Update system, on-vehicle device and server
Patent Information
- Application Number
- JP2023036466
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-03-09
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2043-03-09
AI Technical Summary
Existing in-vehicle devices struggle with accurately detecting fraudulent frames due to changes in the relationship between input and output values of trained models caused by vehicle aging, necessitating large logs for relearning.
An update system that includes an in-vehicle device and a server, where the device compares first and second vehicle values to determine model compatibility, selects and receives an updated trained model from the server, and updates the model without relearning, using vehicle information like model year and total mileage for selection.
Enables rapid model updates that maintain accurate fraudulent frame detection by adapting to vehicle changes, reducing the need for extensive retraining and ensuring compatibility with vehicle conditions.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present disclosure relates to an update system, an in-vehicle device, and a server. [Background technology]
[0002] A vehicle is equipped with various types of in-vehicle devices, such as control system ECUs (Electronic Control Units) that control the engine, transmission, etc., body system ECUs that control headlights, power windows, etc., and information system ECUs for navigation devices, multimedia devices, etc. Each in-vehicle device is connected to an in-vehicle network and can communicate with each other.
[0003] There is a problem that an unauthorized in-vehicle device is connected to an in-vehicle network by masquerading as an authorized in-vehicle device, and the unauthorized in-vehicle device transmits unauthorized frames to the in-vehicle network, thereby illegally controlling the vehicle. For this reason, techniques for detecting unauthorized frames in an in-vehicle network have been proposed (for example, Patent Documents 1 to 3).
[0004] When detecting fraudulent frames using a trained model generated by machine learning, if the relationship between the input value and the output value of the trained model changes due to aging of the vehicle, etc., it becomes impossible to accurately detect fraudulent frames. Patent Document 2 discloses a device that re-trains a trained model when the relationship between a first vehicle value and a second vehicle value acquired from a sensor mounted on the vehicle changes due to deterioration of an in-vehicle device. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] International Publication No. 2020 / 203352 [Patent Document 2] International Publication No. 2019 / 116973 [Patent Document 3] JP 2020-96286 A Summary of the Invention [Problem to be solved by the invention]
[0006] However, in the device disclosed in Patent Document 2, in order to re-learn the learned model, the first vehicle value and the second vehicle value obtained from the sensor need to be recorded as logs, which results in a problem of long waiting times. [Means for solving the problem]
[0007] An update system according to one aspect of the present disclosure includes an in-vehicle device and a server. The in-vehicle device includes a first trained model that uses a first vehicle value transmitted through an in-vehicle network to which the in-vehicle device is connected as input data and outputs an estimated value correlated to the first vehicle value, and a first determination unit that compares the estimated value output from the first trained model with a second vehicle value transmitted through the in-vehicle network to determine whether the first trained model is compatible with the vehicle. The server includes a selection unit that selects a second trained model for updating the first trained model when the first determination unit determines that the first trained model is not compatible with the vehicle, and a transmission unit that transmits the second trained model selected by the selection unit to the in-vehicle device. The in-vehicle device includes a reception unit that receives the second trained model transmitted from the server, and an update unit that updates the first trained model to the second trained model received by the reception unit. Effect of the Invention
[0008] According to the present disclosure, a trained model can be updated in a short period of time. [Brief description of the drawings]
[0009] [Figure 1] FIG. 1 is a block diagram showing an example of a configuration of an update system according to an embodiment. [Diagram 2]FIG. 2 is a block diagram illustrating an example of a hardware configuration of the relay ECU according to the embodiment. [Diagram 3] FIG. 3 is a block diagram illustrating an example of a hardware configuration of a server according to the embodiment. [Figure 4] FIG. 4 is a schematic diagram illustrating an example of the configuration of a trained model according to an embodiment. [Diagram 5] FIG. 5 is a diagram illustrating an example of the configuration of the trained model DB. [Figure 6] FIG. 6 is a functional block diagram illustrating an example of functions of the relay ECU according to the embodiment. [Figure 7] FIG. 7 is a functional block diagram illustrating an example of functions of the server according to the embodiment. [Figure 8] FIG. 8 is a flowchart illustrating an example of the operation of the relay ECU according to the embodiment. [Figure 9] FIG. 9 is a flowchart showing an example of the unauthorized frame detection process. [Figure 10A] FIG. 10A is the first half of a flowchart showing an example of the update process. [Figure 10B] FIG. 10B shows the second half of the flowchart illustrating an example of the update process. [Figure 11] FIG. 11 is a flowchart showing an example of the operation of the server according to the embodiment. [Figure 12] FIG. 12 is a flowchart illustrating an example of the model selection process. [Figure 13] FIG. 13 is a sequence diagram showing an example of the operation of the update system according to the embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0010] <Overview of the embodiment of the present disclosure> Below, an overview of the embodiments of the present disclosure will be listed and described.
[0011] (1) A management system according to the present embodiment includes an in-vehicle device and a server, the in-vehicle device includes a first trained model that uses a first vehicle value transmitted through an in-vehicle network to which the in-vehicle device is connected as input data and outputs an estimated value correlated with the first vehicle value, and a first determination unit that compares the estimated value output from the first trained model with a second vehicle value transmitted through the in-vehicle network to determine whether the first trained model is suitable for the vehicle, the server includes a selection unit that selects a second trained model for updating the first trained model when the first determination unit determines that the first trained model is not suitable for the vehicle, and a transmission unit that transmits the second trained model selected by the selection unit to the in-vehicle device, and the in-vehicle device includes a reception unit that receives the second trained model transmitted from the server, and an update unit that updates the first trained model to the second trained model received by the reception unit. This makes it possible to update the trained model in a short period of time without the need for re-learning in the in-vehicle device.
[0012] (2) In the above (1), the in-vehicle device may further include a storage unit that stores a first vehicle value and a second vehicle value that have been transmitted through the in-vehicle network in the past, and the first determination unit may compare the estimated value output from the first trained model by inputting the first vehicle value stored in the storage unit to the first trained model with the second vehicle value stored in the storage unit to determine whether the first trained model is suitable for the vehicle. In this way, by using the first vehicle value and the second vehicle value, which are actual values stored in the storage unit, it is possible to accurately determine whether the first trained model is suitable for the vehicle.
[0013] (3) In the above (2), the first determination unit may determine whether or not the first trained model is compatible with the vehicle when the vehicle is stopped. This makes it possible to determine whether or not the first trained model is compatible with the vehicle while the vehicle is stopped and there is no need to perform vehicle driving control.
[0014] (4) In the above (2) or (3), the in-vehicle device may further include a mode setting unit that sets an operation mode to either a normal mode in which the vehicle runs or a maintenance mode for performing maintenance on the vehicle, and the first determination unit may determine whether or not the first trained model is compatible with the vehicle when the operation mode is set to the maintenance mode. This makes it possible to perform a determination of whether or not the first trained model is compatible with the vehicle while the operation mode is set to the maintenance mode.
[0015] (5) In the above (4), the in-vehicle device may further include a second determination unit that, when the operation mode is set to the normal mode, compares the estimated value output from the first trained model with a second vehicle value transmitted through the in-vehicle network to determine whether a frame including the second vehicle value is an unauthorized frame. This makes it possible to detect unauthorized frames using the first trained model while the operation mode is the normal mode.
[0016] (6) In any one of (1) to (5) above, the selection unit may select the second trained model based on vehicle information related to the vehicle. This makes it possible to provide the second trained model corresponding to the vehicle to the in-vehicle device.
[0017] (7) In the above (6), the vehicle information may include a vehicle model of the vehicle. This makes it possible to provide the in-vehicle device with a second trained model corresponding to the vehicle model.
[0018] (8) In the above (6) or (7), the vehicle information may include a model year of the vehicle. This makes it possible to provide the in-vehicle device with a second trained model corresponding to the model year of the vehicle.
