Intrusion detection method and apparatus, and vehicle
By obtaining and analyzing the characteristic data of surrounding traffic objects in autonomous driving vehicles and detecting intrusion events, the problem of vehicle out of control under positioning signal forgery attacks is solved, and detection and defense of large-scale position signal counterfeiting attacks is realized, ensuring the safe driving of the vehicle.
Patent Information
- Application Number
- PCT/CN2024/131072
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-14
- Filing Date
- 2024-11-08
- Publication Date
- 2025-05-22
AI Technical Summary
Autonomous vehicles may lead to out of control under positioning signal forgery attacks, and prior art is difficult to effectively detect and defend against these attacks.
This data is analyzed by obtaining characteristic data of static and dynamic traffic objects around the vehicle and using intrusion detection rules to determine whether an intrusion event has occurred. This method relies on the sensor equipment that has been equipped by the vehicle, avoids direct dependence on GPS signals, and realizes detection of large-scale position signal counterfeiting attacks.
Effectively detect and defend against attacks on positioning signals of autonomous vehicles, ensure the safe driving of the vehicle without adding additional hardware costs.
Smart Images

Figure CN2024131072_22052025_PF_FP_ABST
Abstract
Description
Intrusion detection method, device and vehicle
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on November 14, 2023, with application number 202311519004.6 and application name "A method, device and vehicle for intrusion detection", the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of vehicle technology, and in particular to an intrusion detection method, device, and vehicle. Background Art
[0004] Currently, vehicles achieve autonomous driving through internal autonomous driving systems that calculate routes based on maps and information about the vehicle's surroundings. Safe operation relies on both awareness of surrounding obstacles and centimeter-level positioning on maps by global satellite navigation systems. Misaligned positioning can cause the vehicle to run off the road or in the wrong direction, leading to an accident.
[0005] Attackers can deceive the intelligent driving systems of autonomous vehicles by forging positioning signals, leading to loss of control due to positioning errors. Therefore, detecting these attacks to ensure the safe operation of autonomous vehicles remains a critical issue that needs to be addressed.
[0006] Summary of the Invention
[0007] The present application provides an intrusion detection method, device, and vehicle for detecting attacks on vehicle positioning signals to ensure the safe driving of autonomous vehicles.
[0008] In the first aspect, the present application provides an intrusion detection method, which can be performed by an intrusion detection device, which can be an independent device, a chip or component in a device, or software. The intrusion detection device can be deployed on a vehicle, which can be a vehicle in a fully manual driving mode, or a vehicle in a fully automatic driving mode, or the vehicle can be configured as a vehicle in a partially automatic driving mode. A vehicle in a partially automatic driving mode, for example, means that the vehicle can control itself while in automatic driving mode, and can determine the current state of the vehicle and the surrounding environment through human operation, determine the possible behavior of at least one other vehicle in the surrounding environment, and control the vehicle based on the determined information. When the vehicle is in a fully automatic driving mode, the vehicle can be set to operate without human interaction. The present application does not limit the product form and deployment method of the intrusion detection device.
[0009] The method includes: obtaining first characteristic data, the first characteristic data describing information about static traffic objects related to the area where the first vehicle is located; obtaining second characteristic data, the second characteristic data describing information about dynamic traffic objects related to the area where the first vehicle is located; determining the occurrence of an intrusion event based on the first characteristic data, the second characteristic data and an intrusion detection rule, the intrusion detection rule describing a detection method for an intrusion event associated with the service to be detected of the first vehicle; and sending an alarm message to the intelligent driving system of the first vehicle, the alarm message indicating the intrusion event. The service to be detected includes a positioning service. In this application, autonomous driving and intelligent driving both refer to the driving behavior performed by a vehicle under the control of an intelligent driving system, and are not distinguished.
[0010] Through the above method, the intrusion detection device can perform intrusion detection based on the information of static traffic objects and dynamic traffic objects to prevent attackers from blocking the vehicle's position sensor and then forging the position information to perform a counterfeit attack. In this method, the feature data relied on for intrusion detection does not come from the position sensor, and can effectively detect a large range of position signal counterfeit attacks without incurring additional hardware costs.
[0011] In combination with the first aspect, in a possible design, obtaining the first characteristic data includes: filtering the first characteristic data from N types of third characteristic data, wherein the N types of third characteristic data are obtained after perceptual processing of N types of perception data, and the N types of perception data are original perception data collected by N sensors associated with the first vehicle, N is greater than or equal to 1, and the N sensors do not include position sensors.
[0012] Through the above method, the feature data relied on for intrusion detection does not come from the position sensor but from other sensor devices installed on the vehicle, which can effectively detect a wide range of position signal counterfeiting attacks.
[0013] In combination with the first aspect, in one possible design, the perception processing includes multi-target detection processing, the N types of third feature data include labels of identified traffic objects, and filtering the first feature data from the N types of third feature data includes: filtering the first feature data from the N types of third feature data according to the labels, wherein the labels associated with the first feature data are used to describe the static traffic objects.
[0014] Through the above method, the vehicle's various sensors can be used to obtain specific static features of the surrounding environment and road conditions for intrusion detection, thereby preventing attackers from blocking the global positioning system (GPS) signal receiving device and then forging GPS signals to conduct counterfeit attacks.
[0015] In combination with the first aspect, in a possible design, the dynamic traffic objects include other vehicles within a first range around the first vehicle, and obtaining the second characteristic data includes: obtaining the second characteristic data based on N types of third characteristic data, wherein the second characteristic data includes the number of the other vehicles, and the N types of third characteristic data are obtained after perception processing of N types of perception data, and the N types of perception data are original perception data collected by N sensors associated with the first vehicle, and N is greater than or equal to 1.
