Computing device for an automated vehicle
The computing device with an AI unit detects and responds to attacks on automatically operable vehicles, ensuring safety by identifying threats and implementing appropriate responses, thus maintaining operational readiness and safety.
Patent Information
- Application Number
- DE102021205292
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-05-25
- Publication Date
- 2025-10-09
- Estimated Expiration
- 2041-05-25
AI Technical Summary
Existing systems fail to effectively detect and respond to attacks on automatically operable vehicles, such as disruptions to environment recognition sensors, which can compromise the vehicle's ability to operate safely and autonomously.
A computing device with a computing module, including an artificial intelligence unit trained through machine learning, evaluates data from environment recognition sensors to identify attack patterns and risks, and determines appropriate responses such as cleaning, maneuvering, or alerting occupants to ensure the vehicle's safety.
The system enables reliable and efficient detection of attacks on automatically operable vehicles, maintaining their operational readiness and safety for both occupants and traffic.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a computing device for an automated vehicle for detecting attacks on the automated vehicle. Furthermore, the invention relates to a security system for an automated vehicle and to a corresponding automated vehicle. Furthermore, the invention also relates to a computer-implemented method for detecting attacks on an automated vehicle and to a corresponding computer program product.
[0002] Systems for detecting attacks on automated vehicles are known from the state of the art.
[0003] DE 10 2020 005 843 A1 describes a method for securing a vehicle's surroundings, a surroundings protection system, and a vehicle. DE 10 2019 209 291 A1 describes a method and a device for detecting contamination of at least one surroundings sensor of an autonomous vehicle.
[0004] A computing device for an automated vehicle is proposed for detecting attacks on the automated vehicle. The computing device comprises at least one first interface for receiving data from environment detection sensors of at least one environment detection device of the automated vehicle. The computing device comprises at least one computing module that is provided for evaluating the data in order to detect at least one attack pattern and / or attack risk, to determine at least one response depending on the detected attack pattern and / or attack risk, and to determine at least one control or regulating signal for the environment detection device and / or at least one vehicle control device of the automated vehicle in accordance with the determined response.The computing device comprises at least one second interface to provide the control or regulation signal to the environment recognition device and / or the vehicle control device.
[0005] An "automated vehicle" is understood to mean, in particular, a vehicle with one of the automation levels 1 to 5 of the SAE J3016 standard. In particular, the automated vehicle has technical equipment required for these automation levels. The technical equipment includes, in particular, the environment detection device with the environment detection sensors, such as radar sensors, lidar sensors, cameras and / or acoustic sensors, control units, or the like. The automated vehicle is preferably designed as a land vehicle. The automated vehicle can be designed, in particular, as a passenger car, preferably as a passenger transport vehicle, as a truck, as a construction vehicle, as an agricultural vehicle, or as another vehicle deemed appropriate by a person skilled in the art.The automated vehicle can alternatively be configured as an aircraft, for example, a drone, an airplane, a helicopter, a vertical takeoff and landing aircraft, or the like, or as a watercraft, for example, a ship, a submarine, or the like. "Intended" is understood to mean, in particular, being specially programmed, specially equipped, and / or specially designed. The fact that an object is intended for a function is understood to mean, in particular, that the object performs the function in at least one operating state.
[0006] In particular, a control unit, e.g. an electronic control unit, of the automated vehicle can comprise the computing device or at least partially form it. A control unit prepares data from sensors as input signals, processes them by means of the computing device, in particular by means of the computing module, e.g. a programmable logic module, an FPGA or ASIC module or a computer platform, and provides logic and / or power levels as a control or regulating signal. With the control or regulating signal, actuators for longitudinal and / or lateral guidance of the vehicle can be controlled or regulated, in particular via the second interface, in order to keep the vehicle in lane and / or to predict a trajectory. The control unit is preferably integrated into an on-board electrical system of the vehicle, e.g. into a CAN bus.The control unit is, for example, an electronic control unit for automated driving functions, referred to as a domain ECU. In particular, the control unit can be an ADAS (advanced driver assistance system) / AD (autonomous driving) domain ECU for assisted to fully automated, i.e., autonomous, driving.
[0007] The computing device, in particular the computing module, is implemented, for example, as a system-on-a-chip with a modular hardware concept, i.e., all or at least a large portion of functions are integrated on a single chip and can be expanded modularly. The chip can be integrated, in particular, into the control unit. The computing device, in particular the computing module, comprises, for example, a multi-core processor and memory modules. The multi-core processor is configured for signal / data exchange with storage media. For example, the multi-core processor comprises a bus system. The memory modules form a main memory. The memory modules are, for example, RAM, DRAM, SDRAM, or SRAM. In a multi-core processor, several cores are arranged on a single chip, i.e., a semiconductor component.Multi-core processors achieve higher computing power and are more cost-effective to implement on a single chip compared to multi-processor systems, where each individual core is located in a processor socket and the individual processor sockets are arranged on a motherboard. According to one aspect of the invention, the computing device, in particular the computing module, comprises at least one central processing unit (CPU).
[0008] The computing device, in particular the computing module, preferably also includes at least one graphics processor, referred to in English as a graphic processing unit (GPU). Graphics processors have a special microarchitecture for parallel processing of sequences. According to a further aspect of the invention, a classifier is provided using CUDA programming technology. Thus, software code sections of the classifier are processed directly by the GPU. Preferably, the computing device or the control unit is configured to be modularly expanded with several, for example, at least four, such chips.
