Computer-implemented method for identifying erratic system behavior of a vehicle and information technology system
The method employs a machine learning model to compare actual and artificially generated time series data from vehicles, effectively detecting unauthorized manipulations and ensuring vehicle safety and compliance.
Patent Information
- Application Number
- DE102024001754
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-05-31
- Publication Date
- 2025-05-15
- Estimated Expiration
- 2044-05-31
AI Technical Summary
Existing technologies lack a reliable method to detect unauthorized manipulations of vehicle system technology, which can lead to erratic system behavior, safety risks, and non-compliance with vehicle specifications.
A computer-implemented method using a machine learning model to identify erratic system behavior by recording and processing time series data from test and fleet vehicles, training the model to generate artificial data, and comparing it with actual data to detect deviations.
The method effectively identifies erratic system behaviors indicative of unauthorized manipulations, allowing for timely countermeasures to ensure vehicle safety and compliance.
Smart Images

Figure 00000009_0000 
Figure 00000009_0001 
Figure 00000009_0002
Abstract
Description
[0001] The invention relates to a computer-implemented method for identifying an erratic system behavior of a vehicle by means of a machine learning model and to an information technology system for carrying out the method.
[0002] Software-based technology in vehicles can become the target of hacker attacks or manipulation. For example, so-called chip tuning or vehicle coding can be carried out, which fundamentally intervenes in the vehicle's system technology. This can increase performance or reduce fuel consumption. However, chip tuning can lead to the vehicle no longer complying with vehicle specifications or certifications no longer being met. In the worst case, the vehicle can even be damaged and become a safety risk. Such manipulation can also damage other vehicle components, such as control units connected to a manipulated processing unit. It is therefore desirable to be able to detect such manipulation of the vehicle's system technology.
[0003] A device for detecting engine tuning in a vehicle is known from KR 102356315 B1. Using suitable sensors, various parameters, such as the engine's intake pressure, are monitored. It is then checked whether these parameters correspond to standard values. If deviations occur, engine tuning is detected. The disadvantage of this is that dedicated components for detecting engine tuning must be installed in the vehicle.
[0004] WO 2016 / 046819 A1 also describes a method for detecting cyber attacks in vehicles.
[0005] Furthermore, DE 10 2021 208 988 A1 discloses the detection of malfunctions in a vehicle based on the use of artificial intelligence. With the help of suitable environmental sensors, such as cameras or laser scanners, objects in the vehicle's surroundings are detected and classified. Object attributes are assigned to corresponding objects. Information about the objects and object attributes, as well as their temporal behavior, is transferred to an artificial machine learning system for training, enabling the learning system to learn typical behavior of the objects. This makes it possible to identify malfunctions of the corresponding sensor-based object recognition using the artificial machine learning system.
[0006] The object of the present invention is to provide means by which it is possible to reliably detect manipulations of the system technology in the vehicle.
[0007] According to the invention, this object is achieved by a computer-implemented method for identifying erratic system behavior of a vehicle using a machine learning model having the features of claim 1. Advantageous embodiments and further developments as well as an information technology system suitable for carrying out the method emerge from the dependent claims.
[0008] A generic computer-implemented method for identifying an erratic system behavior of a vehicle using a machine learning model is further developed according to the invention by the following method steps: - Recording the signals transmitted during operation of a test vehicle via a fieldbus of the test vehicle and / or processed by a computing unit in the test vehicle in the form of initial time series data; - training a machine learning model with the first time series data so that the machine learning model is able to artificially generate time series for the signals comprised by the first time series data while maintaining a specified tolerance level; - Generating artificial time series data by the machine learning model, comprising time series of the signals artificially generated by the machine learning model; - Recording the signals transmitted during operation of a fleet vehicle via a fieldbus of the fleet vehicle and / or processed by a computing unit in the fleet vehicle in the form of second time series data; - Transferring the second time series data from the fleet vehicle to a central computing device; - comparing the artificial time series data with the second time series data, by the central computing device; and - issuing a warning signal by the central computing device if the artificial time series data and the second time series data differ from each other by more than a specified deviation measure.