[0019] (9) In any one of (6) to (8) above, the vehicle information may include a total mileage of the vehicle. This makes it possible to provide the in-vehicle device with a second trained model corresponding to the total mileage of the vehicle.
[0020] (10) In the above (6), the vehicle information includes the vehicle model, year, and total mileage of the vehicle, the selection unit selects the second trained model corresponding to the vehicle model and year included in the vehicle information, and when there are multiple second trained models corresponding to the vehicle model and year included in the vehicle information, the selection unit may select one of the multiple second trained models based on the total mileage included in the vehicle information. This makes it possible to select a second trained model corresponding to the vehicle model and year. Furthermore, when there are multiple second trained models corresponding to the vehicle model and year, it is possible to select an appropriate second trained model based on the total mileage.
[0021] (11) In any one of the above (1) to (10), the selection unit may select the second trained model from a storage unit that stores a plurality of trained models. This makes it possible to select a trained model that is compatible with the vehicle as the second trained model from various trained models.
[0022] (12) In any one of the above (1) to (11), the in-vehicle device may further include a third determination unit that compares an estimated value output from the second trained model with a second vehicle value transmitted through the in-vehicle network to determine whether the second trained model is compatible with the vehicle, and a learning unit that generates a third trained model by performing supervised learning using the first vehicle value and the second vehicle value transmitted through the in-vehicle network as teacher data when the third determination unit determines that the second trained model is not compatible with the vehicle, and the update unit may update the first trained model to the third trained model generated by the learning unit. In this way, when the second trained model provided by the server is not compatible with the vehicle, a third trained model compatible with the vehicle is generated, and the first trained model can be updated to the third trained model.
[0023] (13) In the above (12), the in-vehicle device may further include a storage control unit that stores the third trained model generated by the learning unit in a storage unit that stores a plurality of trained models available for a plurality of vehicles. This allows the generated third trained model to be used in other vehicles.
[0024] (14) In any one of (1) to (13) above, the in-vehicle device may be a relay device connected to a plurality of communication lines included in the in-vehicle network and relaying frames between the plurality of in-vehicle devices. This makes it possible to update the learning model in the relay device that relays frames between the plurality of in-vehicle devices.
[0025] (15) An in-vehicle device according to the present embodiment is an in-vehicle device connected to an in-vehicle network, and includes: a first trained model that uses a first vehicle value transmitted through the in-vehicle network as input data and outputs an estimated value correlated with the first vehicle value; a first determination unit that compares the estimated value output from the first trained model with a second vehicle value transmitted through the in-vehicle network to determine whether the first trained model is suitable for the vehicle; a receiving unit that receives a second trained model for updating the first trained model from a server when the first determination unit determines that the first trained model is not suitable for the vehicle; and an updating unit that updates the first trained model to the second trained model received by the receiving unit. This eliminates the need for re-learning in the in-vehicle device, and allows the trained model to be updated in a short period of time.
[0026] (16) A server according to the present embodiment is a server capable of communicating with an in-vehicle device, and includes a selection unit that selects a second trained model for updating the first trained model when it is determined that the first trained model is not suitable for the vehicle by comparing an estimated value output from a first trained model that uses a first vehicle value transmitted through an in-vehicle network to which the in-vehicle device is connected as input data and outputs an estimated value correlated with the first vehicle value with a second vehicle value transmitted through the in-vehicle network, and a transmission unit that transmits the second trained model selected by the selection unit to the in-vehicle device. This makes it possible to update the trained model in a short period of time without the need to perform re-learning in the in-vehicle device.
[0027] The present disclosure can be realized not only as an update system having the above-mentioned characteristic configuration, an in-vehicle device included in the update system, and a server included in the update system, but also as an update method having steps corresponding to characteristic processes in an in-vehicle device, an update program for causing the in-vehicle device to execute characteristic processes, or a part or all of the relay device as a semiconductor integrated circuit. Furthermore, the present disclosure can be realized as a method having steps corresponding to characteristic processes in the server, a program for causing the server to execute characteristic processes, or a part or all of the server as a semiconductor integrated circuit.
[0028] <Details of the embodiment of the present disclosure> Hereinafter, the details of the embodiments of the present invention will be described with reference to the drawings. Note that at least some of the embodiments described below may be combined in any desired manner.
[0029] [1. Update system] 1 is a block diagram showing an example of the configuration of an update system according to this embodiment. The update system 10 includes a relay ECU 200 mounted on a vehicle, and a server 500 provided outside the vehicle.
[0030] The vehicle has an in-vehicle system 100. The in-vehicle system 100 includes a relay ECU 200 and ECUs 300A, 300B, 300C, 300D, and 300E. The in-vehicle system 100 is an in-vehicle network configured by the relay ECU 200, the ECUs 300A, 300B, 300C, 300D, and 300E, and communication lines (communication buses) connecting them.
[0031] The multiple ECUs 300A, 300B, 300C, 300D, and 300E are disposed in various parts of the vehicle. The ECUs 300A, 300B, 300C, 300D, and 300E individually control the hardware of the various parts of the vehicle and monitor the status of the hardware of the various parts of the vehicle. For example, the ECUs 300A, 300B, 300C, 300D, and 300E are ECUs for a control system, a body system, and an information system. In the following description, the ECUs 300A, 300B, 300C, and 300D are also collectively referred to as "ECU 300."
[0032] The ECUs 300A, 300B, 300C, and 300D are connected to sensors. The sensors detect physical quantities related to the vehicle. For example, a sensor 310A that detects an engine speed is connected to the ECU 300A. For example, a sensor 310B that detects the amount of depression of an accelerator pedal, i.e., a throttle opening, is connected to the ECU 300B. For example, a sensor 310C that detects a gear position in a transmission mechanism mounted on the vehicle is connected to the ECU 300C. For example, a sensor 310D that detects the rotation speed of the wheels, i.e., the vehicle speed is connected to the ECU 300D. The engine speed, the throttle opening, the gear position, and the vehicle speed are examples of "vehicle values."
[0033] The relay ECU 200 is connected to each of the ECUs 300A, 300B, 300C, 300D, and 300E via communication buses 400A, 400B, and 400C, such as a CAN (Controller Area Network) bus. Specifically, the ECUs 300A and 300B are connected to the bus 400A. The ECUs 300C and 300D are connected to the bus 400B. The ECU 300E is connected to the bus 400C. The relay ECU 200 can communicate with each of the ECUs 300A, 300B, 300C, 300D, and 300E. The relay ECU 200, the ECUs 300A, 300B, 300C, 300D, and 300E are examples of "in-vehicle devices."
[0034] The relay ECU 200 and the ECU 300 use a communication protocol for periodically or non-periodically transmitting and receiving messages. The communication protocol is, for example, CAN or CAN FD (CAN with Flexible Data Rate). In another example, the protocol is Ethernet.
[0035] The relay ECU 200 has a function as a gateway that relays communication between a plurality of ECUs 300. The ECUs 300 can transmit frames. The frames are messages that comply with the above-mentioned communication protocol. The relay ECU 200 relays frames between ECUs connected to different buses. For example, the relay ECU 200 can relay frames between an ECU 300A connected to a bus 400A and an ECU 300C connected to a bus 400B.
[0036] The ECUs 300A, 300B, 300C, and 300D can transmit frames including the vehicle values described above. The ECUs 300A, 300B, 300C, 300D, and 300E that receive the frames can obtain the vehicle values from the received frames.
[0037] The relay ECU 200 is connected to an external communication device 350 via a bus 400C. The external communication device 350 is, for example, a TCU (Telematics Control Unit) and can communicate with devices outside the vehicle. The external communication device 350 includes a wireless communication interface for a mobile communication system such as a fifth generation mobile communication system (5G) or a fourth generation mobile communication system (4G). The external communication device 350 can transmit and receive packets of, for example, TCP / IP (Transmission Control Protocol / Internet Protocol). The external communication device 350 can connect to a base station (not shown) of a mobile communication network and communicate with devices connected to the Internet via the base station. Specifically, the external communication device 350 can communicate with a server 500. The external communication device 350 relays communication between the relay ECU 200 and the server 500.