[0016] Through the above method, the vehicle's various sensors can be used to obtain specific dynamic characteristics of the surrounding environment and road conditions for intrusion detection, thereby preventing attackers from forging GPS signals based on locations with similar environmental characteristics.
[0017] In combination with the first aspect, in a possible design, the service to be detected is associated with the location information of the first vehicle, the intrusion detection rule includes analyzing the difference in information obtained by different means, and the method further includes: obtaining the first location information of the first vehicle through the positioning component of the first vehicle; obtaining the fourth feature data of the first vehicle from the map server, the fourth feature data being the information of the surrounding vehicles of the first vehicle provided by the map server; determining the occurrence of an intrusion event based on the first feature data, the second feature data and the intrusion detection rule, including: when the difference between the location information determined according to the first feature data and the first location information meets the first condition, and the difference between the second feature data and the fourth feature data meets the second condition, determining that a positioning intrusion event has occurred.
[0018] Through the above method, the GPS signal detection feature does not come from the GPS signal itself, and can effectively detect a large range of GPS signal spoofing attacks. At the same time, it only needs to rely on the sensor equipment and computing equipment already installed in the autonomous driving vehicle, without relying on other hardware support and without incurring additional hardware costs.
[0019] In combination with the first aspect, in a possible design, the first condition includes: the similarity between the location information determined based on the first feature data and the first location information is less than or equal to a first threshold value, and the method further includes: inputting the feature data associated with different sensors in the first feature data into M location prediction models to obtain M location prediction values, where M is greater than 1; weighting the M location prediction values to obtain the location information determined based on the first feature data; wherein each of the M location prediction models is used to predict a location information based on feature data obtained based on a sensor, and the M location prediction models are trained based on samples in a feature library associated with GPS services. Exemplarily, the M location prediction models include a supervised learning model corresponding to at least one of the following sensors: a camera, a lidar sensor, a millimeter-wave radar sensor, or an ultrasonic radar sensor.
[0020] Through the above method, multiple location prediction models can be pre-trained to predict the vehicle's location information based on the original perception data collected by different sensors, and the predicted location information can be compared with the location information collected by the location sensor to determine whether GPS spoofing exists.
[0021] In combination with the first aspect, in one possible design, the fourth characteristic data includes a reference number of other vehicles within a first range around the first vehicle; the second condition includes: the similarity between the number of other vehicles indicated by the second characteristic data and the reference number of other vehicles indicated by the fourth characteristic data is less than or equal to a second threshold.
[0022] In the second aspect, the present application provides an intrusion detection device, including: a first acquisition unit, used to acquire first characteristic data, the first characteristic data describes information about static traffic objects related to the area where the first vehicle is located; a second acquisition unit, used to acquire second characteristic data, the second characteristic data describes information about dynamic traffic objects related to the area where the first vehicle is located; a determination unit, used to determine the occurrence of an intrusion event based on the first characteristic data, the second characteristic data and an intrusion detection rule, the intrusion detection rule describes a detection method for an intrusion event associated with the business to be detected of the first vehicle; a communication unit, used to send an alarm message to the intelligent driving system of the first vehicle, the alarm message indicating the intrusion event.
[0023] In combination with the second aspect, in a possible design, the first acquisition unit is used to: filter the first feature data from N types of third feature data, wherein the N types of third feature data are obtained after perception processing of N types of perception data, and the N types of perception data are original perception data collected by N sensors associated with the first vehicle, and N is greater than or equal to 1.
[0024] In combination with the second aspect, in one possible design, the perception processing includes multi-target detection processing, the N types of third feature data include labels of identified traffic objects, and the first acquisition unit filters the first feature data from the N types of third feature data, including: filtering the first feature data from the N types of third feature data according to the label, wherein the label associated with the first feature data is used to describe the static traffic object.
[0025] In combination with the second aspect, in a possible design, the dynamic traffic objects include other vehicles within a first range around the first vehicle, and the second acquisition unit is used to: obtain the second feature data based on N types of third feature data, wherein the second feature data includes the number of the other vehicles, and the N types of third feature data are obtained after perception processing of N types of perception data, and the N types of perception data are original perception data collected by N sensors associated with the first vehicle, and N is greater than or equal to 1.
[0026] In combination with the second aspect, in a possible design, the service to be detected is associated with the location information of the first vehicle, the intrusion detection rule includes analyzing the differences in information obtained through different methods, and the determination unit is further used to: obtain the first location information of the first vehicle through the positioning component of the first vehicle; obtain the fourth feature data of the first vehicle from the map server, and the fourth feature data is the information of the surrounding vehicles of the first vehicle provided by the map server; when the difference between the location information determined according to the first feature data and the first location information meets the first condition, and the difference between the second feature data and the fourth feature data meets the second condition, it is determined that an intrusion event has occurred.
[0027] In combination with the second aspect, in a possible design, the first condition includes: the similarity between the location information determined based on the first feature data and the first location information is less than or equal to a first threshold, and the determination unit is used to: input the feature data associated with different sensors in the first feature data into M location prediction models to obtain M location prediction values, where M is greater than 1; and obtain the location information determined based on the first feature data by weighting according to the M location prediction values; wherein each of the M location prediction models is used to predict a location information for feature data obtained based on a sensor, and the M location prediction models are trained based on samples in a feature library associated with the GPS service.
[0028] In combination with the second aspect, in one possible design, the M position prediction models include a supervised learning model corresponding to at least one of the following sensors: a camera, a lidar sensor, a millimeter-wave radar sensor, or an ultrasonic radar sensor.