[0009] The method according to the invention allows for the identification of erratic system behavior in a vehicle through the use of algorithms based on artificial intelligence. Such erratic system behavior can indicate unauthorized manipulation of the vehicle's system technology. Countermeasures can be initiated accordingly. This allows the reliable operation of the vehicle to be maintained and road safety to be safeguarded.
[0010] The test vehicle can be used to generate the initial time series data. This initial time series data can be used to describe the typical system behavior of a vehicle. The signals transmitted and / or processed by the vehicle can be of a diverse nature.For example, these include signals from a wide variety of sensors, such as temperature values, mileage, speed information, traction battery charge level, volume flow, mass flow, engine speed, acceleration value, steering angle, engine performance data, engine consumption data, status information from a vehicle control unit, route information from a navigation system, information from the vehicle's infotainment system such as the selected radio station, information derived from a vehicle occupant's voice input, the active driving program in the vehicle, states of actuators such as the vehicle's brake or accelerator pedal, and the like. The signals can be tapped via the respective fieldbus and / or read from a computing unit in the vehicle.The vehicle can have various fieldbus systems as a fieldbus, such as CAN, Flex-Ray, LIN, Byteflight, Ethernet and the like.
[0011] The respective signals are aggregated over time, creating time series. The time series of the signals are then combined to form the first time series data. This first time series data is used as training data for the machine learning model. The machine learning model can be trained both in the vehicle and externally, in particular also on the aforementioned central computing device.
[0012] By training the machine learning model, it is enabled to recognize patterns in the time series of signals, which ultimately allows the machine learning model to generate corresponding time series itself. The machine learning model is trained until the time series artificially generated by the machine learning model match the time series of signals actually recorded in the test vehicle within the specified tolerance level. The tolerance level can be specified by the vehicle manufacturer, for example. Signals can differ in two different ways. Firstly, a certain signal can have a different magnitude for the same point in time. It is also possible that a characteristic value of a signal is present in the initial time series data and the artificial time series data at different points in time.This can result in a temporal difference as well as a difference in the magnitude of a respective value of a particular signal. A signal-specific tolerance value is then defined for both types of deviation.
[0013] After the machine learning model has been sufficiently trained, it is used to generate corresponding artificial time series data. This artificial time series data then serves as a reference for comparison with corresponding second time series data generated in the fleet vehicle. The computer-implemented process is then used to check the system behavior of the fleet vehicle. For this purpose, the central computing device compares the artificial time series data with the second time series data. Proven methods for data comparison can be used for this purpose. In particular, artificial intelligence can also be used for this purpose. In particular, this comparison not only checks for overlaps between the respective signal time series curves, but also the respective dependencies between the various signals. For example, a fully depressed accelerator pedal can lead to a typical longitudinal acceleration value.This longitudinal acceleration value then becomes established after a characteristic period of time. If the fleet vehicle exhibits erratic system behavior, this longitudinal acceleration value may, for example, be higher or lower and / or occur after a shorter or longer period of time than usual. The precise moment when such erratic system behavior occurs is indicated for each signal by the specified deviation measure. The deviation measure can also be defined signal-specifically by the vehicle manufacturer. The deviation measure can also be determined by the machine learning model itself. To do this, the machine learning model defines the signal-specific deviation measure based on the insights gained from analyzing the initial time series data.
[0014] If erratic system behavior is detected, the central processing unit issues a warning signal. Depending on the warning signal, various subsequent reactions can be triggered, which will be discussed in more detail below.
[0015] In general, it would also be possible to directly compare the first time series data with the second time series data to identify erratic system behavior. However, with the help of the machine learning model, large amounts of data can be generated, so that a particularly large data set in the form of artificial time series data is available for comparison. This eliminates the corresponding effort for manually generating a sufficiently large initial time series data set. Furthermore, there is always the risk that the fleet vehicle will exhibit permissible system behavior that is not reflected in the initial time series data. By artificially generating corresponding data using the machine learning model, such values can also be generated, thus reducing the risk of a false-positive detection of erratic system behavior.In addition, this makes it possible to determine the deviation measure by the machine learning model itself, which, due to the superior capabilities of the machine learning model for pattern recognition, enables a particularly reliable differentiation between erratic system behavior and permissible system behavior.