[0038] A connector 410 is connected to the bus 400C. The connector 410 is, for example, a connector conforming to OBD1 (On-board Diagnostics first generation) or OBD2 (On-board Diagnostics second generation). A diagnostic device 370 for diagnosing a vehicle can be connected to the connector 410. The diagnostic device 370 can communicate with the relay ECU 200 and the ECU 300 using the above-mentioned communication protocol. For example, the diagnostic device 370 can collect, from the relay ECU 200 and the ECU 300, vehicle values detected by sensors, abnormality or warning information detected in the past by the ECU 300, and the like.
[0039] [2. Hardware configuration of relay ECU] 2 is a block diagram showing an example of a hardware configuration of the relay ECU according to the present embodiment. The relay ECU 200 includes a processor 201, a nonvolatile memory 202, a volatile memory 203, and communication interfaces (hereinafter also referred to as "communication I / F") 204A, 204B, and 204C. The processor 201, the nonvolatile memory 202, the volatile memory 203, and the communication I / F 204 are connected to each other by a bus 205 which is a communication line. The processor 201, the nonvolatile memory 202, the volatile memory 203, and the communication I / F 204 can transmit data to each other via the bus 205. The relay ECU 200 is an example of a "relay device."
[0040] The volatile memory 203 is, for example, a semiconductor memory such as a static random access memory (SRAM) or a dynamic random access memory (DRAM). The non-volatile memory 202 is, for example, a flash memory, a hard disk, a read only memory (ROM), etc. The non-volatile memory 202 stores an unauthorized frame detection program 210 and an update program 211, which are computer programs, and data used for executing the unauthorized frame detection program 210 and the update program 211. Functions of the relay ECU 200, which will be described later, are realized by the processor 201 executing the unauthorized frame detection program 210 and the update program 211.
[0041] The processor 201 is, for example, a CPU (Central Processing Unit). However, the processor 201 is not limited to a CPU. The processor 201 may be a GPU (Graphics Processing Unit). In a specific example, the processor 201 is a multi-core processor. The processor 201 may be a single-core processor. The processor 201 is configured to be able to execute a computer program. However, the processor 201 may be, for example, an ASIC (Application Specific Integrated Circuit) or a programmable logic device such as an FPGA (Field Programmable Gate Array). In this case, the ASIC or the programmable logic device is configured to be able to execute the same functions as the fraudulent frame detection program 210 and the update program 211.
[0042] The communication I / Fs 204A, 204B, and 204C are communication interfaces that comply with the above-mentioned communication protocol for the in-vehicle network. The communication I / Fs 204A, 204B, and 204C are, for example, CAN interfaces. The communication I / Fs 204A, 204B, and 204C may be Ethernet interfaces.
[0043] The communication I / F 204A is connected to the bus 400A. The communication I / F 204B is connected to the bus 400B. The communication I / F 204C is connected to the bus 400C. The relay ECU 200 can communicate with the ECUs 300A and 300B through the communication I / F 204A. The relay ECU 200 can communicate with the ECUs 300C and 300D through the communication I / F 204B. The relay ECU 200 can communicate with the ECU 300E through the communication I / F 204C. Furthermore, the relay ECU 200 can communicate with the diagnostic device 370 through the communication I / F 204C, and can communicate with the server 500 via the external communication device 350.
[0044] A trained model 212 used for detecting fraudulent frames is stored in the non-volatile memory 202. The trained model 212 will be described later.
[0045] The non-volatile memory 202 stores log data 213. The log data 213 includes previously detected vehicle values, such as engine speed, throttle opening, gear position, and vehicle speed.
[0046] The non-volatile memory 202 stores vehicle information 214. The vehicle information 214 includes the vehicle model, year, and total mileage. For example, the vehicle information 214 may be stored in a non-volatile memory (not shown) of the ECU 300, instead of the non-volatile memory 202 of the relay ECU 200. In this case, the relay ECU 200 can obtain the vehicle information from the ECU 300 through communication.
[0047] [3. Server hardware configuration] 3 is a block diagram showing an example of a hardware configuration of a server according to this embodiment. The server 500 includes a processor 501, a nonvolatile memory 502, a volatile memory 503, and a communication I / F 504. The processor 501, the nonvolatile memory 502, the volatile memory 503, and the communication I / F 504 are connected to each other by a bus 505, which is a communication line. The processor 501, the nonvolatile memory 502, the volatile memory 503, and the communication I / F 504 can transmit data to each other via the bus 505.
[0048] The volatile memory 503 is, for example, a semiconductor memory such as an SRAM or a DRAM. The non-volatile memory 502 is, for example, a flash memory, a hard disk, a ROM, etc. The non-volatile memory 502 stores a distribution program 510, which is a computer program, and data used for executing the distribution program 510. The functions of the server 500, which will be described later, are realized by the processor 501 executing the distribution program 510.
[0049] The processor 501 is, for example, a CPU. However, the processor 501 is not limited to a CPU. The processor 501 may be a GPU. In a specific example, the processor 501 is a multi-core processor. The processor 501 may be a single-core processor. The processor 501 is configured to be able to execute a computer program. However, the processor 501 may be, for example, an ASIC or a programmable logic device such as an FPGA. In this case, the ASIC or the programmable logic device is configured to be able to execute the same function as the provided program 510.
[0050] The communication I / F 504 is, for example, an Ethernet interface ("Ethernet" is a registered trademark). The communication I / F 504 is connected to, for example, the Internet. The communication I / F 504 can send and receive, for example, TCP / IP packets.
[0051] The non-volatile memory 502 is provided with a trained model database 511 (hereinafter also referred to as "trained model DB 511"). A plurality of trained models are stored in the trained model DB 511. The trained model DB 511 is an example of a "storage unit." In response to a request from a vehicle, the provision program 510 selects a trained model suitable for the vehicle from the trained model DB 511, and provides the selected trained model to the vehicle. The trained model DB 511 will be described later.
[0052] [4. Trained Model] The trained model 212 is a computer program executable by the processor 201 and is used to detect fraudulent frames.
[0053] 4 is a schematic diagram illustrating an example of a configuration of a trained model according to an embodiment. The trained model 212 is configured, for example, by a neural network and includes an input layer, a hidden layer, and an output layer.
[0054] The trained model 212 is configured by, for example, a deep neural network. The trained model 212 may be a convolutional neural network, a recurrent neural network, a Long Short Term Memory (LSTM), or another neural network.
[0055] The input layer receives vehicle values (first vehicle values) detected by a sensor and included in a frame transmitted from ECU 300. Input layer 212IN includes one or more nodes. For example, the input layer receives first vehicle values of the engine speed, the throttle opening, and the gear position.
[0056] The hidden layer is composed of one or more processing layers. In the example shown in FIG. 4, the hidden layer has a three-layer structure. Each layer that composes the hidden layer has one or more nodes. Each node in the input layer is connected to each node in the second layer by an edge. An individual weight is set for each edge. Each node in the second layer is connected to each node in the third layer by an edge. Each node in the third layer is connected to each node in the fourth layer by an edge.
[0057] The output layer contains at least one node. Each of the fourth-layer nodes in the hidden layer is connected by an edge to a node in the output layer.
[0058] The first vehicle value given to the nodes in the input layer is weighted by the edge weight and passed to the nodes in the second layer. The nodes in the second layer execute the processing assigned to each of the given data. The data processed by the nodes in the second layer is weighted by the edge weight and passed to the nodes in the third layer. The nodes in the third layer execute the processing assigned to each of the given data. In the same manner, the data is passed sequentially to the fourth layer and the output layer. The data of the nodes included in the output layer is an estimate of the second vehicle value. The second vehicle value is a vehicle value that is correlated to the first vehicle value. For example, if the first vehicle value is engine speed, throttle opening, and gear position, the second vehicle value is vehicle speed.