[0029] In combination with the second aspect, in one possible design, the fourth characteristic data includes a reference number of other vehicles within a first range around the first vehicle; the second condition includes: the similarity between the number of other vehicles indicated by the second characteristic data and the reference number of other vehicles indicated by the fourth characteristic data is less than or equal to a second threshold.
[0030] In a third aspect, the present application provides a communication device comprising at least one processor and an interface circuit, wherein the interface circuit is used to provide data or code instructions to the at least one processor, and the at least one processor is used to implement the method described in the first aspect and any possible design of the first aspect through a logic circuit or executing code instructions.
[0031] In a fourth aspect, the present application provides a computer-readable storage medium, which stores program code. When the program code runs on a computer, the computer executes the method described in the first aspect and any possible design of the first aspect.
[0032] In a fifth aspect, the present application provides a computer program product, which, when executed on a computer, enables the computer to execute the method described in the first aspect and any possible design of the first aspect.
[0033] In a sixth aspect, the present application provides a chip comprising a processor, which is coupled to a memory and is used to execute a computer program or instruction stored in the memory. When the computer program or instruction is executed, the method described in the first aspect and any possible design of the first aspect is implemented.
[0034] In a seventh aspect, an embodiment of the present application provides a vehicle, comprising a module for implementing the method described in the first aspect and any possible design of the first aspect, or the intrusion detection device described in the second aspect and any possible design of the second aspect.
[0035] Based on the implementations provided in the above aspects, the embodiments of the present application can be further combined to provide more implementations.
[0036] The technical effects that can be achieved by any possible implementation method in any of the second to seventh aspects mentioned above can be referred to the description of the technical effects that can be achieved by any possible implementation method in any of the first aspect mentioned above, and the repetitions will not be discussed. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] FIG1 is a schematic diagram showing an application scenario to which the present application is applicable;
[0038] FIG2 shows a schematic structural diagram of a vehicle of the present application;
[0039] FIG3 shows a schematic flow chart of the intrusion detection method of the present application;
[0040] FIG4 shows a schematic diagram of the process of generating a feature library and training a model in the present application;
[0041] FIG5 shows a schematic diagram of the principle of model training of the present application;
[0042] FIG6 shows a schematic flow chart of the intrusion detection method of the present application;
[0043] FIG7 shows a schematic diagram of the prediction process based on the position prediction model of the present application;
[0044] FIG8 shows a schematic structural diagram of a communication device of the present application;
[0045] FIG9 shows a schematic structural diagram of the communication device of the present application. DETAILED DESCRIPTION
[0046] The embodiments of the present application provide an intrusion detection method, device, and vehicle for detecting attacks on vehicle positioning signals to ensure the safe driving of autonomous vehicles. The method and device are based on the same technical concept. Since the principles of the method and device for solving problems are similar, the implementation of the device and the method can refer to each other, and the repeated parts will not be repeated. In addition, in the various embodiments of the present application, unless otherwise specified and there is a logical conflict, the terms and / or descriptions between the various embodiments are consistent and can be referenced to each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0047] The intrusion detection scheme of the present application can be applied to the Internet of Vehicles, such as vehicle to everything (V2X), long term evolution-vehicle (LTE-V), vehicle to vehicle (V2V), etc. For example, it can be applied to a vehicle, or other devices in a vehicle. The other devices include but are not limited to: other sensors such as an on-board terminal, an on-board control unit, an on-board module, an on-board module, an on-board component, an on-board chip, an on-board unit, an on-board radar or an on-board camera. The vehicle can implement the intrusion detection method provided in the embodiment of the present application through the on-board terminal, the on-board control unit, the on-board module, the on-board module, the on-board component, the on-board chip, the on-board unit, the on-board radar or the on-board camera. Of course, the intrusion detection scheme in the embodiment of the present application can also be used for other intelligent terminals with mobile control functions other than the vehicle, or be set in other intelligent terminals with mobile control functions other than the vehicle, or be set in a component of the intelligent terminal. The intelligent terminal can be an intelligent transportation device, an intelligent home device, a robot, etc. It also includes but is not limited to smart terminals or control units, chips, radars, cameras and other sensors, and other components within smart terminals.
[0048] In the embodiments of the present application, "at least one" refers to one or more, and "more" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, c can be single or multiple.
[0049] Also, unless otherwise specified, ordinal numbers such as "first" and "second" mentioned in the embodiments of the present application are used to distinguish multiple objects and are not used to limit the priority or importance of multiple objects.
[0050] The following describes the embodiments of the present application in conjunction with the accompanying drawings.
[0051] FIG1 is a schematic diagram of an application scenario applicable to an embodiment of the present application. This application scenario may include a vehicle 100. In one possible implementation, this application scenario may also include a cloud server 200, and the vehicle 100 and the cloud server 200 may communicate via a network. In one embodiment, the cloud server 200 may be implemented as a virtual machine.
[0052] Some or all functions of the vehicle 100 are controlled by a computing platform 150 (or computer system). The computing platform 150 may include at least one processor 151, which may execute instructions 153 stored in a non-transitory computer-readable medium such as a memory 152. In some embodiments, the computing platform 150 may also be a plurality of computing devices that control individual components or subsystems of the vehicle 100 in a distributed manner. The processor 151 may be any conventional processor, such as a central processing unit (CPU). Alternatively, the processor 151 may also include a graphics processing unit (GPU), a field programmable gate array (FPGA), a system on chip (SoC), an application-specific integrated circuit (ASIC), or a combination thereof.