[0009] An interface, in particular the first interface and the second interface of the computing device, is / are preferably provided for data exchange. In particular, the data exchange is designed as a signal transmission of a signal, in particular an electrical signal. The data exchange at the interfaces preferably takes place via a cable or wireless connection. The first interface is preferably provided to supply the computing module with data from the environment detection sensors connected to the computing module via the interface for data transmission purposes. The second interface is preferably provided to output signals determined by the computing module, in particular control or regulating signals. In particular, the second interface is provided to output the control or regulating signals to the environment detection device and / or the vehicle control device.In particular, the computing module is connected to the environment detection device and / or the vehicle control device via the second interface in terms of signal transmission.
[0010] The vehicle control device is preferably provided to control or regulate various functions of the automated vehicle, in particular at least partially autonomously. The vehicle control device preferably comprises at least one drive control unit, which is provided to control movement, in particular driving operation, of the automated vehicle. In particular, the drive control unit comprises actuators for longitudinal and lateral guidance of the automated vehicle. In particular, the actuators can be controlled by means of the control or regulating signals determined by the computing module. An actuator for lateral guidance can be designed, for example, as an electric motor of an electromechanical power steering system. The vehicle control device preferably comprises at least one alarm and / or emergency call unit, which is provided to output alarm signals.In particular, the alarm and / or emergency call unit can be controlled by means of the control or regulation signals determined by the computing module.
[0011] The environment detection device, in particular the environment detection sensors, is / are provided during normal operation, in particular during driving operation, of the automated vehicle, in particular for detecting the environment of the automated vehicle. Preferably, the environment detection device, in particular the environment detection sensors, is / are provided for detecting objects, in particular obstacles, in the environment of the automated vehicle. Preferably, the environment detection device comprises at least one environment detection central unit, which is provided for evaluating data generated by the environment detection sensors in order to enable at least partially autonomous control of the automated vehicle.The environment detection central unit is preferably provided to provide the vehicle control device with control or regulating signals for controlling the automatically operable vehicle depending on the evaluation. The environment detection central unit is preferably provided to forward the data from the environment detection sensors to the computing device. Alternatively, it is conceivable that the environment detection central unit is provided to at least pre-process the data for the computing device, or that the environment detection central unit comprises or at least partially forms the computing device. The environment detection device preferably comprises at least one cleaning unit which is provided to clean the environment detection sensors, for example from dirt, icing, or the like.
[0012] An "attack on the automated vehicle" is understood to mean, in particular, an attack on components of the automated vehicle, such as a body, tires, the environment detection device, or the like, on occupants of the automated vehicle, and / or on a load of the automated vehicle. An attack can, in particular, be in the form of vandalism, robbery, theft, kidnapping, injury to occupants, or the like. The computing device is preferably provided to detect attacks on the environment detection sensors of the environment detection device. An "attack on the environment detection device or on the environment detection sensors" is understood to mean, in particular, a targeted disruption or blocking of the environment detection sensors in order to restrict or completely prevent the function of the environment detection sensors.Optical environment detection sensors, such as cameras or lidars, can be attacked, in particular disrupted or blocked, in particular through deliberate contamination, covering, covering, or the like. Radar sensors can be attacked, in particular disrupted or blocked, in particular through deliberate metallic shielding, the use of decoys with metallic properties, or the like. Disturbed or blocked environment detection sensors, in particular, cannot provide the data necessary for at least partially autonomous driving. This has the particular consequence that the automated vehicle must stop or cannot start driving. An attack on the environment detection device of the automated vehicle can, in particular, prevent the automated vehicle from reaching a destination and / or facilitate theft, robbery, or the like of the automated vehicle.In a conventional vehicle with a driver, the driver could, in particular, detect an attack and respond to it. In an automated vehicle, designed, for example, as an autonomous shuttle, which is driverless and passengerless and is en route to a passenger pick-up point, taking a refueling break, or similar, an attack cannot be detected by a human. The computing device, in particular, enables automated detection of attacks on the automated vehicle.
[0013] The computing device is preferably designed to be operated while the automated vehicle is in motion, in particular to detect attacks on the automated vehicle. The computing device is preferably designed to be operated continuously or at predetermined intervals while the automated vehicle is stationary, in particular to detect attacks on the automated vehicle. The computing device can preferably supplement an alarm system and / or an anti-theft device of the automated vehicle, for example, be activated by them and / or provide supplementary data to them.
[0014] An "attack pattern" is understood in particular to mean a typical process before or during an attack on the automated vehicle. An attack pattern can, for example, be a disruption of several environment detection sensors, an approach of particularly suspicious, e.g. armed, persons to the automated vehicle, in particular to the environment detection sensors, a road blockade, or any other attack pattern that appears reasonable to an expert. An "attack risk" is understood in particular to mean a probability measure for an attack on the automated vehicle. For example, the attack risk may be higher in a quiet parked location than in moving traffic.Preferably, various attack patterns and / or attack risks can be stored in a memory unit of the computing device, and the computing module can be configured to select the most appropriate attack pattern and / or attack risk based on the evaluation of the data. Alternatively or additionally, it is conceivable that the computing module is trained using a machine learning method to recognize various attack patterns and / or attack risks based on the data from the environment detection sensors.