[0016] An advantageous development of the method according to the invention provides for the use of a large language model as the machine learning model. Large language models are also referred to as "Large Language Models" (LLM). Due to their ability to artificially generate information, large language models are particularly suitable for use in the method according to the invention. In particular, large language models are capable of reading in and outputting corresponding time series data. For example, corresponding time series can be formulated in the form of a table or vector. For example, a timestamp can be entered in a respective row, and a respective value of a respective signal can be entered in a respective row.
[0017] Preferably, the central computing device integrates the large language model by issuing a prompt to the large language model to compare the artificial time series data with the second time series data. The large language model can be interacted with using a prompt. The large language model can therefore be used not only to artificially generate artificial time series data, but also to compare the artificial time series data with the second time series data. Such a prompt could, for example, be: "How likely is it that the data deviation is due to data manipulation?" Since the large language model has been trained to artificially generate corresponding artificial time series data, it is also able to identify corresponding deviations between the artificial time series data and the second time series data particularly reliably.This makes it possible to identify erratic system behavior and corresponding manipulation of the vehicle system components even more reliably.
[0018] A further advantageous embodiment of the method according to the invention further provides for the use of a machine learning model pre-trained for processing time series. For example, this can be a so-called "foundation model" for time series data. The correspondingly pre-trained machine learning model or artificial neural network is already characterized by a high degree of training in recognizing patterns in time series data, which allows it to complete the sufficient training using a smaller or smaller initial time series data set.
[0019] According to a further advantageous embodiment of the method according to the invention, it is further provided that several machine learning models dependent on the configuration of the test vehicle are trained, wherein to generate artificial time series data for the fleet vehicle, such a machine learning model is used whose training is based on first time series data recorded by a test vehicle whose configuration matches that of the fleet vehicle. The time series of the signals recorded in a respective vehicle can depend on the respective configuration of the respective vehicle. If, for example, a more powerful engine is installed in a vehicle, correspondingly higher performance parameters such as engine power, longitudinal acceleration, driving speed, and the like can be achieved.Accordingly, customized machine learning models are trained for the various vehicle configurations. This allows even more accurate artificial time series data to be generated for each vehicle and detects corresponding discrepancies between the artificial time series data and the second time series data.
[0020] To differentiate the differently trained machine learning models, they can be sorted into groups. This allows corresponding test vehicles or fleet vehicles to be assigned to these groups. By comparing the artificial time series data generated for a test vehicle with the initial time series data recorded in the test vehicle, the quality of the machine learning model adapted to the vehicle's configuration can be verified.
[0021] A further advantageous embodiment of the method according to the invention further provides that the central computing device, by issuing the warning signal, causes: - a workshop appointment is automatically booked for the fleet vehicle; - a remote diagnosis is carried out for the fleet vehicle; - a warning message is issued in the fleet vehicle; and / or - a vehicle function in the fleet vehicle is restricted or blocked.
[0022] If the warning signal is issued, this is an indication of unauthorized manipulation of the vehicle system components. For example, the program code of a control unit's control software may have been tampered with, additional devices may have been installed in the vehicle to manipulate the signals exchanged via the corresponding fieldbuses, and so on. Appropriate countermeasures must then be taken.
[0023] The central computing device can be connected to an online system for booking appointments with workshops. The owner of a fleet vehicle can have a user account with the vehicle manufacturer. This user account can store the owner's address or a favorite workshop. Using the address, a nearby workshop can be located or the favorite workshop can be selected for appointment booking. This allows the owner to conveniently visit the workshop to correct the tampering in the respective vehicle.
[0024] Additionally or alternatively, the central computing device can also initiate remote diagnostics. For this purpose, corresponding fleet vehicles and the central computing device can exchange data in a proven manner. For example, a fleet vehicle can be equipped with a telecommunications unit that allows the vehicle to be connected to the Internet via mobile communications, Wi-Fi, or similar. The central computing device can also be connected to the Internet and, in this context, also be referred to as a cloud server. Corresponding diagnostic data can then be transmitted via the Internet from a respective fleet vehicle to the central computing device for analysis. This makes it possible to get to the bottom of the cause of the erratic system behavior even more precisely. The analysis of the diagnostic data can be carried out manually by a developer or with assistance or fully automated by a computer system.