[0059] For example, if the frame transmitting the vehicle speed, which is the second vehicle value, is a regular frame (hereinafter also referred to as a "regular frame"), the vehicle speed included in the regular frame is a normal value indicating the actual vehicle speed. Therefore, if the input data of the engine speed, throttle opening, and gear position are each normal, the estimated value of the vehicle speed output from the learned model 212 is a value close to the vehicle speed included in the regular frame. For example, if the frame transmitting the vehicle speed, which is the second vehicle value, is an illegal frame, the vehicle speed included in the illegal frame is an abnormal value different from the actual vehicle speed. Therefore, the estimated value of the vehicle speed output from the learned model 212 will be a value that is not close to the vehicle speed included in the illegal frame.
[0060] A plurality of learned models may be stored in the non-volatile memory 202 of the relay ECU 200. For example, the non-volatile memory 202 may store a learned model in which the depression amount of the brake pedal is used as input data and an estimated value of acceleration is used as output data, a learned model in which the rotation angle of the steering wheel is used as input data and an estimated value of the steering angle of the wheels is used as output data, and the like.
[0061] [5. Trained Model DB] FIG. 5 is a diagram showing an example of the configuration of a trained model DB. The trained model DB 511 stores vehicle information and trained models in association with each other. That is, the trained model DB 511 stores vehicle information and trained models adapted to a vehicle identified by the vehicle information in association with each other. Specifically, the vehicle information is vehicle information of a vehicle for which a corresponding trained model has been generated. In the example of FIG. 5, the trained model M1 is a trained model generated by a vehicle of the model "Model A", the year "2011", and the total mileage "9251 km". The trained model M2 is a trained model generated by a vehicle of the model "Model A", the year "2015", and the total mileage "8289 km". The trained model M3 is a trained model generated by a vehicle of the model "Model A", the year "2015", and the total mileage "20350 km". Trained model M4 is a trained model generated by a vehicle of type "Vehicle Model B", year "2021", and total mileage "563 km".
[0062] [6. Functions of the update system] FIG. 6 is a functional block diagram illustrating an example of functions of the relay ECU according to the embodiment.
[0063] When the processor 201 of the relay ECU 200 executes the fraudulent frame detection program 210 and the update program 211, the functions of the mode setting unit 221, the input unit 231, the frame determination unit 232, the output unit 233, the input unit 241, the first compatibility determination unit 242, the request unit 243, the receiving unit 244, the input unit 245, the second compatibility determination unit 246, the update unit 247, the learning unit 248, and the storage control unit 249 are realized.
[0064] The relay ECU 200 can set two operation modes: a normal mode and a maintenance mode. The normal mode is an operation mode that is set when the vehicle is traveling. The maintenance mode is an operation mode that is set when maintenance work is performed on the vehicle. In other words, the maintenance mode is an operation mode that is set when the vehicle is not traveling.
[0065] Please refer to Fig. 1. For example, maintenance work such as inspection and repair of a vehicle is performed by a dealer or the like. A worker at the dealer connects diagnostic device 370 to connector 410 during maintenance work. When diagnostic device 370 is connected to in-vehicle system 100, a frame is transmitted from diagnostic device 370 to in-vehicle system 100. Relay ECU 200 detects the connection of diagnostic device 370 by receiving the frame.
[0066] Returning to Fig. 6, for example, when mode setting unit 221 detects connection of diagnostic device 370, it switches the operation mode from normal mode to maintenance mode. When diagnostic device 370 is disconnected from in-vehicle system 100, mode setting unit 221 switches from maintenance mode to normal mode. That is, normal mode is an operation mode that is set when diagnostic device 370 is not connected to in-vehicle system 100. Maintenance mode is an operation mode that is set when diagnostic device 370 is connected to in-vehicle system 100.
[0067] The input unit 231, the frame determination unit 232, and the output unit 233 are functions executed in the normal mode. The input unit 231, the frame determination unit 232, and the output unit 233 are realized by the unauthorized frame detection program 210.
[0068] The input unit 231 inputs the first vehicle value to the learned model 212. In a specific example, the input unit 231 acquires the first vehicle value from a frame received by the relay ECU 200 from the in-vehicle network, and inputs the acquired first vehicle value to the learned model 212. That is, the first vehicle value that the input unit 231 inputs to the learned model 212 is the vehicle value most recently detected by the sensors 310A, 310B, and 310C, that is, the current value.
[0069] When the trained model 212 receives the first vehicle value as input data, it outputs an estimate of the second vehicle value. That is, the output data from the trained model 212 is an estimate of the current value of the second vehicle value obtained from the current value of the first vehicle value, and is an estimate of the vehicle value most recently detected by the sensor 310D. The trained model 212 stored in the non-volatile memory 202 is an example of a "first trained model."
[0070] The frame determination unit 232 compares the estimated value output from the learned model 212 with the second vehicle value transmitted through the in-vehicle network to determine whether or not the frame including the second vehicle value is an unauthorized frame. The frame determination unit 232 is an example of a "second determination unit". In a specific example, the frame determination unit 232 acquires the current value of the second vehicle value from the frame received by the relay ECU 200 from the in-vehicle network. The frame determination unit 232 compares the estimated value output from the learned model 212 with the current value of the second vehicle value. For example, the frame determination unit 232 calculates the difference between the estimated value output from the learned model 212 and the current value of the second vehicle value, and determines whether or not the difference is equal to or greater than a threshold. If the difference is less than the threshold, the frame determination unit 232 determines that the frame including the second vehicle value is a regular frame. If the difference is equal to or greater than the threshold, the frame determination unit 232 determines that the frame including the second vehicle value is an unauthorized frame.
[0071] When the frame determination unit 232 detects an unauthorized frame, the output unit 233 outputs notification data for notifying the user of the detection of the unauthorized frame. For example, the output unit 233 generates a notification frame for notifying the user of the detection of the unauthorized frame, and transmits the generated notification frame to the in-vehicle network. For example, a user interface device (hereinafter also referred to as a "UI device") is connected to the in-vehicle system (not shown). The UI device is one of the in-vehicle devices mounted on the vehicle. The UI device is used by the driver of the vehicle. The UI device includes an input device and a display device, and can accept input from the driver and display information to be provided to the driver. The UI device receives the notification frame transmitted from the relay ECU 200, and displays a screen for notifying the user of the detection of the unauthorized frame. This notifies the driver of the detection of the unauthorized frame.
[0072] The input unit 241, the first conformity determination unit 242, the request unit 243, the receiving unit 244, the input unit 245, the second conformity determination unit 246, the update unit 247, the learning unit 248, and the storage control unit 249 are functions executed in the maintenance mode. The input unit 231, the input unit 241, the first conformity determination unit 242, the request unit 243, the receiving unit 244, the input unit 245, the second conformity determination unit 246, the update unit 247, the learning unit 248, and the storage control unit 249 are realized by the update program 211.
[0073] The input unit 241 inputs the first vehicle value to the learned model 212. In a specific example, the input unit 241 reads the first vehicle value from the log data 213, and inputs the read first vehicle value to the learned model 212. That is, the first vehicle value that the input unit 241 inputs to the learned model 212 is a vehicle value previously detected by the sensors 310A, 310B, and 310C, that is, a past value (actual value).
[0074] When the trained model 212 receives the first vehicle value as input data, it outputs an estimate of the second vehicle value. That is, the output data from the trained model 212 is an estimate of the past value of the second vehicle value obtained from the past value of the first vehicle value, and is an estimate of the vehicle value previously detected by the sensor 310D.