[0015] Preferably, the computing module can draw conclusions from available and / or determined information, in particular from different categories, and perform a corresponding criticality assessment. An environment category can, for example, include attack patterns and / or attack risks arising from the environment of the automated vehicle. For example, the computing module can, from the information that general possible attack patterns have been detected in the environment of the automated vehicle, conclude that a possible, but not specific, threat exists and assess the situation with a criticality value of 1.For example, based on the information that an attack pattern corresponding to potential attackers without a vehicle has been detected in the environment of the automated vehicle, the computing module can conclude that a potentially concrete threat with a fundamental chance of escape exists and assess the situation with a criticality value of 2. In particular, the higher the number of the criticality value, the higher the criticality. For example, based on the information that an attack pattern corresponding to potential attackers with a vehicle has been detected in the environment of the automated vehicle, the computing module can conclude that a potentially concrete threat with a limited chance of escape exists and assess the situation with a criticality value of 3.
[0016] A vehicle category can, for example, include information about a state of the automated vehicle. For example, the computing module can use the information that the automated vehicle is drivable without functional limitations to conclude that all vehicle-based options are available and assess the situation with a criticality value of 1. For example, the computing module can use the information that the automated vehicle has functional limitations to conclude that the limitation of vehicle-based options must be considered for possible responses and assess the situation with a criticality value of 2 to 3. Preferably, the computing module is designed to determine an overall threat to the automated vehicle, taking into account the criticality values of all categories.
[0017] Preferably, various responses to attack patterns and / or attack risks are stored in the memory unit of the computing device. In particular, the computing module is designed to determine the most appropriate response depending on the identified attack pattern and / or attack risk. A response can be configured, for example, as cleaning the environment detection sensors, performing a driving maneuver, issuing an alarm signal, or any other response deemed appropriate by a person skilled in the art. Depending on the identified attack pattern and / or attack risk, the computing module is designed, in particular, to determine a response to prevent and / or defend against an attack.
[0018] The most appropriate response may, in particular, be to prevent an active approach, for example because doing so would increase the danger to the occupants. Preferably, the computing module is designed to carry out a risk-benefit assessment of possible responses or combinations of responses depending on the determined attack pattern and / or attack risk and, if applicable, further information such as the number and / or health status of the occupants, location information and / or remaining range of the automated vehicle, or the like. In particular, the computing module is designed to determine, depending on the available information, a probability of success for possible responses or combinations of responses and a probability of new attack risks or dangers resulting from the possible responses or combinations of responses.Preferably, the calculation module is designed to consider the determined probability of success and the determined probability of new attack risks or hazards when determining the response or combination of responses. Preferably, the calculation module is designed to prioritize the safety of people, in particular the occupants, uninvolved third parties, and possibly an attacker, higher than the safety of the components or cargo of the automated vehicle.
[0019] In particular, different reactions can be carried out to achieve different goals. In particular, different reactions can be assigned different contraindications to be considered. The calculation module is preferably provided to consider at least one goal and / or at least one contraindication of a reaction when prioritizing a reaction. For example, a first reaction corresponding to leaving a location or replanning a route can have the goal of avoiding a risk, wherein a contraindication can be an automated vehicle that is not ready for operation or the lack of route alternatives. The calculation module can, for example, evaluate the first reaction with a prioritization value of 1.For example, a second reaction corresponding to initiating an escape may have the goal of escaping a likely or ongoing attack, whereby a contraindication may be an impossible or unpromising escape or an excessively great risk of being noticed during the escape. The calculation module may, for example, rate the second reaction with a prioritization value of 2. In particular, the smaller the number of the prioritization value, the more likely a reaction is to be prioritized. For example, a third reaction corresponding to requesting help or attracting attention may have the goal of requesting help when a likely or ongoing attack cannot be effectively countered using one's own resources, whereby a contraindication may be that necessary alarm and / or emergency call means are out of order or that there is a risk of attracting danger to oneself through the reaction.The calculation module can, for example, rate the third response with a prioritization value of 3 to 4. For example, a fourth response, corresponding to the initiation of defensive measures, can aim to independently repel an attack if this is the most sensible remaining option. A contraindication could be a risk of escalation that is too great compared to the potential benefit, or a disproportionate number of possible measures. The calculation module can, for example, rate the fourth response with a prioritization value of 3 to 4.
[0020] The inventive design of the computing device advantageously allows for the detection and response of attack patterns and / or attack risks with regard to an automated vehicle. This advantageously enables the automated vehicle to be permanently operational. This advantageously enables the automated vehicle to be roadworthy and safe for its occupants.
[0021] Furthermore, it is proposed that the computing module comprise at least one artificial intelligence unit to recognize the attack pattern and / or the attack risk. The artificial intelligence unit is trained, in particular by means of a machine learning method, to recognize attack patterns and / or attack risks based on the data from the environment detection sensors. Preferably, the artificial intelligence unit is designed to perform tensor and / or matrix multiplication. Tensor and / or matrix multiplication are the central computing operations for deep learning. In particular, the artificial intelligence unit has hardware accelerators for artificial intelligence, for example, so-called deep learning accelerators. Preferably, the computing module, in particular the artificial intelligence unit, executes program instructions to evaluate the data to recognize the attack patterns and / or attack risks.In particular, the program instructions include a machine learning algorithm trained to determine the attack pattern and / or attack risk from the received data. The machine learning algorithm is preferably implemented as an artificial neural network. Advantageously, attack patterns and / or attack risks can be determined particularly reliably and efficiently.