[0025] The warning information can also be used to inform the vehicle owner or person driving the vehicle about the detected tampering. Corresponding warning information can be issued via a visual, acoustic and / or haptic transmission channel. For example, a warning message can be shown on a display in the fleet vehicle, a corresponding warning tone can be sounded in the vehicle and / or an actuator such as a piezo actuator or a motor can be controlled, for example to impart vibrations to the steering wheel of the fleet vehicle. It is also conceivable that the respective vehicle owner or person driving the vehicle is logged in with their user account via an application running on a mobile device such as a smartphone. The mobile device can also be connected to the fleet vehicle, for example via a wired USB cable or wirelessly, for example via Wi-Fi, Bluetooth, NFC or the like.This means that warning information can also be displayed on mobile devices.
[0026] After detecting potential tampering with vehicle system components, a vehicle function can also be restricted or disabled to protect the fleet vehicle. For example, the tampering could result in the fleet vehicle's performance being increased without authorization, causing vehicle components to operate outside their approved operating range, resulting in excessive wear or damage. Vehicle functions that affect the operating range of the respective components can then be restricted or disabled. This can counteract premature aging or damage to the components until the tampering has been removed from the vehicle. After that, the respective vehicle functions can be re-enabled or made available for unrestricted use.
[0027] According to a further advantageous embodiment of the method according to the invention, only those signals are processed in the form of time series that do not allow any conclusions to be drawn about personal information. This ensures data protection. For example, time series associated with route navigation can generate personal information, since this could allow the location of the person driving the vehicle to be deduced.
[0028] A further advantageous embodiment of the method according to the invention further provides that - if the artificial time series data and the second time series data differ from each other by a specified outlier measure, where the outlier measure is greater than the deviation measure, the central computing device adapts the generation behavior of the machine learning model so that the machine learning model generates time series of the signals with a higher variance; - the central computing device generates outlier artificial time series data using the adapted machine learning model; - the central computing device compares the second time series data with the outlier artificial time series data; and - the central computing device refrains from issuing the warning signal if the difference between the comparison of the second time series data and the outlier artificial time series data is smaller than the difference between the comparison of the second time series data and the artificial time series data.
[0029] The differences detected between the artificial time series data and the second time series data may not only be due to erratic behavior resulting from manipulation of the vehicle system technology, but also to outliers in the underlying signals. Such outliers are characterized by a particularly large deviation from the standard behavior. Accordingly, the central computing device can check whether there are such large differences between the artificial time series data and the second time series data that they exceed the specified outlier threshold. This can be an indication of corresponding outliers. In this case, the warning signal must be prevented from being issued, since there is actually no manipulation of the vehicle system components.
[0030] To validate the detection of outliers, the central computing device generates artificial outlier time series data. If the machine learning model is a large language model, the so-called "temperature value" of the generation can be adjusted to generate the artificial outlier time series data with a high variance or a high random component. This can lead to the large language model incorporating disproportionately high values into the time series data, which is also referred to as "hallucinating" in the context of large language models.
[0031] By comparing the second time series data with the outlier artificial time series data, it can then be checked whether these are actually outliers or whether there is manipulation of the vehicle system components.
[0032] An information technology system according to the invention for carrying out a method described above is characterized by a central computing device comprising at least one machine learning model trained with first time series data of a test vehicle and a computer program product, the computer program product comprising machine-interpretable instructions which, when executed by a processor of the central computing device, cause the processor to generate artificial time series data by means of the machine learning model, to compare second time series data received from a fleet vehicle with the artificial time series data and to output a warning signal depending on the comparison.
[0033] Thus, the invention relates not only to the said method for identifying erratic system behavior of a vehicle, but also to the hardware and software components required for this purpose.
