's Hospital, and EVENT_CONTENT_1 to seeing a dentist, forming a complete calendar creation instruction. Finally, the in-vehicle interactive control system calls the system calendar service through the application programming interface of the in-vehicle operating system to write the restored complete instruction into the calendar database.After the interaction is completed, in response to the current session end event, the vehicle interaction control system will immediately perform a memory erase operation on the storage area storing the first mapping relationship in the trusted execution environment, clearing all data bits to zero.

[0109] In another specific embodiment, a vehicle is cruising at 120 km / h on a highway when a child inside the vehicle accidentally triggers the voice assistant, issuing a voice command to open all windows and the sunroof. The in-vehicle interactive control system obtains the semantic features corresponding to this request information and executes the corresponding processing flow based on the matching result of the semantic features and a preset command set. Ultimately, it parses the standardized operational intent as opening the windows, with the target being all windows and the sunroof, and the target opening degree being 100%. Before controlling the vehicle to perform the corresponding operation based on the restored processing result, the in-vehicle interactive control system obtains the vehicle speed signal from the chassis domain controller and the rain sensor signal from the body domain controller via a service-oriented protocol, obtaining the current vehicle speed as 120 km / h and the windshield wipers as not in operation. The in-vehicle interactive control system inputs the target control parameters indicated by the restored processing result and the current driving state parameters into the rule engine stored locally on the vehicle for safety verification. The rule engine stores deterministic rule entries based on physical safety boundaries, including the rule that when the vehicle speed is greater than 80 km / h, the maximum allowable opening degree of the windows and sunroof must not exceed 10%. After the rules engine performs rule matching based on the current vehicle speed of 120 km / h and the target sunroof opening degree of 100%, it determines that the target control parameter violates the aforementioned safety rules, and the safety verification fails. Therefore, the rules engine determines that the allowable range for the sunroof opening degree is no more than 10% based on the current driving status parameters. The in-vehicle interactive control system corrects the target control parameter from 100% to 10%, changing the sunroof from fully open to a ventilation mode. Finally, the in-vehicle interactive control system converts the corrected control parameter into a Controller Area Network (CAN) Flexible Data Rate Bus (FDNB) message and sends it to the body controller. The body controller then drives the sunroof actuator to open the sunroof to 10%. Simultaneously, the in-vehicle interactive control system can also announce a correction message via the in-vehicle voice synthesis device: "Vehicle speed is too high; for safety, ventilation mode has been activated for you."

[0110] The foregoing primarily describes the solutions of the embodiments of this disclosure from a methodological perspective. It is understood that, in order to achieve the aforementioned functions, the in-vehicle interactive control device includes at least one of the hardware structures and software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, in conjunction with the units and algorithm steps of the various examples described in the embodiments disclosed herein, the embodiments of this disclosure can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in a hardware-driven or software-driven manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments of this disclosure.

[0111] This disclosure embodiment can divide the vehicle interactive control device into functional modules according to the above method embodiment. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one functional module. The integrated module can be implemented in hardware or software. It should be noted that the module division in this disclosure embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods. The following description uses the example of dividing each functional module according to each function.

[0112] Figure 3 This is a schematic diagram of the structure of an in-vehicle interactive control device provided in an embodiment of this disclosure. This in-vehicle interactive control device can execute the in-vehicle interactive control method provided in the above-described method embodiments. Figure 3 As shown, the in-vehicle interactive control device 300 includes: an information desensitization module 301, a communication module 302, an information restoration module 303, and an execution module 304. The information desensitization module 301 replaces privacy entities in the user's request information to obtain desensitized information and a first mapping relationship. The privacy entity is an information entity of a preset privacy type. The desensitized information contains a substitution identifier, which has the same syntactic attributes as the privacy entity in the request information. The first mapping relationship represents the correspondence between the privacy entity and the substitution identifier. The communication module 302 sends the desensitized information to the semantic parsing terminal and receives the processing result returned by the semantic parsing terminal. The processing result contains the substitution identifier. The information restoration module 303 restores the substitution identifier in the processing result to a privacy entity according to the first mapping relationship. The execution module 304 controls the vehicle to perform corresponding operations based on the restored processing result.

[0113] When implementing the functions of the integrated modules described above in hardware, this disclosure provides a possible structure for the control device involved in the above embodiments. For example... Figure 4As shown, the control device 400 includes a processor 402 and a bus 404. Optionally, the control device may also include a memory 401; optionally, the control device 400 may also include a communication interface 403.

[0114] Processor 402 may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with embodiments of this disclosure. Processor 402 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with embodiments of this disclosure. Processor 402 may also be a combination of functions implementing computational capabilities, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0115] Communication interface 403 is used to connect to other devices via a communication network. This communication network can be Ethernet, wireless access network, wireless local area network (WLAN), etc.