[0022] According to the invention, it is proposed that the computing module is provided to detect the attack pattern and / or the attack risk depending on a malfunction, in particular a failure, of a plurality of the environment detection sensors within a predetermined period of time. In particular, the computing module is provided to detect the attack pattern and / or the attack risk depending on a malfunction, in particular a failure, of at least 50% of the environment detection sensors, preferably of at least 75% of the environment detection sensors, and particularly preferably of all environment detection sensors within the predetermined period of time. Preferably, the computing module is provided to detect the attack pattern and / or the attack risk depending on malfunctions, in particular failures, of the environment detection sensors occurring consecutively within the predetermined period of time.Preferably, the computing module is designed to detect the attack pattern and / or the attack risk depending on at least substantially simultaneous disturbances, in particular failures, of the environment detection sensors. Advantageously, the computing module can assess a possible attack scenario.
[0023] It is further proposed that the computing module is provided to recognize the attack pattern and / or attack risk depending on at least one object detected in an environment of the automated vehicle. In particular, the computing module is provided to recognize the attack pattern and / or attack risk depending on a design and / or behavior of the object. The object can in particular be a person approaching the automated vehicle, in particular the environment recognition sensors, for example in order to tamper with them, an adhesive tape that could be stuck over the environment recognition sensors, a bucket of paint by means of which the environment recognition sensors, the bodywork, headlights or the like can be painted.could be contaminated, as an implausible and / or manipulated traffic sign and / or an implausible and / or manipulated traffic control system that could deceive the environment detection sensors, as an obstacle on a roadway that could damage the automated vehicle, in particular the environment detection sensors, as a weapon, in particular an unauthorized one, by means of which the automated vehicle, in particular the environment detection sensors, could be damaged, or the like. The object can in particular also be designed as a jammer, for example of another vehicle, which could emit light and / or radar interference to disrupt the environment detection sensors, for example by dazzling, changing a signal-to-noise ratio, oversaturating, deceiving, or the like.In particular, the computing module can be designed to detect interference based on the data analysis. Advantageously, the computing module can assess another possible attack scenario.
[0024] It is also proposed that the computing module be designed to detect the attack pattern and / or attack risk depending on at least one environmental condition and / or at least one vehicle state of the automated vehicle. The environmental condition can be configured, in particular, as a location of the automated vehicle, a time of day, a season, weather, lighting of the surroundings of the automated vehicle, or the like. An environmental condition can also be derived, for example, from risk data from the media and / or police reports, data regarding regionally known risks, for example, from at least one database, or the like.The vehicle state can be configured in particular as a movement situation of the automated vehicle, as a tank state of the automated vehicle, as a malfunction of at least one component of the automated vehicle, or the like. The movement situation can be configured in particular as movement, in particular at a certain speed, or as a standstill. In particular, the computing module is provided to estimate the risk of attack to be higher when the automated vehicle is at a standstill than when it is moving. In particular, the computing module is provided to estimate the risk of attack to be higher at isolated locations, in dark locations, at locations free of possible witnesses, or the like than at busy locations, in brightly lit locations, or the like.Preferably, the computing module can be configured to detect the attack pattern and / or attack risk depending on a combination of various scenarios described above. Advantageously, the computing module can assess an additional possible attack scenario.
[0025] Furthermore, it is proposed that the computing module is provided to determine at least one cleaning of the environment detection sensors depending on the detected attack pattern and / or attack risk. In particular, the computing module is provided to determine a necessity and / or extent of cleaning of the environment detection sensors depending on the detected attack pattern and / or attack risk. Preferably, the computing module is provided to determine the cleaning of the environment detection sensors, in particular to the determined extent of cleaning, depending on the determined necessity of cleaning. In particular, the computing module is provided to determine a control or regulating signal corresponding to cleaning of the environment detection sensors.In particular, the computing module is designed to control the cleaning unit of the environment detection device depending on the detected attack pattern and / or attack risk. Preferably, the computing module is designed to determine whether to perform a cleaning of at least the blocked environment detection sensor or all environment detection sensors depending on a detected optical blockage of at least one environment detection sensor. A possible reaction can advantageously be determined.
[0026] It is further proposed that the computing module be provided to determine at least one execution of a driving maneuver depending on the detected attack pattern and / or attack risk. In particular, the computing module is provided to determine a control or regulating signal corresponding to the execution of a driving maneuver. In particular, the computing module is provided to control the driving control unit of the vehicle control device depending on the detected attack pattern and / or attack risk. The driving maneuver can be designed in particular as an evasive maneuver, an acceleration maneuver, a braking maneuver, a driving off, a route change, or another driving maneuver that appears sensible to a person skilled in the art. In particular, the computing module can also be provided to determine boundary conditions of the driving maneuver.For example, it may be useful to switch off vehicle lights during an escape at night, depending on a detected highly threatening attack pattern, to make it more difficult to fire on the vehicle when the automated vehicle is dark. In particular, many environment detection sensors, which operate in radiation frequency ranges different from vehicle lighting, e.g., with infrared radiation, radar radiation, or similar, do not require headlights. This can advantageously determine another possible response.
[0027] It is further proposed that the computing module is provided to determine at least one output of an alarm signal depending on the detected attack pattern and / or attack risk. In particular, the computing module is provided to determine a control or regulating signal corresponding to an output of an alarm signal. In particular, the computing module is provided to control the alarm and / or emergency call unit of the vehicle control device depending on the detected attack pattern and / or attack risk. The alarm signal can be designed in particular as an acoustic alarm signal, for example a horn, as an optical alarm signal, for example hazard warning lights, as an emergency call or as another alarm signal that appears appropriate to a person skilled in the art. In particular, the computing module can be provided to determine an output of a plurality of, in particular different, alarm signals.Preferably, the computing module can be provided to determine a combination of various of the reactions described above depending on the detected attack pattern and / or attack risk.