[0075] The mechanical characteristics of a vehicle change due to aging. When the mechanical characteristics change, the correlation between the first vehicle value and the second vehicle value changes. For this reason, the trained model 212 that correctly reflected the relationship between the first vehicle value and the second vehicle value in the past may no longer correctly reflect the relationship between the first vehicle value and the second vehicle value due to aging of the vehicle.
[0076] The first compatibility determination unit 242 compares the estimated value output from the learned model 212 with the second vehicle value transmitted through the in-vehicle network to determine whether the learned model 212 is compatible with the vehicle. The first compatibility determination unit 242 is an example of a "first determination unit." In a specific example, the first compatibility determination unit 242 reads out the second vehicle value from the log data 213. The second vehicle value recorded in the log data 213 is a past value of the second vehicle value. The first compatibility determination unit 242 compares the estimated value output from the learned model 212 with the second vehicle value read out from the log data 213. The second vehicle value used for comparison with the estimated value is the second vehicle value detected at the time when the first vehicle value input to the learned model 212 was detected or at a time close to the time when the first vehicle value was detected.
[0077] For example, the first compatibility determination unit 242 calculates the difference between the estimated value output from the trained model 212 and the past value of the second vehicle value, and determines whether the difference is equal to or greater than a threshold. If the difference is less than the threshold, the first compatibility determination unit 242 determines that the trained model 212 is compatible with the vehicle. If the difference is equal to or greater than the threshold, the first compatibility determination unit 242 determines that the trained model 212 is not compatible with the vehicle.
[0078] If the first compatibility determination unit 242 determines that the trained model 212 is compatible with the vehicle, the trained model 212 is not updated and continues to be used to detect fraudulent frames.
[0079] The input / output relationship in the trained model 212 that is not adapted to the vehicle deviates from the actual correlation between the first vehicle value and the second vehicle value. For this reason, if the trained model 212 that is not adapted to the vehicle is used to detect fraudulent frames, there is a risk that the fraudulent frames will be erroneously detected or will not be detected at all. Therefore, if the trained model 212 is not adapted to the vehicle, it is necessary to update the trained model 212 to a trained model that correctly reflects the correlation between the first vehicle value and the second vehicle value.
[0080] When the first compatibility determination unit 242 determines that the trained model 212 is not compatible with the vehicle, the request unit 243 requests a new trained model from the server 500. In a specific example, the request unit 243 generates a request frame for requesting a new trained model, and transmits the request frame to the in-vehicle network.
[0081] The request frame includes the vehicle information. That is, the request unit 243 reads the vehicle information 214 from the non-volatile memory 202, and generates a request frame including the read vehicle information 214. The request frame transmitted by the request unit 243 is received by the external communication device 350. Upon receiving the request frame, the external communication device 350 performs necessary processing such as protocol conversion, and transmits the request frame to the server 500.
[0082] FIG. 7 is a functional block diagram illustrating an example of functions of the server according to the embodiment.
[0083] When the processor 501 of the server 500 executes the provision program 510, the functions of a receiving unit 521, a selecting unit 522, and a transmitting unit 523 are realized.
[0084] The receiving unit 521 receives a request frame transmitted from a vehicle.
[0085] When the receiving unit 521 receives a request frame, the selecting unit 522 selects a trained model for update from the trained model DB 511.
[0086] In a specific example, the selection unit 522 selects a trained model for update from among multiple trained models stored in the trained model DB 511, based on the vehicle information included in the request frame.
[0087] For example, the selection unit 522 can select a trained model corresponding to the same vehicle model as the vehicle model included in the request frame. It can be estimated that the mechanical characteristics of vehicles of the same vehicle model are similar. For this reason, it is estimated that the relationship between the first vehicle value and the second vehicle value is similar for vehicles of the same vehicle model. Therefore, it is considered that a trained model for a vehicle of the same vehicle model as the vehicle that requested the trained model is likely to be compatible with the requesting vehicle.
[0088] There is a high possibility that the configuration of the in-vehicle network is different between vehicles of different models. For example, a vehicle value used in a first in-vehicle network may not be used in a second in-vehicle network. In contrast, there is a high possibility that the configuration of the in-vehicle network is common between vehicles of the same model. From this perspective, too, it is considered that a trained model for a vehicle of the same model as the vehicle that requests the trained model is likely to be compatible with the requesting vehicle.
[0089] For example, the selection unit 522 can select a trained model corresponding to a model year close to the model year included in the request frame. It can be estimated that the deterioration over time of vehicles with similar model years is similar. For this reason, it is estimated that the relationship between the first vehicle value and the second vehicle value is close to that of the vehicle that has requested the trained model. Therefore, it is considered that a trained model for a vehicle with a model year close to that of the vehicle that has requested the trained model is likely to be compatible with the vehicle that has requested the trained model.
[0090] For example, if multiple learned models corresponding to the same vehicle model as that included in the request frame are stored in the learned model DB 511, the selection unit 522 can select the learned model corresponding to the model year that is closest to the model year included in the request frame.
[0091] For example, the selection unit 522 can select a trained model corresponding to a total mileage close to the total mileage included in the request frame. It can be estimated that the deterioration of vehicles with similar total mileages is similar. For this reason, it is estimated that the relationship between the first vehicle value and the second vehicle value is similar for vehicles with similar total mileages. Therefore, it is considered that a trained model for a vehicle with a total mileage close to that of the vehicle that requested the trained model is likely to be compatible with the requesting vehicle.
[0092] For example, the selection unit 522 can select a trained model corresponding to the vehicle model and year included in the vehicle information. When there are multiple trained models corresponding to the vehicle model and year included in the vehicle information, the selection unit 522 can select one of the multiple trained models based on the total mileage included in the vehicle information. In a specific example, when multiple trained models corresponding to the same vehicle model and year as the vehicle model and year included in the request frame are stored in the trained model DB 511, the selection unit 522 can select a trained model corresponding to a total mileage closest to the total mileage included in the request frame.
[0093] The transmission unit 523 transmits the trained model for update selected by the selection unit 522 to the requesting vehicle.
[0094] Returning to Fig. 6, the trained model transmitted from the server 500 is received by the external communication device 350. The external communication device 350 divides the received trained model, for example, into a plurality of frames and transmits the frames to the relay ECU 200. The receiving unit 244 receives the frames transmitted from the external communication device 350, i.e., the trained model for update.
[0095] The input unit 245 inputs the first vehicle value to the received trained model for update (hereinafter also referred to as the "update model"). The update model is an example of the "second trained model". In a specific example, the input unit 231 reads out the first vehicle value from the log data 213, and inputs the read out first vehicle value to the update model. That is, the first vehicle value that the input unit 231 inputs to the update model is the vehicle value previously detected by the sensors 310A, 310B, 310C, that is, the past value (actual value).
[0096] When the update model receives the first vehicle value as input data, it outputs an estimate of the second vehicle value. That is, the output data from the update model is an estimate of the past value of the second vehicle value obtained from the past value of the first vehicle value, and is an estimate of the vehicle value previously detected by sensor 310D.
[0097] The second compatibility determination unit 246 compares the estimated value output from the update model with the second vehicle value transmitted through the in-vehicle network to determine whether the update model is compatible with the vehicle. The second compatibility determination unit 246 is an example of a "third determination unit." In a specific example, the second compatibility determination unit 246 reads out the second vehicle value from the log data 213. The second vehicle value recorded in the log data 213 is a past value of the second vehicle value. The second compatibility determination unit 246 compares the estimated value output from the update model with the second vehicle value read out from the log data 213. The second vehicle value used for comparison with the estimated value is the second vehicle value detected at the time when the first vehicle value input to the update model was detected or at a time close to the time when the first vehicle value was detected.