[0053] Alternatively, the vehicle 100 may be a car, truck, motorcycle, bus, boat, airplane, helicopter, lawn mower, recreational vehicle, amusement park vehicle, construction equipment, tram, golf cart, train, etc., and the present embodiment does not impose any particular limitation. In one possible implementation, the vehicle 100 may be a new energy vehicle.
[0054] The structure of the vehicle in FIG1 should not be understood as limiting the embodiments of the present application.
[0055] The intrusion detection method of the embodiment of the present application can be implemented by an intrusion detection device, which can be an independent device, a chip or component in the vehicle 100 shown in Figure 1, or a software module, which can be deployed on the relevant on-board equipment of the vehicle 100. In the following, for the sake of ease of understanding and description, the intrusion detection scheme of the embodiment of the present application will be introduced by taking the intrusion detection device as the processor of the computing platform 150 integrated in the aforementioned vehicle 100 as an example. In other embodiments, the intrusion detection scheme can also be integrated into other electronic control units (ECU) of the vehicle, such as an intelligent driving domain control unit, or a vehicle control unit (VCU), etc. The embodiment of the present application does not limit the product form or deployment method of the intrusion detection device.
[0056] Fig. 2 shows a possible structural diagram of a vehicle 100. The vehicle 100 may include a sensing device, an intrusion detection device, and an execution device.
[0057] As shown in FIG2 , the sensing device can obtain sensing data of the environment in which the vehicle is located, and keep monitoring and collecting data on the environment around the vehicle at all times. The sensing device may include at least one sensor in the vehicle's sensing system, and the sensing system may include but is not limited to: a camera, a light detection and ranging (LIDAR), a millimeter-wave radar (RADAR), an ultrasonic radar sensor or other sensor devices. The sensing data obtained by the sensing system may include: an image or video of the vehicle's current surroundings, a target object (such as a traffic object) identified based on the image or video, and the distance (or interval) between the vehicle and the identified target object. Optionally, the sensing system may also include a position sensor, which may be, for example, a GPS receiver, which can be used to receive the vehicle's position information.
[0058] The sensing device may provide the acquired sensing data to the intrusion detection device. For example, the sensing device may send the sensing data to the intrusion detection device via an in-vehicle communication network (eg, an onboard bus, not shown).
[0059] In one example, the intrusion detection device itself can be equipped with the ability to perform perception processing on raw perception data, and can obtain a variety of raw perception data from various sensors, and perform perception processing on the obtained raw perception data to obtain a variety of feature data. The intrusion detection device can filter out the feature data required for performing intrusion detection analysis from the obtained feature data, such as first feature data and second feature data, where the first feature data describes information about static traffic objects related to the vehicle's area, and the second feature data describes information about dynamic traffic objects related to the vehicle's area. The intrusion detection device can perform intrusion detection analysis based on the filtered first and second feature data to determine whether an intrusion event has occurred.
[0060] In another example, the intrusion detection device itself may not have the function of performing perception processing on the original perception data, but may obtain the original perception data from various sensors with the help of other devices (such as the fusion perception module of the intelligent driving system, not shown in Figure 2), and perform perception processing on the original perception data. The fusion perception module can provide the corresponding feature data obtained after the perception processing to the intrusion detection device. For example, the fusion perception module can send the corresponding feature data obtained after the perception processing to the intrusion detection device through the in-vehicle communication network. The intrusion detection device can filter out the feature data required to perform intrusion detection analysis from the multiple feature data obtained, such as first feature data and second feature data, the first feature data describing the information of static traffic objects related to the area where the vehicle is located, and the second feature data describing the information of dynamic traffic objects related to the area where the vehicle is located. The intrusion detection device can perform intrusion detection analysis based on the filtered first feature data and second feature data to determine whether an intrusion event has occurred.
[0061] In the embodiment of the present application, traffic objects include any traffic participants other than the vehicle in the area where the vehicle is located, including but not limited to the vehicle's current lane and the lane markings of the current lane; other vehicles around the vehicle in the current lane (including the vehicle in front and behind); adjacent lanes of the current lane and the lane markings of adjacent lanes; several other vehicles in adjacent lanes; pedestrians in the current lane, adjacent lanes, or at road intersections; various traffic facilities: such as crosswalks, roadside units (RSUs), traffic lights (such as motor vehicle lights, non-motor vehicle lights, crosswalk lights, direction indicators, lane lights, flashing lights, road-railway intersection lights, etc.), fences, lighting facilities, sight guidance signs, highway reflectors, highway information boards, etc.; buildings or mountains around the area, etc. Among them, dynamic traffic objects include dynamic traffic participants such as vehicles and pedestrians, which will move over time according to traffic rules. Static objects include lane lines, traffic facilities, buildings, mountains and other static traffic participants. These static traffic objects remain unchanged (for example, their position remains unchanged) within a certain time range. That is, they are relatively fixed traffic participants with a low frequency of change and will not move over time like dynamic traffic objects.
[0062] The aforementioned perception processing may include, but is not limited to, semantic segmentation and multi-target detection of the raw perception data. Through perception processing, characteristic data of various traffic objects surrounding the vehicle's location can be obtained, represented, for example, as third characteristic data. The intrusion detection device may filter the aforementioned first characteristic data and / or second characteristic data from the various third characteristic data and perform intrusion detection analysis based on the filtered first and second characteristic data to determine whether an intrusion event has occurred.
[0063] The intrusion detection device may be pre-installed with an intrusion detection rule that describes a method for detecting intrusion events associated with the vehicle's service to be detected. The intrusion detection device may use the filtered feature data and the intrusion detection rule to analyze whether an intrusion event associated with the service to be detected has occurred. For example, the intrusion detection rule describes the conditions that must be met for different features corresponding to an intrusion event. If the filtered feature data meets the corresponding conditions described in the intrusion detection rule, the intrusion detection device may deem that the intrusion event has occurred. If the filtered feature data does not meet the corresponding conditions described in the intrusion detection rule, the intrusion detection device may deem that the intrusion event has not occurred.