[0028] Alternatively or additionally, it is conceivable that the computing module is provided to determine the output of an alarm signal in order to communicate with at least one occupant. In particular, the alarm signal can be output via a human-machine interface (HMI) of the alarm and / or emergency call unit. The human-machine interface can be designed, for example, as a screen, a loudspeaker, or the like. Preferably, the alarm signal, in particular in addition to information about a possible threat, can include a request to the occupant regarding a course of action. The request can, in particular, be designed as a decision question, for example whether a safer route should be chosen, as an alternative question, for example whether escape should be attempted or abandoned, or as an open question. For example, a silent emergency call can be made at the same time.Preferably, the occupant can specify a procedure to the computing module via the human-machine interface and / or override a procedure of the computing module, for example, via gesture control, keystrokes, touch-sensitive input, and / or voice control. For example, it is conceivable that the occupant aborts the vehicle's defensive or escape measures if they believe this could lead to a knee-jerk reaction from an attacker. In particular, it can be provided that, by default, a query is sent to the occupant before cleaning the environment detection sensors and / or performing a driving maneuver. Advantageously, an additional possible reaction can be determined.
[0029] Furthermore, a security system for an automated vehicle is proposed. The security system comprises at least one computing device according to the invention. The security system comprises at least one environment detection device, in particular the aforementioned one. The security system can preferably comprise further sensors designed to provide the computing device with data for detecting attack patterns and / or attack risks. The further sensors can be designed, for example, as vibration sensors, attitude sensors, acceleration sensors, position sensors, temperature sensors, or the like. The security system can preferably comprise at least one communication unit designed to provide the computing device with data for detecting attack patterns and / or attack risks.In particular, the communication unit can be designed to provide the computing device with risk data from media and / or police reports, data regarding regionally known risks, for example, from at least one database, and / or other data deemed appropriate by a specialist. Advantageously, a safety system can be provided that enables the roadworthy and occupant-safe operation of an automated vehicle.
[0030] Furthermore, an automated vehicle is proposed. The automated vehicle comprises at least one, in particular the aforementioned, environment detection device. The automated vehicle comprises at least one, in particular the aforementioned, vehicle control device. The automated vehicle comprises at least one, in particular the aforementioned, computing device for detecting attacks on the automated vehicle. The computing device has at least one, in particular the aforementioned, first interface for receiving data from environment detection sensors of the environment detection device.The computing device has at least one computing module, in particular the aforementioned one, which is intended to evaluate the data in order to recognize at least one attack pattern and / or attack risk, to determine at least one reaction depending on the recognized attack pattern and / or attack risk, and to determine at least one control or regulating signal for the environment detection device and / or the vehicle control device in accordance with the determined reaction. The computing device has at least one interface, in particular the aforementioned second interface, in order to provide the control or regulating signal to the environment detection device and / or the vehicle control device. The computing module is intended to recognize the attack pattern and / or the attack risk depending on a malfunction of a plurality of the environment detection sensors within a predetermined period of time.Advantageously, a roadworthy and passenger-safe automated vehicle can be provided.
[0031] Furthermore, a computer-implemented method for detecting attacks on an automated vehicle is proposed. In the method, received data is evaluated to detect at least one attack pattern and / or attack risk. At least one response is determined depending on the detected attack pattern and / or attack risk. In accordance with the determined response, at least one control or regulating signal is determined for at least one environment detection device and / or at least one vehicle control device of the automated vehicle. The control or regulating signal is provided to the environment detection device and / or the vehicle control device. The attack pattern and / or the attack risk is detected depending on a malfunction of a plurality of the environment detection sensors within a predetermined period of time.Advantageously, a method can be provided which enables traffic- and passenger-safe operation of the automated vehicle.
[0032] Furthermore, a computer program product for detecting attacks on an automated vehicle is proposed. The computer program product comprises execution instructions that, when executed by a computing device according to the invention, cause the device to execute a method according to the invention. Advantageously, a computer program product can be provided that enables roadworthy and occupant-safe operation of the automated vehicle.
[0033] The invention is illustrated by an exemplary embodiment in the following figures. They show: Fig. 1 shows a schematic representation of an automated vehicle according to the invention in an environment, Fig. 2 a block diagram of the automated vehicle according to the invention from Fig. 1 in a schematic representation, Fig. 3 a computing device according to the invention of the automated vehicle according to the invention from Fig. 1 in a schematic representation, Fig. 4 a flowchart of a computer-implemented method according to the invention in a schematic representation, Fig. 5 a flowchart of a first part of the computer-implemented method according to the invention from Fig. 4 in a schematic representation, Fig. 6 a flowchart of a second part of the computer-implemented method according to the invention from Fig. 4 in a schematic representation, Fig. 7 is a flowchart of a third part of the computer-implemented method according to the invention Fig. 4 in a schematic representation and Fig. 8 is a flowchart of a fourth part of the computer-implemented method according to the invention Fig. 4 in a schematic representation.