[0034] Further advantageous embodiments of the computer-implemented method according to the invention for identifying an erratic system behavior of a vehicle also result from the exemplary embodiments which are described in more detail below with reference to the figures.
[0035] Showing: Fig. 1 a diagram showing the course of signals transmitted via a fieldbus of a vehicle and / or processed by an on-board computing unit in the form of time series; Fig. 2 a diagram showing the course of signals artificially generated by a machine learning model in the form of time series; Fig. 3 a diagram showing the difference between the signals from the Fig. 1 and Fig. 2 diagrams shown; and Fig. 4 a flowchart of a method according to the invention for identifying erratic system behavior of a vehicle.
[0036] Modern vehicles such as cars rely on signal processing using computing units, such as control units. Using a drive-by-wire system, for example, a desired output can be requested from the vehicle's engine based on a detected accelerator pedal position. This can be achieved by controlling, for example, a pump for delivering liquid fuel to increase the fuel flow rate injected into the engine, a throttle valve control unit to open the throttle valve, and similar devices. Thus, during vehicle operation, a wide variety of signals are transmitted via the vehicle's fieldbus system and processed by the respective computing units installed in the vehicle.
[0037] Fig. 1 exemplarily shows, in a qualitative representation, the level or intensity of such signals 1, plotted over time t in the form of time series. The representation in Fig. 1 shows so-called first time series data ZRD1, which were recorded in a test vehicle, and second time series data ZRD2, which were recorded in a fleet vehicle. The first time series data ZRD1 and the second time series data ZRD2 can be identical or differ from one another. It can happen that vehicle system components, in particular in the form of the respective control units and / or the software running on them, are manipulated. Such manipulation can occur as part of a cyberattack or, for example, through so-called chip tuning. The system behavior of a correspondingly manipulated vehicle will differ from the operating mode intended by the vehicle manufacturer. A method according to the invention for identifying such erratic system behavior is based on the use of artificial intelligence.For this purpose, a machine learning model is trained with the initial time series data ZRD1 recorded in the test vehicle, enabling the machine learning model to artificially generate corresponding time series data in the form of artificial time series data KZRD. The artificial time series data KZRD generated by the machine learning model are shown in . Fig. 2 shown.
[0038] The aim is now to examine whether a fleet vehicle exhibits erratic system behavior. For this purpose, second time series data (ZRD2) are recorded in the fleet vehicle during operation and compared with the artificial time series data (KZRD) by a central computer. The difference from this comparison is shown in Fig. 3. The corresponding signals 1 can have a temporal offset from one another, which is indicated by corresponding horizontal arrows, and / or differ in their height from one another, which is indicated by a corresponding vertical arrow. Signal-specific limit values can be defined for each signal, which can occur during normal operation of the fleet vehicle between the second time series data ZRD2 and the artificial time series data KZRD. The totality of these limit values is referred to as the deviation measure. As soon as at least one signal 1 exceeds this deviation measure, this is interpreted by the central computing device as erratic system behavior, which is an indication of corresponding unauthorized manipulation of the vehicle system components. The central computing device then issues a warning signal.
[0039] The procedure of the method according to the invention is explained again with reference to Fig.4. In a step 401, the signals 1 transmitted during operation of a test vehicle via the fieldbus of the test vehicle and / or processed by a computing unit in the test vehicle are recorded in the form of first time series data ZRD1.
[0040] In step 402, the machine learning model is trained with the first time series data ZRD1, for example by the central computing device.
[0041] In step 403, the machine learning model generates artificial time series data KZRD.
[0042] In step 404, the signals 1 transmitted during operation of the fleet vehicle via the field bus of the fleet vehicle and / or processed by a computing unit in the fleet vehicle are recorded in the form of second time series data ZRD2.
[0043] In step 405, the second time series data ZRD2 is transmitted from the fleet vehicle to the central computing device. In step 406, the central computing device compares the artificial time series data KZRD with the second time series data ZRD2.
[0044] Finally, in step 407, the central computing device outputs a warning signal if the artificial time series data KZRD and the second time series data ZRD2 differ from each other by more than said specified deviation measure.