[0064] As an example, the detection method described by the intrusion detection rule may be a method of analyzing whether an intrusion event has occurred by comparing the above-mentioned first feature data or second feature data with their respective corresponding reference information. The reference information corresponding to the first feature data may include the vehicle position information obtained by the vehicle's positioning component (such as a position sensor), and the reference information corresponding to the second feature data may include feature data obtained from a map server (such as the number of surrounding vehicles). If the difference between the position information determined according to the first feature data and the vehicle position information obtained by the vehicle's positioning component meets the first condition, and if the difference between the second feature data and the feature data obtained from the map server meets the second condition, it can be determined that an intrusion event has occurred. The first condition includes, for example, that the similarity of the position information obtained by different means is less than or equal to a first threshold, and the second condition includes, for example, that the similarity of the number of other surrounding vehicles obtained by different means is less than or equal to a second threshold. This analysis process will be described in detail below in conjunction with the method embodiment, and will not be repeated here.
[0065] Upon determining an intrusion event, the intrusion detection device can send an alert indicating the intrusion event to the vehicle's execution device. The execution device, in turn, can receive the alert from the intrusion detection device and, based on the alert, perform vehicle-related control operations to ensure safe driving.
[0066] Exemplarily, the service to be detected may include the intelligent driving service of the vehicle, the execution device may include the intelligent driving system of the vehicle, and the intrusion event may include an event in which an attacker forges the location information of the vehicle or forges the information of other surrounding vehicles to "cheat" the intelligent driving system of the vehicle. If the intrusion detection device determines that an intrusion event has occurred after analyzing the obtained characteristic data, it can send an alarm message to the intelligent driving system of the vehicle through the vehicle communication network (such as a gateway) to indicate the intrusion event, so that the intelligent driving system can make intelligent driving decisions (such as path planning, vehicle control decisions, etc.) based on the alarm information, and send control commands to the ECU related to the vehicle control to reduce or even eliminate the interference caused by the intrusion event on the intelligent driving control decision, assist in controlling the safe driving of the vehicle, and thus ensure the safe driving of the vehicle.
[0067] Among them, the vehicle control-related ECU may include a motor control unit (MCU), and the MCU may include, for example, a front axle motor control unit (denoted as MCU_F) or a rear axle motor control unit (denoted as MCU_R). Or, for example, the vehicle control-related ECU may include an electronic stability control system (ESC). Or, for example, the vehicle control-related ECU may include a vehicle braking system, specifically an integrated power brake (IPB), which may integrate, for example, an anti-lock brake system (ABS), ESP, an acceleration slip regulation (ASR) (also known as a traction control system), etc. The embodiments of the present application do not limit the specific implementation of this vehicle control-related ECU.
[0068] In an optional embodiment, the execution device may further include a smart cockpit of the vehicle, which may include the vehicle's central control display, head-up display, audio system, seat vibration, lighting, etc. The smart cockpit may receive warning information from the intrusion detection device and output the warning information through the central control display, head-up display, audio system, seat vibration, lighting, etc. for reference by vehicle occupants (including the driver or other occupants), thereby assisting the vehicle driver in controlling the vehicle's safe driving, or enabling other occupants to provide driving assistance to the vehicle driver based on the warning information.
[0069] In another optional embodiment, the intrusion detection device may also send an alert message to a peripheral device associated with the vehicle (e.g., a user's mobile smart device) via a gateway to indicate an intrusion event to the user, allowing the user to promptly learn of the intrusion event and make appropriate solutions. The description of the execution device or peripheral device herein is provided as an example and not as a limitation. In other embodiments, the intrusion detection device may also send an alert message to other vehicle components or associated devices to promptly detect and resolve intrusion events. This description is omitted here.
[0070] In an embodiment of the present application, the intrusion detection rules may be pre-stored on a storage medium accessible to the intrusion detection device, which may be a local storage device of the vehicle or a cloud server, and this embodiment of the present application does not limit this. In an optional implementation, the operator may pre-design at least one intrusion detection rule for different attack methods based on crowdsourced data and experience. The intrusion detection device may obtain and save at least one intrusion detection rule from the cloud server as needed, or may manually save at least one intrusion detection rule on a local storage device of the vehicle, and this embodiment of the present application does not limit the method for obtaining the at least one intrusion detection rule.
[0071] In Figure 2, the bidirectional arrows between different modules are only used to indicate that the corresponding modules can communicate with each other, and do not limit any communication method or information format. The other modules in the vehicle shown in Figure 2 are only examples, and the dotted boxes only indicate that the corresponding modules are optional modules. The vehicle may not contain some of the modules shown in Figure 2, or may include other modules in addition to some of the modules shown in Figure 2, or some of the modules in Figure 2 may be replaced by other modules not shown, which will not be repeated here. In some designs, the vehicle's sensing system may also be integrated into any one of the MDC, VCU or vehicle domain controller (VDC). The embodiments of the present application do not limit the product form or integration method of different modules of the vehicle.
[0072] The intrusion detection method of the embodiment of the present application can be implemented in combination with the system architecture shown in Figures 1 and 2. Referring to Figure 3, the intrusion detection method may include the following steps:
[0073] S310: The intrusion detection device obtains first feature data.
[0074] In the embodiment of the present application, the first characteristic data describes information about static traffic objects related to the area where the first vehicle is located.