[0034] Fig. 1 shows an automated vehicle 2 in an environment 12 in a schematic representation. The automated vehicle 2 is embodied, for example, as a land vehicle, in particular as a passenger car. The automated vehicle 2 has at least one vehicle control device 9. The automated vehicle 2 comprises a security system 15. The security system 15 comprises at least one environment recognition device 3. The security system 15 comprises at least one computing device 1. The computing device 1 is provided for detecting attacks on the automated vehicle 2. The computing device 1 comprises at least a first interface 4 for receiving data from environment recognition sensors 5, 6, 7 of the environment recognition device 3 (cf. Fig. 3). In the present exemplary embodiment, the environment detection device 3 comprises, for example, three environment detection sensors 5, 6, 7. A first environment detection sensor 5 is embodied, for example, as a camera, a second environment detection sensor 6 is embodied, for example, as a lidar, and a third environment detection sensor 7 is embodied, for example, as a radar. The computing device 1 comprises at least one computing module 8, which is provided to evaluate the data in order to detect at least one attack pattern and / or attack risk, to determine at least one reaction depending on the detected attack pattern and / or attack risk, and to determine at least one control or regulating signal for the environment detection device 3 and / or the vehicle control device 9 in accordance with the determined reaction (cf. Fig. 2 and Fig. 3). The computing device 1 comprises at least one second interface 10 in order to provide the control or regulating signal to the environment detection device 3 and / or the vehicle control device 9 (cf. Fig. 3).
[0035] In Fig. 1 shows an object 13 and another object 14. The object 13 is designed as a person. The other object 14 is designed as a bucket of paint. The object 13 could, in particular by means of the other object 14, attack the automated vehicle 2, in particular the environment detection sensors 5, 6, 7. In particular, the object 13 could block at least the first environment detection sensor 5 and the second environment detection sensor 6 with the paint.
[0036] Fig. 2 shows a block diagram of the automated vehicle 2 from Fig. 1 in a schematic representation. The vehicle control device 9 is intended to control or regulate various functions of the automated vehicle 2, in particular at least partially autonomously. The vehicle control device 9 comprises at least one driving control unit 16, which is intended to control movement, in particular driving operation, of the automated vehicle 2. The vehicle control device 9 comprises at least one alarm unit 17, which is intended to output alarm signals. The vehicle control device 9 comprises at least one emergency call unit 18, which is intended to make emergency calls.
[0037] The environment recognition device 3 comprises at least one environment recognition central unit 19, which is intended to evaluate data generated by the environment recognition sensors 5, 6, 7 during normal operation, in particular during color operation, of the automated vehicle 2 in order to enable at least partially autonomous control of the automated vehicle 2. The environment recognition central unit 19 is intended to forward the data from the environment recognition sensors 5, 6, 7 to the computing device 1. Alternatively, it is conceivable that the environment recognition central unit 19 is intended to at least preprocess the data for the computing device 1, or that the environment recognition central unit 19 comprises or at least partially forms the computing device 1.The environment detection device 3 comprises at least one cleaning unit 20, which is intended to clean the environment detection sensors 5, 6, 7, for example, from dirt, icing, or the like. The cleaning unit 20 is connected to the computing device 1 via the environment detection central unit 19 for signal transmission. The computing device 1 is connected to the environment detection central unit 19, to the driving control unit 16, to the alarm unit 17, and to the emergency call unit 18 for signal transmission.
[0038] The computing device 1 is intended to be operated while the automated vehicle 2 is in operation, in particular to detect attacks on the automated vehicle 2. The computing device 1 is intended to be operated continuously or at predetermined intervals while the automated vehicle 2 is stationary, in particular to detect attacks on the automated vehicle 2. The computing device 1 can supplement an alarm system and / or an anti-theft device of the automated vehicle 2, for example, can be activated by them and / or can provide them with supplementary data (not shown here).
[0039] Fig. 3 shows the computing device 1 of the automated vehicle 2 from Fig. 1 in a schematic representation. The computing module 8 comprises at least one artificial intelligence unit 11 to detect the attack pattern and / or the attack risk.
[0040] The computing module 8 is designed to detect the attack pattern and / or the attack risk depending on a malfunction, in particular a failure, of a plurality of the environment detection sensors 5, 6, 7 within a predetermined period of time. For example, at least the first environment detection sensor 5 and the second environment detection sensor 6 can be disturbed by the object 13 using the color.
[0041] The computing module 8 is provided to detect the attack pattern and / or the attack risk depending on at least one object 13, 14 detected in the environment 12 of the automated vehicle 2. In the present exemplary embodiment, the computing module 8 is provided, for example, to detect the attack pattern and / or the attack risk depending on the object 13 and the further object 14.
[0042] The computing module 8 is provided to recognize the attack pattern and / or attack risk depending on at least one environmental condition and / or at least one vehicle state of the automated vehicle 2. In the present exemplary embodiment, the automated vehicle 2 is, for example, stationary, which can mean a higher risk of attack than when the automated vehicle 2 is moving. In the present exemplary embodiment, the automated vehicle 2 is, for example, at an isolated location where no witnesses are present except for the object 13 identifiable as a possible attacker. In the present exemplary embodiment, the computing module 8 can estimate the risk of attack to be higher than, for example, at a busy location.
[0043] The computing module 8 is provided to determine at least one cleaning of the environment detection sensors 5, 6, 7 depending on the detected attack pattern and / or attack risk. The computing module 8 is provided to control the cleaning unit 20 of the environment detection device 3 depending on the detected attack pattern and / or attack risk. For example, in the present exemplary embodiment, the environment detection sensors 5, 6, 7, in particular the first environment detection sensor 5 and the second environment detection sensor 6, can be smeared with paint and blocked by the object 13. For example, the paint can be removed from the environment detection sensors 5, 6, 7 using the cleaning unit 20, such as cleaning nozzles.