[0116] The memory 401 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.

[0117] In one possible implementation, the memory 401 can exist independently of the processor 402. The memory 401 can be connected to the processor 402 via a bus 404 and is used to store instructions or program code. When the processor 402 calls and executes the instructions or program code stored in the memory 401, it can implement the vehicle interactive control method provided in this embodiment. In another possible implementation, the memory 401 can also be integrated with the processor 402.

[0118] Bus 404 can be an extended industry standard architecture (EISA) bus, etc. Bus 404 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 4 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0119] Some embodiments of this disclosure provide a computer-readable storage medium (e.g., a non-transitory computer-readable storage medium) storing computer program instructions that, when executed on a processor, cause the processor to perform the in-vehicle interactive control method as described in any of the above embodiments.

[0120] Exemplary examples of computer-readable storage media may include, but are not limited to: magnetic storage devices (e.g., hard disks, floppy disks, or magnetic tapes), optical discs (e.g., compact disks (CDs), digital versatile disks (DVDs), etc.), smart cards, and flash memory devices (e.g., erasable programmable read-only memory (EPROMs), cards, sticks, or key drives, etc.). The various computer-readable storage media described in this disclosure may represent one or more devices and / or other machine-readable storage media for storing information. The term "machine-readable storage medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing, and / or carrying instructions and / or data.

[0121] This disclosure provides a computer program product containing instructions that, when run on a processor, cause the processor to execute the in-vehicle interactive control method described in any of the above embodiments.

[0122] This disclosure provides a vehicle including the control device of any of the preceding embodiments; or the computer-readable storage medium of any of the preceding embodiments; or the computer program product of any of the preceding embodiments.

[0123] The vehicle provided in this application may be a passenger vehicle or a freight vehicle, and may also be an electric vehicle or a hybrid vehicle. This application does not limit the specific purpose or power type of the vehicle, and the choice can be made according to actual needs.

[0124] A vehicle consists of a body and wheels. The body is used for passengers and for carrying goods, while the wheels are mounted underneath the body to support it and allow it to roll on the road, thus enabling the vehicle to move.

[0125] In some possible examples, the vehicle is equipped with a control system, which typically adopts a layered distributed architecture. From the bottom layer to the top layer, it can be roughly divided into a perception layer, a control layer, a coordination layer, and an interaction layer. The layers communicate with each other through an in-vehicle network.

[0126] The perception layer mainly consists of various sensors distributed inside and outside the vehicle, including but not limited to external environment cameras, millimeter-wave radar, lidar, ultrasonic sensors, in-vehicle driver monitoring cameras, microphone arrays, and various vehicle status sensors (such as wheel speed sensors, inertial measurement units, temperature sensors, etc.). The perception layer is responsible for collecting multi-dimensional data such as the vehicle's own operating status, driver behavior, and external driving environment in real time.

[0127] The control layer consists of dozens to hundreds of electronic control units (ECUs), distributed across multiple functional domains including powertrain, chassis, body, intelligent driving, and infotainment. Each ECU embeds real-time control software that performs closed-loop control of the vehicle's actuators based on preset control strategies or upper-level commands, and generates corresponding alarm signals when abnormal conditions are detected. Typical ECUs include the engine control unit, transmission control unit, brake control unit, steering control unit, vehicle stability control unit, airbag control unit, intelligent driving domain controller, and in-vehicle infotainment unit.

[0128] The coordination layer typically exists in the form of a domain controller or a central computing platform, responsible for cross-domain data fusion, global state management, and collaborative decision-making. The coordination layer centrally processes and schedules the sensing data and control commands that were originally scattered across various functional domains, connecting downwards to various electronic control units and supporting human-machine interaction functions upwards.

[0129] The interaction layer mainly includes in-cabin display devices (such as instrument panel, central control screen, head-up display), voice interaction system, haptic feedback device, etc., which are responsible for presenting vehicle status, warning information and driving suggestions to the driver in the form of visual, auditory or tactile, while receiving the driver's touch, voice and other input commands.

[0130] Data transmission and interaction between different layers are achieved through the vehicle bus network. Common vehicle bus protocols include CAN (Controller Area Network), CAN FD (CAN with Flexible Data-Rate), LIN (Local Interconnect Network), FlexRay, and vehicle Ethernet, which supports high-bandwidth data transmission. Among these, CAN and CAN FD buses are widely used for communication in real-time control domains such as powertrain and chassis, while vehicle Ethernet is gradually being applied to high-bandwidth sensor data transmission in the intelligent driving domain and multimedia interaction scenarios in the cockpit domain.

[0131] In some possible examples, the intelligent driving domain controller, as the core of the in-vehicle computing platform, is equipped with a processor and memory to execute the in-vehicle interactive control method provided in the embodiments of this application.