[0075] Among them, the first vehicle is the self-vehicle introduced above. Static traffic objects include static traffic participants related to the area where the first vehicle is located, such as lane lines, traffic facilities, buildings, mountains, etc. The information of static traffic objects may, for example, include attribute information of the static traffic objects themselves, such as location information, size information, shape information, etc. The information of static traffic objects may also, for example, include information about the static traffic objects relative to the first vehicle, such as distance information and azimuth information of the static traffic objects relative to the first vehicle. The embodiment of the present application does not limit the content of the information of this static traffic object.
[0076] When implementing S310, the intrusion detection device may filter the first characteristic data from N types of third characteristic data. The N types of third characteristic data may be obtained by perceptually processing N types of perception data, where the N types of perception data are road condition information collected by N sensors associated with the first vehicle, the road condition information being, for example, raw perception data, and N being greater than or equal to 1.
[0077] Among them, the intrusion detection device may perform perception processing on the N types of perception data, or other devices may perform perception processing on the N types of perception data, and the embodiments of the present application do not limit this. The perception processing may include but is not limited to semantic segmentation processing, multi-target detection processing, etc. of the original perception data. Taking the original perception data including an image as an example, the N types of third feature data obtained after the perception processing may include, for example, the RGB matrix vector of the image and the labels corresponding to the traffic objects identified in the image. The intrusion detection device can filter the first feature data from the N types of third feature data according to the labels. The labels associated with the first feature data are used to describe static traffic objects, such as lane line features, traffic facility features, building features, mountain features, etc.
[0078] S320: The intrusion detection device obtains second feature data.
[0079] In the embodiment of the present application, the second characteristic data describes information about dynamic traffic objects related to the area where the first vehicle is located.
[0080] Among them, dynamic traffic objects include dynamic traffic participants related to the area where the first vehicle is located, such as other vehicles and pedestrians around the first vehicle. The information of dynamic traffic objects includes, for example, attribute information of the dynamic traffic objects themselves, such as the location information, shape information, size information of other vehicles, etc. The information of dynamic traffic objects may also include, for example, information about the dynamic traffic objects relative to the first vehicle, such as distance information and azimuth information of the dynamic traffic objects relative to the first vehicle. The embodiments of the present application do not limit the content of the information of the dynamic traffic objects.
[0081] When implementing S320, the intrusion detection device may obtain the second feature data based on N types of third feature data. The N types of third feature data may be obtained by perceptually processing N types of perception data, where the N types of perception data are road condition information collected by N sensors associated with the first vehicle, the road condition information being, for example, raw perception data, and N being greater than or equal to 1.
[0082] The intrusion detection device or other device may perform perception processing on the N types of perception data, and this embodiment of the present application does not limit this. The perception processing may include, but is not limited to, semantic segmentation processing and multi-target detection processing of the raw perception data. For example, if the dynamic traffic objects include other vehicles around the first vehicle, the second feature data may include, for example, the number of other vehicles.
[0083] S330: The intrusion detection device determines that an intrusion event occurs based on the first feature data, the second feature data, and an intrusion detection rule.
[0084] In the embodiment of the present application, the intrusion detection rule describes a method for detecting an intrusion event associated with the service to be detected of the first vehicle.
[0085] Taking the service to be detected as the intelligent driving service of a vehicle and the execution device including an intelligent driving system as an example, an intrusion event may include, for example, an event in which an attacker forges the vehicle's location information or forges the information of other surrounding vehicles to "cheat" the vehicle's intelligent driving system. The detection method described in the intrusion detection rule may be a method of comparing the above-mentioned first feature data or second feature data with their respective corresponding reference information to analyze whether an intrusion event has occurred.
[0086] Among them, the reference information corresponding to the first characteristic data may include the first position information of the first vehicle obtained by the positioning component of the first vehicle, and the first characteristic data can be used to determine the position information of the first vehicle, for example, represented as the second position information. The intrusion detection device can compare the first position information with the second position information to determine whether an intrusion event has occurred. The reference information corresponding to the second characteristic data may include the fourth characteristic data of the first vehicle obtained from the map server, and the fourth characteristic data is information about the surrounding vehicles of the first vehicle provided by the map server. The second characteristic data is obtained based on a perception method and is used to determine the information of the surrounding vehicles of the first vehicle. The intrusion detection device can be used to compare the second characteristic data with the fourth characteristic data to determine whether an intrusion event has occurred.
[0087] If an intrusion event is determined to have occurred, the intrusion detection device may further perform the following steps:
[0088] S340: The intrusion detection device sends an alarm message to the intelligent driving system of the first vehicle, where the alarm message indicates the intrusion event.
[0089] Accordingly, the intelligent driving system can receive warning information from the intrusion detection device and, based on this warning information, perform vehicle-related control processing to ensure safe driving. For example, the intelligent driving system can send control commands to the vehicle control ECU, causing it to perform braking, steering, acceleration, deceleration, etc., to assist in controlling the vehicle's safe driving, thereby ensuring safe driving of the vehicle.
[0090] For ease of understanding, the following takes the intelligent driving service as an example of the service to be detected, and introduces the detailed implementation of S310-S340 in combination with the accompanying drawings and embodiments.
[0091] Before implementing S310, the intrusion detection device can generate a feature library associated with the GPS service, and obtain M position prediction models based on sample training in the feature library. The M position prediction models can be used to predict the second position information based on the first feature data when implementing the above S330. The second position information can be used to compare with the first position information of the first vehicle obtained through the positioning component of the first vehicle to analyze whether an intrusion event has occurred.