[0044] The computing module 8 is designed to determine at least one driving maneuver to be executed based on the detected attack pattern and / or attack risk. The computing module 8 is designed to control the driving control unit 16 of the vehicle control device 9 based on the detected attack pattern and / or attack risk. For example, in the present exemplary embodiment, the automated vehicle 2 can start driving in order to move out of range of the objects 13, 14.
[0045] The computing module 8 is designed to determine at least one output of an alarm signal depending on the detected attack pattern and / or attack risk. The computing module 8 is designed to control the alarm unit 17 and / or the emergency call unit 18 of the vehicle control device 9 depending on the detected attack pattern and / or attack risk. In the present exemplary embodiment, for example, an acoustic and / or visual alarm signal could be output to drive away the object 13, and an emergency call could be made to notify the police.
[0046] Fig. Figure 4 shows a flowchart of a computer-implemented method for detecting attacks on the automated vehicle 2, in a schematic representation. The method is preferably repeated cyclically. Preferably, the method is part of a cyclical environment detection and trip planning and / or control of the automated vehicle 2.
[0047] The method is started in a first method step 21. Data is recorded in a second method step 22. At least one attack pattern and / or attack risk is determined and assessed in a third method step 23. A fourth method step 24 checks whether at least one acute attack pattern and / or attack risk exists. If no acute attack pattern and / or attack risk exists, a fifth method step 25 checks whether future attack risks exist. If at least one acute attack pattern and / or attack risk exists, at least one reaction to the acute attack pattern and / or attack risk is determined in a sixth method step 26 before the fifth method step 25. If no future attack risk exists, the method is terminated in a seventh method step 27.If at least one future risk of attack exists, prevention measures regarding the future risk of attack are carried out in an eighth method step 28 before the seventh method step 27. After the seventh method step 27, the first method step 21 can be started again. The second method step 22, the third method step 23, the sixth method step 26, and the eighth method step 28 comprise sub-method steps that are described in the following figures.
[0048] Fig. 5 shows a flowchart of a first part of the computer-implemented method of Fig. 4 in a schematic representation. The sub-process steps of the second process step 22 are shown. In a first sub-process step 29 of the second process step 22, data acquisition is started. In a second sub-process step 30 of the second process step 22, data is received from the environment detection sensors 5, 6, 7 of the environment detection device 3. In a third sub-process step 31 of the second process step 22, a state of the automated vehicle 2 is determined. In a fourth sub-process step 32 of the second process step 22, the received data is evaluated in order to identify at least one attack pattern and / or attack risk. In a fifth sub-process step 33 of the second process step 22, data acquisition is terminated.
[0049] Fig. 6 shows a flowchart of a second part of the computer-implemented method of Fig. 4 in a schematic representation. The sub-process steps of the third process step 23 are shown. In a first sub-process step 34 of the third process step 23, the determination and assessment of at least one attack pattern and / or attack risk is started. In a second sub-process step 35 of the third process step 23, it is checked whether at least one, in particular significant, attack pattern and / or attack risk is present in the environment of the automated vehicle 2. If no, in particular significant, attack pattern and / or attack risk is present in the environment of the automated vehicle 2, a third sub-process step 36 of the third process step 23 checks whether at least one, in particular significant, attack pattern and / or attack risk is present for journey planning.If at least one, in particular significant, attack pattern and / or attack risk is present in the environment of the automated vehicle 2, at least one best response to the, in particular acute, attack pattern and / or attack risk is determined in a fourth sub-step 37 of the third method step 23 prior to the third sub-step 36 of the third method step 23. If no, in particular significant, attack pattern and / or attack risk is present for the trip planning, a determined action plan is output to at least one occupant of the automated vehicle 2 in a, in particular optional, fifth sub-step 38 of the third method step 23.If at least one, particularly significant, attack pattern and / or attack risk exists for the journey planning, at least one best option for risk minimization is determined in a sixth sub-step 39 of the third method step 23 before the fifth sub-step 38 of the third method step 23. The determination and assessment of at least one attack pattern and / or attack risk is terminated in a seventh sub-step 40 of the third method step 23.
[0050] Fig. Figure 7 shows a flowchart of a third part of the computer-implemented method of Fig. 4 in a schematic representation. The sub-process steps of the sixth process step 26 are shown. In a first sub-process step 41 of the sixth process step 26, the determination of the reaction to the acute attack pattern and / or attack risk is started. In a second sub-process step 42 of the sixth process step 26, it is checked whether an override by the occupant has occurred. If an override by the occupant has occurred, the determination of the reaction to the acute attack pattern and / or attack risk is terminated in a third sub-process step 43 of the sixth process step 26.If there is no override by the occupant, before the third sub-process step 43 of the sixth process step 26, in a fourth sub-process step 44 of the sixth process step 26, at least one control or regulating signal for the surroundings detection device 3 and / or the vehicle control device 9 is determined in accordance with the determined best reaction and is provided to the surroundings detection device 3 and / or the vehicle control device 9.
[0051] Fig. Figure 8 shows a flowchart of a fourth part of the computer-implemented method of Fig.4 in a schematic representation. Shown are the sub-process steps of the eighth process step 28. In a first sub-process step 45 of the eighth process step 28, prevention of the future risk of attack is initiated. In a second sub-process step 46 of the eighth process step 28, it is checked whether an override by the occupant has occurred. If an override by the occupant has occurred, prevention of the future risk of attack is terminated in a third sub-process step 47 of the eighth process step 28.If there is no override by the occupant, in a fourth sub-step 48 of the eighth method step 28, prior to the third sub-step 47 of the eighth method step 28, at least one control or regulating signal for the surroundings detection device 3 and / or the vehicle control device 9 is determined according to the determined best response and provided to the surroundings detection device 3 and / or the vehicle control device 9. In particular, the route planning is intervened in.