[0098] For example, the second compatibility determination unit 246 calculates the difference between the estimated value output from the update model and the past value of the second vehicle value, and determines whether the difference is equal to or greater than a threshold. If the difference is less than the threshold, the second compatibility determination unit 246 determines that the update model is compatible with the vehicle. If the difference is equal to or greater than the threshold, the second compatibility determination unit 246 determines that the update model is not compatible with the vehicle.
[0099] When the second compatibility determination unit 246 determines that the update model is compatible with the vehicle, the update unit 247 updates the trained model 212 stored in the non-volatile memory 202 to the update model. That is, the update unit 247 overwrites the trained model 212 stored in the non-volatile memory 202 with the update model.
[0100] If the second compatibility determination unit 246 determines that the update model is not compatible with the vehicle, the learning unit 248 generates a new trained model (hereinafter also referred to as a "new model") by performing supervised learning using the first vehicle value and the second vehicle value transmitted through the in-vehicle network as training data. The new model is an example of the "third trained model."
[0101] In a specific example, the learning unit 248 reads out the first vehicle value and the second vehicle value from the log data 213, and creates teacher data from the read out first vehicle value and second vehicle value. For example, the log data 213 includes the first vehicle value and the second vehicle value in a sufficient amount of data required for supervised learning. Specifically, the log data 213 accumulates the first vehicle value and the second vehicle value detected during a certain period. For example, when the relay ECU 200 receives new first vehicle value and second vehicle value, the received first vehicle value and second vehicle value are added to the log data 213. For example, when new first vehicle value and second vehicle value are added to the log data 213, the oldest first vehicle value and second vehicle value may be deleted from the log data 213. For example, the learning unit 248 can create teacher data from all the first vehicle values and second vehicle values included in the log data 213.
[0102] The learning unit 248 generates a trained model that uses the first vehicle value as an input and the second vehicle value as an output based on the teacher data. That is, the learning unit 248 executes machine learning using the teacher data to construct a trained model.
[0103] The learning unit 248 provides the neural network with training data and executes supervised learning. In supervised learning, the first vehicle value in the training data is provided as an input to the neural network, and learning is performed so that the output is the same as the second vehicle value. Such machine learning is repeatedly performed using a plurality of data sets combining the first vehicle value and the second vehicle value. In machine learning, an existing learning algorithm such as backpropagation or gradient descent may be used. The weights of the neural network are adjusted by machine learning, and a trained model is constructed.
[0104] The update unit 247 can update the trained model 212 stored in the non-volatile memory 202 to a new model generated by the training unit 248.
[0105] The storage control unit 249 stores the new model generated by the learning unit 248 in the trained model DB 511. In a specific example, the storage control unit 249 transmits a registration request including the new model generated by the learning unit 248 and the vehicle information 214. The registration request is, for example, divided into a plurality of frames and transmitted to the external communication device 350. Upon receiving the registration request, the external communication device 350 performs necessary processing such as protocol conversion and transmits the registration request to the server 500.
[0106] When the server 500 receives the registration request, the server 500 registers the vehicle information and the new model included in the registration request in the trained model 511. This makes the new model available for use in multiple vehicles.
[0107] [7. Update system operation] The operation of the in-vehicle system according to this embodiment will be described below.
[0108] FIG. 8 is a flowchart illustrating an example of the operation of the relay ECU according to the embodiment.
[0109] The normal mode is the default operation mode of the relay ECU 200. That is, the relay ECU 200 is set to the normal mode at the time of startup.
[0110] When diagnostic device 370 is connected to the in-vehicle network, diagnostic device 370 transmits a frame. Processor 201 of relay ECU 200 detects the connection of diagnostic device 370 by receiving the frame. Processor 201 determines whether diagnostic device 370 is connected to the in-vehicle network (step S101).
[0111] If diagnostic device 370 is not connected to the in-vehicle network (NO in step S101), processor 201 maintains the normal mode and executes the unauthorized frame detection process (step S102).
[0112] FIG. 9 is a flowchart showing an example of the unauthorized frame detection process.
[0113] In the fraudulent frame detection process, the processor 201 receives a frame including a first vehicle value and a frame including a second vehicle value (step S201). For example, in the CAN, a CAN ID indicating the source ECU 300 is assigned. The processor 201 identifies the source by the CAN ID of the frame, and can thereby identify whether the frame is a frame including the first vehicle value, a frame including the second vehicle value, or another frame.
[0114] The processor 201 acquires the first vehicle value from the received frame, and inputs the acquired first vehicle value to the learned model 212. The learned model 212 outputs an estimated value of the second vehicle value (step S202).
[0115] The processor 201 acquires the current value of the second vehicle value from the frame received in step S201, and calculates the difference between the acquired current value of the second vehicle value and the estimated value of the second vehicle value (step S203).
[0116] The processor 201 compares the calculated difference with a threshold value (step S204). If the difference is less than the threshold value (NO in step S204), the processor 201 ends the unauthorized frame detection process.
[0117] If the difference is equal to or greater than the threshold (YES in step S204), the processor 201 determines that the received frame is an unauthorized frame, and transmits a notification frame to notify the user of the detection of the unauthorized frame (step S205). The UI device receives the notification frame and displays a screen to notify the user of the detection of the unauthorized frame. This ends the unauthorized frame detection process.
[0118] Returning to Fig. 8, when the unauthorized frame detection process ends, the operation of the relay ECU 200 ends. The relay ECU 200, for example, repeatedly executes the operation shown in Fig. 8 at a predetermined cycle.
[0119] If diagnostic device 370 is connected to the in-vehicle network (YES in step S101), processor 201 sets the operation mode to the maintenance mode (step S103).
[0120] The processor 201 executes the update process (step S104).
[0121] 10A and 10B are flowcharts showing an example of the update process.
[0122] 10A, in the update process, the processor 201 reads out the past values of the first vehicle value and the second vehicle value from the log data 213 (step S301).
[0123] The processor 201 inputs the first vehicle value read from the log data 213 to the learned model 212. The learned model 212 outputs an estimated value of the second vehicle value (step S302).
[0124] The processor 201 calculates the difference between the past value of the second vehicle value read from the log data 213 and the estimated value of the second vehicle value (step S303).
[0125] The processor 201 compares the calculated difference with a threshold value (step S304). If the difference is less than the threshold value (NO in step S304), the processor 201 determines that the trained model 212 is compatible with the vehicle, and ends the update process.
[0126] If the difference is equal to or greater than the threshold (YES in step S304), the processor 201 determines that the trained model 212 is not suitable for the vehicle. The processor 201 transmits a request frame to request an update model to the server 500. The request frame includes the vehicle information 214. The request frame is received by the external communication device 350, and the external communication device 350 transfers the request frame to the server 500.
[0127] FIG. 11 is a flowchart showing an example of the operation of the server according to the embodiment.
[0128] The server 500 receives the request frame (step S401), which causes the processor 501 of the server 500 to accept the request for an update model.
[0129] The processor 501 executes a model selection process to select an update model from the trained model DB 511 based on the vehicle information included in the request frame (step S402).
[0130] FIG. 12 is a flowchart illustrating an example of the model selection process.
[0131] In the model selection process, the processor 501 searches the learned model DB 511 for a learned model corresponding to the vehicle model and year included in the vehicle information (step S501).
[0132] The processor 501 determines whether or not multiple trained models corresponding to the vehicle model and year included in the vehicle information are obtained as a search result (step S502). If only one trained model corresponding to the vehicle model and year included in the vehicle information is obtained (NO in step S502), the processor 501 selects the trained model as an update model (step S503).
[0133] When multiple trained models corresponding to the vehicle model and year included in the vehicle information are obtained (YES in step S502), the processor 501 selects, from among these trained models, the trained model corresponding to the total mileage closest to the total mileage included in the vehicle information as the update model (step S504). This ends the model selection process.
[0134] 11, the processor 501 transmits the selected update model to the requesting vehicle (external communication device 350) (step S403). With this, the operation of the server 500 is completed.