[0092] As shown in FIG4 , taking the perception processing of raw perception data by the fusion perception module of the intelligent driving system as an example, the process of generating a feature library associated with GPS services and the corresponding model training process may include the following steps:
[0093] S401: N sensors associated with the first vehicle collect N types of raw perception data and provide the N types of raw perception data to a fusion perception module of the intelligent driving system, where N is greater than or equal to 1.
[0094] S402: The fusion perception module of the intelligent driving system performs perception processing on the N types of original perception data obtained, such as semantic segmentation processing, multi-target detection processing, etc., and provides the N types of third feature data obtained after the perception processing to the intrusion detection device.
[0095] After perception processing, N types of third feature data are obtained. The third feature data is a feature matrix, including sensor feature vectors and labels, expressed as (X, Y), where X represents the sensor feature vector and Y represents the label of the identified traffic object, such as street lights, traffic signs, ramps, etc.
[0096] S403: The intrusion detection device selects the required feature data from the N types of third feature data based on the tag and saves it, thereby generating a feature library associated with the GPS service. This feature data describes information about static traffic objects in the area where the first vehicle is located. Feature data other than this feature data is discarded.
[0097] The feature matrix obtained after screening can be spliced with the corresponding location information (such as GPS latitude and longitude data) into a new matrix, expressed as (X, Y, P), where X represents the sensor feature vector, Y represents the label of the identified traffic object, and P represents the GPS latitude and longitude data. The feature matrix (X, Y, P) corresponding to different sensor feature vectors can be used to train location prediction models corresponding to different types of sensors.
[0098] S404: The intrusion detection device trains position prediction models corresponding to different types of sensors based on feature matrices (X, Y, P) corresponding to different sensors.
[0099] As shown in Figure 5, the M position prediction models trained include supervised learning models corresponding to at least one of the following sensors: a camera, a lidar sensor, a millimeter-wave radar sensor, or an ultrasonic radar sensor. Taking the supervised learning model as a deep learning model, during training, the feature matrices corresponding to different sensor types, obtained after screening and splicing, can be input into the corresponding initial deep learning model. After a supervised learning training process based on the position vector P, position prediction models corresponding to different sensor types can be obtained, such as a position prediction model for a camera, a position prediction model for a lidar sensor, a position prediction model for a millimeter-wave radar sensor, or an ultrasonic radar sensor. Each of the M position prediction models is used to predict a position information based on feature data obtained from a sensor.
[0100] The screening and training process can be implemented through an interface call, similar to the get_models_from_sensors(sensor_name_list) interface, which can be used to train a deep model based on road condition data identified from sensors and output the trained model. Similarly, sensor_id_list represents the list of sensor IDs that participate in model training data input. The implementation of this interface is similar to the formal description of the logic as follows:
[0101] Let t1, t2, t3, and t4 represent the API interfaces of the deep learning model to be trained corresponding to different sensors, and S1, S2, S3, and S4 represent the feature matrices provided by different types of sensors to the corresponding deep learning model. Xi represents the input feature vector corresponding to the sensor, Yi represents the label vector, and Pi represents the longitude and latitude data feature vector corresponding to the position, as shown below: S1=(X1, Y1, P1), S2=(X2, Y2, P2), S3=(X3, Y3, P3), S3=(X4, Y4, P4);
[0102] Then: M1=t1(S1), M2=t2(S2), M3=t3(S3), M4=t4(S4);
[0103] Among them, M1, M2, M3, and M4 represent the trained deep learning models respectively.
[0104] In the specific implementation, ti will filter the input feature vector according to the label vector Yi, thereby screening out the required information Xi describing the static traffic object, and discard the unnecessary feature vectors, which will not participate in the model training process.
[0105] S405 (optional step): Incrementally synchronize the M location prediction models obtained through training with the model data of the cloud server as needed.
[0106] That is, the model data for location prediction stored on the cloud server is updated to the model data corresponding to the M location prediction models obtained through training.
[0107] After M position prediction models are obtained through training based on Figures 4 and 5, the method shown in Figure 3 can be implemented using the M position prediction models. As shown in Figure 6, the method may include the following steps:
[0108] S601: N sensors associated with the first vehicle collect N types of raw perception data and provide the N types of raw perception data to a fusion perception module of the intelligent driving system, where N is greater than or equal to 1.
[0109] S602: The fusion perception module of the intelligent driving system performs perception processing on the N types of original perception data obtained, such as semantic segmentation processing, multi-target detection processing, etc., and provides the N types of third feature data obtained after the perception processing to the intrusion detection device.
[0110] After perception processing, N types of third feature data are obtained. The third feature data is a feature matrix, including sensor feature vectors and labels, expressed as (X, Y), where X represents the sensor feature vector and Y represents the label of the identified traffic object, such as street lights, traffic signs, ramps, etc.
[0111] S603: The intrusion detection device filters the required first feature data from N types of third feature data according to the label, the first feature data describes the information of static traffic objects related to the area where the first vehicle is located, and / or, the intrusion detection device obtains second feature data based on the N types of third feature data, the second feature data includes the number of the other vehicles.
[0112] S604: The intrusion detection device inputs the feature data associated with different sensors in the first feature data into M position prediction models to obtain M position prediction values, and weights the M position prediction values to obtain the position information determined based on the first feature data, that is, the average position prediction value, which is expressed as the second position information, where M is greater than 1.
[0113] As shown in Figure 7, (X, Y) represents the feature matrix obtained after screening, where X represents the sensor feature vector and Y represents the label of the identified traffic object, such as a streetlight, traffic sign, or ramp. The (X, Y) values associated with different sensors are input into M position prediction models. Each position prediction model outputs a position prediction value. A weighted average of these M position prediction values is performed to obtain the average GPS prediction value, i.e., the second position information.