[0052] A computer program product for detecting attacks on the automated vehicle 2 comprises execution instructions which, when the program is executed by the computing device 1, cause the computing device 1 to execute the method. Reference symbol 1 computing device 2 vehicles 3 Environment detection device 4 Interface 5 Environment detection sensor 6 Environment detection sensor 7 Environment detection sensor 8 Calculation module 9 Vehicle control device 10 Interface 11 Artificial Intelligence Unit 12 Environment 13 objects 14 objects 15 Security system 16 Driving control unit 17 Alarm unit 18 Emergency call unit 19 Environment detection central unit 20 cleaning units 21 Process step 22 Process step 23 Process step 24 process steps 25 process steps 26 Process step 27 Process step 28 Process step 29 Sub-process step 30 Sub-process step 31 Sub-process step 32 Sub-process step 33 Sub-process step 34 Sub-process step 35 Sub-process step 36 Sub-process step 37 Sub-process step 38 Sub-process step 39 Sub-process step 40 Sub-process step 41 Sub-process step 42 Sub-process step 43 Sub-process step 44 Sub-process step 45 Sub-process step 46 Sub-process step 47 Sub-process step 48 Sub-process step
Claims
[1] Computing device for an automated vehicle (2) for detecting attacks on the automated vehicle (2), comprising at least one first interface (4) for receiving data from environment detection sensors (5, 6, 7) of at least one environment detection device (3) of the automated vehicle (2), at least one computing module (8) which is provided for evaluating the data in order to detect at least one attack pattern and / or attack risk, to determine at least one reaction depending on the detected attack pattern and / or attack risk, and to determine at least one control or regulating signal for the environment detection device (3) and / or at least one vehicle control device (9) of the automated vehicle (2) in accordance with the determined reaction, and comprising at least one second interface (10),to provide the control or regulating signal to the environment detection device (3) and / or the vehicle control device (9), wherein the computing module (8) is provided to detect the attack pattern and / or the attack risk as a function of a disturbance of a plurality of the environment detection sensors (5, 6, 7) within a predetermined period of time. [2] Computing device according to claim 1, wherein the computing module (8) comprises at least one artificial intelligence unit (11) to detect the attack pattern and / or the attack risk. [3] Computing device according to one of the preceding claims, wherein the computing module (8) is provided to detect the attack pattern and / or attack risk as a function of at least one object (13, 14) detected in an environment (12) of the automated vehicle (2). [4] Computing device according to one of the preceding claims, wherein the computing module (8) is provided to detect the attack pattern and / or attack risk as a function of at least one environmental condition and / or at least one vehicle state of the automated vehicle (2). [5] Computing device according to one of the preceding claims, wherein the computing module (8) is provided to determine at least one cleaning of the environment detection sensors (5, 6, 7) depending on the detected attack pattern and / or attack risk. [6] Computing device according to one of the preceding claims, wherein the computing module (8) is provided to determine at least one execution of a driving maneuver depending on the recognized attack pattern and / or attack risk. [7] Computing device according to one of the preceding claims, wherein the computing module (8) is provided to determine at least one output of an alarm signal depending on the detected attack pattern and / or attack risk. [8] Safety system for an automated vehicle (2), comprising at least one computing device (1) according to one of the preceding claims and at least one environment recognition device (3). [9] An automated vehicle comprising at least one environment recognition device (3), at least one vehicle control device (9), and at least one computing device (1) for detecting attacks on the automated vehicle, wherein the computing device (1) has at least one first interface (4) for receiving data from environment recognition sensors (5, 6, 7) of the environment recognition device (3), has at least one computing module (8) designed to evaluate the data in order to detect at least one attack pattern and / or attack risk, to determine at least one reaction depending on the detected attack pattern and / or attack risk, and to determine at least one control or regulating signal for the environment recognition device (3) and / or the vehicle control device (9) in accordance with the determined reaction, and has at least one second interface (10),to provide the control or regulating signal to the environment detection device (3) and / or the vehicle control device (9), wherein the computing module (8) is provided to detect the attack pattern and / or the attack risk as a function of a disturbance of a plurality of the environment detection sensors (5, 6, 7) within a predetermined period of time. [10] Computer-implemented method for detecting attacks on an automated vehicle (2), wherein received data is evaluated in order to detect at least one attack pattern and / or attack risk, wherein at least one reaction is determined as a function of the detected attack pattern and / or attack risk and, in accordance with the determined reaction, at least one control or regulating signal is determined for at least one environment detection device (3) and / or at least one vehicle control device (9) of the automated vehicle (2), and wherein the control or regulating signal is provided to the environment detection device (3) and / or the vehicle control device (9), wherein the attack pattern and / or the attack risk is detected as a function of a malfunction of a plurality of the environment detection sensors (5, 6, 7) within a predetermined period of time. [11] Computer program product for detecting attacks on an automated vehicle (2), comprising execution instructions which, when the program is executed by a computing device (1) according to one of claims 1 to 7, cause the computing device (1) to execute a method according to claim 10.
Citation Information
Patent Citations
Method and device for detecting contamination of at least one environmental sensor of an autonomous vehicle
DE102019209291A1
Procedures for securing a vehicle's surroundings, environmental protection system and vehicle
DE102020005843A1