[0135] Returning to Fig. 10A, when the external communication device 350 receives the update model transmitted from the server 500, it performs necessary processing such as protocol conversion, and transmits the update model to the relay ECU 200. The relay ECU 200 receives the update model (step S306).
[0136] The processor 201 reads out the past values of the first vehicle value and the second vehicle value from the log data 213 (step S307).
[0137] The processor 201 inputs the first vehicle value read from the log data 213 to the update model. The update model outputs an estimated value of the second vehicle value (step S308).
[0138] The processor 201 calculates the difference between the past value of the second vehicle value read from the log data 213 and the estimated value of the second vehicle value output from the update model (step S309).
[0139] The processor 201 compares the calculated difference with a threshold value (step S310). If the difference is less than the threshold value (NO in step S310), the processor 201 determines that the update model is suitable for the vehicle, and updates the trained model 212 stored in the non-volatile memory 202 to the update model (step S311).
[0140] If the difference is equal to or greater than the threshold value (YES in step S310), the processor 201 determines that the update model is not suitable for the vehicle.
[0141] 10B, the processor 201 reads out the past values of the first vehicle value and the second vehicle value from the log data 213 (step S312). The processor 201 creates teacher data from the read out first vehicle value and second vehicle value (step S313).
[0142] The processor 201 provides the training data to the neural network and executes a learning process (step S314), thereby generating a new model.
[0143] The processor 201 updates the trained model 212 stored in the non-volatile memory 202 to the new model (step S315).
[0144] The processor 201 transmits a registration request including the generated new model and vehicle information. The registration request is transmitted (uploaded) to the server 500 by the external communication device 350. Upon receiving the registration request, the server 500 registers the vehicle information and the new model included in the registration request in the trained model DB 511. This ends the update process.
[0145] Fig. 13 is a flowchart showing an example of the operation of the update system according to the embodiment, in which the operation mode of the relay ECU 200 is the maintenance mode.
[0146] When diagnostic device 370 is connected to the in-vehicle network, processor 201 of relay ECU 200 sets the operation mode to the maintenance mode. Processor 201 executes the update process.
[0147] The processor 201 inputs a first vehicle value included in the log data 213 to the learned model 212. The processor 201 acquires an estimated value output from the learned model 212. The processor 201 compares a second vehicle value included in the log data 213 with the estimated value output from the learned model 212, and determines whether or not the learned model 212 is compatible with the vehicle (step S11).
[0148] If it is determined that the trained model 212 is suitable for the vehicle, the processor 201 ends the process. In this case, the trained model 212 is not updated.
[0149] If it is determined that the trained model 212 is not suitable for the vehicle, the processor 201 reads the vehicle information 214 from the non-volatile memory 202 and transmits a request frame including the vehicle information 214 (step S12). The external communication device 350 receives the request frame, performs necessary processing such as protocol conversion on the received request frame, and then transmits the request frame to the server 500 (step S13).
[0150] When the server 500 receives the request frame, the processor 501 selects a trained model for update from the trained model DB 511 based on the vehicle information included in the request frame (step S14).
[0151] The processor 501 transmits the update model, which is the selected trained model (step S15). The external communication device 350 receives the update model, performs necessary processing such as protocol conversion on the received update model, and transmits the update model to the relay ECU 200 (step S16).
[0152] The relay ECU 200 receives the update model. The processor 201 inputs the first vehicle value included in the log data 213 to the update model. The processor 201 acquires the estimated value output from the update model. The processor 201 compares the second vehicle value included in the log data 213 with the estimated value output from the update model, and determines whether the update model is compatible with the vehicle (step S17).
[0153] If it is determined that the update model is suitable for the vehicle, the processor 201 updates the trained model 212 with the update model.
[0154] If it is determined that the update model is not suitable for the vehicle, the processor 201 creates training data from the log data 213 and performs machine learning using the created training data (step S18). The processor 201 updates the trained model 212 with a new model, which is a trained model generated by machine learning (step S19). Note that FIG. 13 shows an example of the operation of the update system when the update model is not suitable for the vehicle.
[0155] The processor 201 transmits a registration request including the generated new model and the vehicle information 214 (step S20). The external communication device 350 receives the registration request, performs necessary processing such as protocol conversion on the received registration request, and then transmits the registration request to the server 500 (step S21).
[0156] When the server 500 receives the registration request, the processor 501 registers the vehicle information 214 and the new model included in the registration request in the trained model DB 511 (step S22).
[0157] [8. Modifications] In the above-described embodiment, the trained model DB 511 is provided in the server 500, but this is not limiting. For example, a database server including the same database as the trained model DB 511 may be provided separately from the server 500. In this case, for example, the server 500 may access the database server and select an update model that matches the vehicle information.
[0158] In the above-described embodiment, a plurality of trained models are stored in the trained model DB 511, but the present invention is not limited thereto. For example, a plurality of trained models may be stored in a file system. In this case, the server 500 stores a table that stores storage locations (directories) of trained models in association with vehicle information, and can identify the storage location of a trained model that matches the vehicle information by referring to the table. The server 500 can acquire the trained model from the identified storage location and download the acquired trained model to the vehicle. In another example, the server 500 can transmit the storage location of the trained model to the external communication device 350 in response to the request. The external communication device 350 can download the trained model from the received storage location, for example, by FTP (File Transfer Protocol), and transfer the downloaded trained model to the relay ECU 200.
[0159] In the above-described embodiment, the trained model for update is selected based on the vehicle type, model year, and total mileage of the vehicle, but is not limited thereto. In addition to the above-described vehicle information, or instead of at least one of them, the trained model for update may be selected based on the country or region in which the vehicle is registered. Different countries or regions have different climates, and the progression of vehicle deterioration differs depending on the climate. Therefore, it is considered that a trained model corresponding to the same country or region as the requesting vehicle is likely to be compatible with the requesting vehicle.
[0160] In the above-described embodiment, the trained model 212 is a neural network model, but is not limited to this. A trained model generated by a supervised machine learning algorithm other than a neural network, such as a decision tree or a support vector machine, may be used.
[0161] In the embodiment described above, the relay ECU 200 stores the trained model 212 and determines whether the trained model 212 is compatible with the vehicle, but this is not limited to the above. The ECU 300 may store the trained model 212 and determine whether the trained model 212 is compatible with the vehicle.
[0162] [9. Notes] [Appendix 1] A method for updating a trained model used to detect fraudulent frames in an in-vehicle device, comprising: a step of inputting a first vehicle value transmitted through an in-vehicle network to which the in-vehicle device is connected as input data into a first trained model that outputs an estimated value correlated with the first vehicle value, and acquiring, by the in-vehicle device, the estimated value output from the first trained model; The in-vehicle device compares the acquired estimated value with a second vehicle value transmitted through the in-vehicle network to determine whether the first trained model is adapted to the vehicle; When it is determined that the first trained model is not suitable for the vehicle, a server selects a second trained model for updating the first trained model; The server transmits the selected second trained model to the in-vehicle device; A step of receiving the second trained model transmitted from the server by the in-vehicle device; The in-vehicle device updates the first trained model to the received second trained model; Including, How to update.
[0163] [Appendix 2] An update method for an in-vehicle device connected to an in-vehicle network to update a trained model used for detecting fraudulent frames in the in-vehicle device, the update method comprising: A step of inputting a first vehicle value transmitted through the in-vehicle network into a first trained model that uses the first vehicle value as input data and outputs an estimated value correlated with the first vehicle value, and acquiring the estimated value output from the first trained model; A step of comparing the estimated value output from the first trained model with a second vehicle value transmitted through the in-vehicle network to determine whether the first trained model is adapted to the vehicle; receiving, from a server, a second trained model for updating the first trained model when it is determined that the first trained model is not suitable for the vehicle; updating the first trained model to the received second trained model; Including, How to update.