[0045] The method according to the invention makes it possible to reliably detect, with minimal technical effort, whether vehicle system components of the fleet vehicle have been tampered with. By initiating appropriate countermeasures after the warning signal is issued, potential damage to the fleet vehicle can be prevented. Furthermore, road safety can be increased by preventing tampered fleet vehicles from behaving dangerously in traffic.
Claims
[1] Computer-implemented method for identifying erratic system behavior of a vehicle using a machine learning model, characterized by the following procedural steps: - recording the signals (1) transmitted during operation of a test vehicle via a fieldbus of the test vehicle and / or processed by a computing unit in the test vehicle in the form of first time series data (ZRD1); - training a machine learning model with the first time series data (ZRD1) so that the machine learning model is able to artificially generate time series for the signals (1) comprised by the first time series data (ZRD1) while adhering to a specified tolerance level; - generating artificial time series data (KZRD) by the machine learning model, comprising time series of the signals (1) artificially generated by the machine learning model; - recording the signals (1) transmitted during operation of a fleet vehicle via a fieldbus of the fleet vehicle and / or processed by a computing unit in the fleet vehicle in the form of second time series data (ZRD2); - Transferring the second time series data (ZRD2) from the fleet vehicle to a central computing device; - comparing the artificial time series data (KZRD) with the second time series data (ZRD2) by the central computing facility; and - Output of a warning signal by the central computing device if the artificial time series data (KZRD) and the second time series data (ZRD2) differ from each other by a specified degree of deviation. [2] Method according to claim 1, characterized by that a large language model (LLM) is used as a machine learning model. [3] Method according to claim 2, characterized bythat the central computing device integrates the large language model (LLM) by issuing a request to the large language model (LLM) to compare the artificial time series data (KZRD) with the second time series data (ZRD2). [4] Method according to one of claims 1 to 3, characterized by that a machine learning model pre-trained to process time series is used. [5] Method according to one of claims 1 to 4, characterized by that several machine learning models are trained which depend on the configuration of the test vehicle, whereby to generate artificial time series data (KZRD) for the fleet vehicle, such a machine learning model is used, the training of which is based on first time series data (ZRD1) recorded by a test vehicle which corresponds in its configuration to the fleet vehicle. [6] Method according to one of claims 1 to 5, characterized bythat the central processing unit, by issuing the warning signal, causes: - a workshop appointment is automatically booked for the fleet vehicle; - a remote diagnosis is carried out for the fleet vehicle; - a warning message is issued in the fleet vehicle; and / or - a vehicle function in the fleet vehicle is restricted or blocked. [7] Method according to one of claims 1 to 6. characterized by that only those signals (1) are processed in the form of time series which do not allow any conclusions to be drawn about personal information. [8] Method according to one of claims 1 to 7, characterized by , that - if the artificial time series data (KZRD) and the second time series data (ZRD2) differ from each other by a specified outlier measure, where the outlier measure is greater than the deviation measure, the central computing device adapts the generation behavior of the machine learning model so that the machine learning model generates time series of the signals (1) with a higher variance; - the central computing device generates outlier artificial time series data using the adapted machine learning model; - the central computing device compares the second time series data (ZRD2) with the outlier artificial time series data; and - the central computing device refrains from issuing the warning signal if the difference between the comparison of the second time series data (ZRD2) and the outlier artificial time series data is smaller than the difference between the comparison of the second time series data (ZRD2) and the artificial time series data (KZRD). [9] Information technology system for carrying out a method according to one of claims 1 to 8, characterized by a central computing device comprising at least one machine learning model trained with first time series data of a test vehicle and a computer program product, the computer program product comprising machine-interpretable instructions which, when executed by a processor of the central computing device, cause the processor to generate artificial time series data (KZRD) using the machine learning model, to compare second time series data (ZRD2) received from a fleet vehicle with the artificial time series data (KZRD) and to output a warning signal depending on the comparison.
Citation Information
Patent Citations
Training method for training an artificial machine learning system to detect malfunctions and vehicle equipment
DE102021208988A1
Apparatus and method for detecting engine tunning chip
KR102356315B1
Vehicle correlation system for cyber attacks detection and method thereof
WO2016046819A1