[0132] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any changes or substitutions within the technical scope disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.

Claims

1. A vehicle-mounted interactive control method, characterized in that, The method includes: The privacy entity in the user's request information is replaced to obtain de-identified information and a first mapping relationship. The privacy entity is an information entity of a preset privacy type. The de-identified information contains a replacement identifier. The replacement identifier and the privacy entity have the same syntactic attributes in the request information. The first mapping relationship represents the correspondence between the privacy entity and the replacement identifier. Send the de-identified information to the semantic parsing terminal and receive the processing result returned by the semantic parsing terminal, wherein the processing result contains the replacement identifier; Based on the first mapping relationship, the alternative identifier in the processing result is restored to the privacy entity; Based on the restored processing results, control the vehicle to perform corresponding operations.

2. The method according to claim 1, characterized in that, The process of replacing privacy entities in the user's request information to obtain de-identified information and a first mapping relationship includes: Identify privacy entities in the user's request information; Based on the entity type of the privacy entity, the privacy entity is replaced with a corresponding alternative identifier to obtain de-identified information; The first mapping relationship is determined based on the correspondence between the privacy entity and the alternative identifier.

3. The method according to claim 1, characterized in that, The step of replacing privacy entities in the user's request information to obtain de-identified information and the first mapping relationship also includes: Identify privacy entities in the user's request information; The privacy entity is converted into a semantic vector, and perturbation noise is added to the semantic vector as a substitute identifier to obtain de-identified information; The first mapping relationship is determined based on the correspondence between the privacy entity and the alternative identifier.

4. The method according to claim 1, characterized in that, The step of replacing privacy entities in the user's request information to obtain de-identified information and the first mapping relationship also includes: Identify privacy entities in the user's request information; The privacy entity is encrypted, and the encrypted ciphertext fragment is used as a replacement identifier to obtain de-identified information; The first mapping relationship is determined based on the correspondence between the privacy entity and the alternative identifier.

5. The method according to claim 1, characterized in that, Before replacing the privacy entities in the user's request information to obtain the de-identified information and the first mapping relationship, the method further includes: Obtain the semantic features corresponding to the user's request information; Based on the matching result between the semantic features and the preset instruction set, the processing method of the request information is determined; When the processing method is local processing, the vehicle directly executes the vehicle control operation corresponding to the request information; When the processing method is privacy entity replacement processing, the step of replacing the privacy entity in the user's request information is performed.

6. The method according to claim 5, characterized in that, The step of determining the processing method for the request information based on the matching result between the semantic features and the preset instruction set includes: Determine the similarity between the semantic features and each instruction feature in the preset instruction set; If the maximum value of the similarity is greater than or equal to a preset threshold, the processing method is determined to be local processing; If the maximum value is less than the preset threshold, the processing method is determined to be privacy entity replacement processing.

7. The method according to claim 1, characterized in that, Before controlling the vehicle to perform corresponding operations based on the restored processing result, the method further includes: Obtain the vehicle's current driving status parameters; Based on the current driving status parameters, the restored processing result is subjected to a security verification. When the security check passes, the vehicle is controlled to perform corresponding operations based on the restored processing result; If the safety verification fails, the target control parameters indicated by the restored processing result are corrected according to the current driving state parameters in order to control the vehicle to perform the corresponding operation.

8. A vehicle-mounted interactive control device, characterized in that, The device includes: The information desensitization module is used to replace privacy entities in the user's request information to obtain desensitized information and a first mapping relationship. The privacy entity is an information entity of a preset privacy type. The desensitized information contains a replacement identifier. The replacement identifier and the privacy entity have the same syntactic attributes in the request information. The first mapping relationship represents the correspondence between the privacy entity and the replacement identifier. The communication module is used to send the de-identified information to the semantic parsing terminal and receive the processing result returned by the semantic parsing terminal, wherein the processing result contains the replacement identifier; The information restoration module is used to restore the substitute identifier in the processing result to the privacy entity according to the first mapping relationship; The execution module is used to control the vehicle to perform corresponding operations based on the restored processing results.

9. A control device, characterized in that, The control device includes: a memory and a processor; the memory and the processor are coupled; the memory is used to store instructions executable by the processor; when the processor executes the instructions, it performs the vehicle interactive control method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that, when executed on a processor, cause the processor to perform the vehicle interaction control method as described in any one of claims 1 to 7.

11. A computer program product, characterized in that, It includes a computer program; when the computer program is executed, it is able to implement the vehicle interactive control method as described in any one of claims 1 to 7.

12. A vehicle, characterized in that, It includes the control device as claimed in claim 9; or the computer-readable storage medium as claimed in claim 10; or the computer program product as claimed in claim 11.