[0164] [Appendix 3] An update program for updating a trained model used to detect fraudulent frames in an in-vehicle device connected to an in-vehicle network, comprising: On the computer, A step of inputting a first vehicle value transmitted through the in-vehicle network into a first trained model that uses the first vehicle value as input data and outputs an estimated value correlated with the first vehicle value, and acquiring the estimated value output from the first trained model; A step of comparing the estimated value output from the first trained model with a second vehicle value transmitted through the in-vehicle network to determine whether the first trained model is adapted to the vehicle; receiving, from a server, a second trained model for updating the first trained model when it is determined that the first trained model is not suitable for the vehicle; updating the first trained model to the received second trained model; In order to execute Updates.
[0165] [Appendix 4] A method for providing an in-vehicle device connected to an in-vehicle network with a trained model used for detecting an unauthorized frame, the method comprising: a step of selecting a second trained model for updating the first trained model when it is determined that the first trained model is not suitable for the vehicle by comparing an estimated value output from a first trained model, the first trained model using a first vehicle value transmitted through the in-vehicle network as input data and outputting an estimated value correlated with the first vehicle value, with a second vehicle value transmitted through the in-vehicle network; Transmitting the selected second trained model to the in-vehicle device; Including, How it is provided.
[0166] [Appendix 5] A provision program for providing a trained model used for detecting fraudulent frames in an in-vehicle device connected to an in-vehicle network to the in-vehicle device, the trained model comprising: On the computer, a step of selecting a second trained model for updating the first trained model when it is determined that the first trained model is not suitable for the vehicle by comparing an estimated value output from a first trained model, the first trained model using a first vehicle value transmitted through the in-vehicle network as input data and outputting an estimated value correlated with the first vehicle value, with a second vehicle value transmitted through the in-vehicle network; Transmitting the selected second trained model to the in-vehicle device; In order to execute Programs offered.
[0167] [10. Supplementary Note] The embodiments disclosed herein are illustrative in all respects and are not restrictive. The scope of the present invention is defined by the claims rather than the above-described embodiments, and includes the meaning equivalent to the claims and all modifications within the scope thereof. [Explanation of symbols]
[0168] 10 Update System 100 In-vehicle systems 200 Relay ECU (relay device, on-board device) 201 Processor 202 Non-volatile memory 203 Volatile Memory 204A, 204B, 204C Communication interface (communication I / F) 210 Malicious Frame Detection Program 211 Update 212 trained models 213 Log Data 214 Vehicle Information 221 Mode setting section 231 Input section 232 Frame Determination Unit 233 Output section 241 Input section 242 1st Compatibility Judgment Department 243 Request part 244 Receiving section 245 Input section 246 Second Compatibility Determination Section 247 Update Department 248 Learning Department 249 Storage control section 300,300A,300B,300C,300D,300E ECU (vehicle equipment) 310A, 310B, 310C, 310D Sensors 350 External communication device 370 Diagnostic Equipment 400A, 400B, 400C communication bus 410 Connector 500 servers 501 Processor 502 Non-volatile memory 503 Volatile Memory 504 Communication Interface (Communication I / F) 510 Programs Offered 511 Trained Model Database 521 Receiving unit 522 Selection section 523 Transmitter
Claims
1. An in-vehicle device; A server; Equipped with The in-vehicle device includes: a first trained model that uses a first vehicle value transmitted through an in-vehicle network to which the in-vehicle device is connected as input data and outputs an estimated value correlated with the first vehicle value; a first determination unit that compares the estimated value output from the first trained model with a second vehicle value transmitted through the in-vehicle network to determine whether the first trained model is compatible with the vehicle; Including, The server, a selection unit that selects a second trained model for updating the first trained model when the first determination unit determines that the first trained model is not suitable for the vehicle; and A transmission unit that transmits the second trained model selected by the selection unit to the in-vehicle device; Including, The in-vehicle device includes: A receiving unit that receives the second trained model transmitted from the server; An update unit that updates the first trained model to the second trained model received by the receiving unit; Including, Update system.
2. The in-vehicle device further includes a storage unit configured to store a first vehicle value and a second vehicle value previously transmitted through the in-vehicle network; the first determination unit inputs the first vehicle value stored in the storage unit into the first learned model, and compares the estimated value output from the first learned model with the second vehicle value stored in the storage unit to determine whether the first learned model is compatible with the vehicle; The update system of claim 1 .
3. The first determination unit determines whether or not the first trained model is adapted to the vehicle when the vehicle is stopped. The update system of claim 2.
4. The in-vehicle device includes: A mode setting unit sets an operation mode to either a normal mode in which the vehicle runs or a maintenance mode for performing maintenance on the vehicle, The first determination unit determines whether or not the first trained model is adapted to the vehicle when the operation mode is set to the maintenance mode. The update system of claim 2.
5. The in-vehicle device further includes a second determination unit that, when the operation mode is set to the normal mode, compares the estimated value output from the first learned model with a second vehicle value transmitted through the in-vehicle network to determine whether a frame including the second vehicle value is an unauthorized frame. The update system of claim 4.
6. The selection unit selects the second trained model based on vehicle information related to the vehicle. The update system of claim 1 .
7. The vehicle information includes a model of the vehicle. The update system of claim 6.
8. The vehicle information includes a model year of the vehicle. The update system of claim 6.
9. The vehicle information includes a total mileage of the vehicle. The update system of claim 6.
10. The vehicle information includes the vehicle model, year, and total mileage of the vehicle; The selection unit selects the second trained model corresponding to a vehicle type and a year included in the vehicle information, When there are a plurality of second trained models corresponding to the vehicle type and year included in the vehicle information, the selection unit selects one of the plurality of second trained models based on the total mileage included in the vehicle information. The update system of claim 6.
11. The selection unit selects the second trained model from a storage unit that stores a plurality of trained models. The update system of claim 1 .
12. The in-vehicle device includes: a third determination unit that compares an estimated value output from the second trained model with a second vehicle value transmitted through the in-vehicle network to determine whether the second trained model is compatible with the vehicle; a learning unit that generates a third learned model by performing supervised learning using the first vehicle value and the second vehicle value transmitted through the in-vehicle network as teacher data when the third determination unit determines that the second learned model is not suitable for the vehicle; and Further comprising: The update unit updates the first trained model to the third trained model generated by the learning unit. An update system according to any one of claims 1 to 11.
13. The in-vehicle device further includes a storage control unit that stores the third trained model generated by the learning unit in a storage unit that stores a plurality of trained models available in a plurality of vehicles. The update system of claim 12.
14. the in-vehicle device is a relay device connected to a plurality of communication lines included in the in-vehicle network and relays frames between the plurality of in-vehicle devices; The update system of claim 1 .
15. An in-vehicle device connected to an in-vehicle network, A first trained model that uses a first vehicle value transmitted through the in-vehicle network as input data and outputs an estimated value correlated with the first vehicle value; a first determination unit that compares the estimated value output from the first trained model with a second vehicle value transmitted through the in-vehicle network to determine whether the first trained model is compatible with the vehicle; a receiving unit that receives a second trained model for updating the first trained model from a server when the first determination unit determines that the first trained model is not suitable for the vehicle; and An update unit that updates the first trained model to the second trained model received by the receiving unit; Equipped with In-vehicle device.
16. A server capable of communicating with an in-vehicle device, a selection unit that uses a first vehicle value transmitted through an in-vehicle network to which an in-vehicle device is connected as input data, and outputs an estimated value correlated to the first vehicle value, and compares the estimated value output from a first trained model with a second vehicle value transmitted through the in-vehicle network, and selects a second trained model for updating the first trained model when it is determined that the first trained model is not suitable for the vehicle; A transmission unit that transmits the second trained model selected by the selection unit to the in-vehicle device; Equipped with server.