[0114] The above prediction process can also be implemented through an interface call, similar to the get_pos_from_sensors(sensor_name_list) interface, which inputs the road condition data identified by the sensor into a pre-trained deep learning model and outputs the corresponding GPS position prediction value. Similarly, sensor_id_list represents the list of sensor IDs involved in the position calculation. The implementation of this interface is similar to the formal description of the logic as follows:
[0115] f1, f2, f3, and f4 represent the function interfaces corresponding to the pre-trained deep learning models corresponding to different sensors, respectively. S1, S2, S3, and S4 represent the feature matrices provided by different types of sensors to the corresponding deep learning models, respectively. Xi represents the input feature vector corresponding to the sensor, Yi represents the label vector, and Pi represents the longitude and latitude data feature vector corresponding to the location, as shown below: S1 = (X1, Y1), S2 = (X2, Y2), S3 = (X3, Y3), S4 = (X4, Y4);
[0116] Then: P1=f1(S1), P2=f2(S2), P3=f3(S3), P4=f4(S4);
[0117] Among them, fi will filter the feature vector Xi according to the label vector Yi, thereby screening out the required information Xi describing the static traffic object, and discard the unnecessary feature vectors, which will not participate in the model prediction process.
[0118] Among them, P1, P2, P3, and P4 represent the prediction values of the current position (such as longitude and latitude data) of different models respectively. When the weighted average processing of M position prediction values is performed, the position prediction value It can be expressed as follows:
[0119] In the embodiment of the present application, the above interface can be periodically called to generate a sequence including time and location information, and a sliding window algorithm is used to calculate the location prediction value using a similarity algorithm within the time window. The similarity to the GPS sequence received by the first vehicle-based positioning component (eg, GPS signal receiver).
[0120] For example, by periodically calling the get_pos_from_sensors(sensor_name_list) interface in a time window, for example, when the time value is [202303020605, 202303020606, 202303020607], a sequence of time and position information (such as longitude and latitude data) can be generated, as shown below: sensor_position_timing_num = [(202303020605, 22.83239514238987, 114.08831784625996), (202303020605,22.819089228869782,114.10772361277796),(202303020605,22.825155625708656,114.14154185306363)].
[0121] Calling the get_pos_from_gps() interface can be used to obtain location information from a location sensor (such as a GPS signal receiving device). The time series periodically calls the get_pos_from_gps() interface. Within a time window, if the time value is [202303020605, 202303020606, 202303020607], a time and position longitude and latitude sequence can be generated, as shown below: gps_position_timing_num = [(202303020605, 22.83239514238997, 114.08831784625956), (202303020605,22.819089228869792,114.10772361277706),(202303020605,22.825155625708636,114.14154185306323)].
[0122] Call the get_pos_distance(cloud_cars_timing_num, sensor_cars_timing_num) API to calculate the similarity within the time series window. This API returns the difference between the two time series, timing_pos_distance. If timing_pos_distance > POS_DISTANCE_THRESHOLD, that is, the similarity is less than or equal to the first threshold, it can be considered that GPS spoofing has occurred.
[0123] S605: The intrusion detection device obtains the fourth characteristic data of the first vehicle from the map server, and analyzes the difference between the fourth characteristic data and the second characteristic data.
[0124] The fourth feature data is information about surrounding vehicles of the first vehicle provided by the map server. For example, the fourth feature data includes a reference number of other vehicles within a first range around the first vehicle. If the similarity between the number of other vehicles indicated by the second feature data and the reference number of other vehicles indicated by the fourth feature data is less than or equal to a second threshold, GPS spoofing may be considered to have occurred.
[0125] This process can also be implemented through interface calls, periodically calling the relevant interface to generate a sequence of time and vehicle numbers, and using a sliding window algorithm to use a similarity algorithm within the time window to calculate the similarity between the number of other vehicles determined by the perception data and the number of other vehicles obtained from the map server.
[0126] For example, an intrusion detection device can use an interface similar to get_pos_range_cars(longitude, latitude, range, time) provided by a map service provider to obtain the number of other vehicles around the current location of the first vehicle. Longitude and latitude represent the current real-time longitude and latitude information of the first vehicle. This longitude and latitude information is GPS data received by the GPS signal receiving device. Range represents the perception range corresponding to the longitude and latitude, such as a range of 20 meters around the first vehicle. Time represents the request time. The information returned by the map server is a collection of longitude and latitude information, expressed as follows:
[0127] s1={(x1,y1),(x2,y2)}, where x and y represent the latitude and longitude information respectively.
[0128] The intrusion detection device can use an interface similar to get_pos_range_cars to implement an interface similar to get_cars_from_map_service(longitude, latitude, range, time, service_id_list) to obtain information about other vehicles around the first vehicle from the map server. Where service_id_list represents the ID list of the map service provider. The interface implementation logic can be formally described as follows:
[0129] Let s1, s2, and s3 represent the return values of the call interfaces provided by different map service providers: s1 = {(x1, y1), (x2, y2)}; s2 = {(x2, y2), (x3, y3)}; s3 = {(x1, y1), (x2, y2), (x4, y4)}; Then: s = s1∪s2∪s3 = {(x1, y1), (x2, y2), (x3, y3), (x4, y4)};
[0130] After the union process, the interface returns the vehicle position set obtained from the map service provider, and cars_from_cloud = s.size() = 4. That is, the number of other vehicles around the first vehicle is 4.
[0131] The get_cars_from_map_service(longitude,latitude,range,time,service_id_list) interface is called periodically in a time series. Within a time window, for example, if the time value is [202303020605,202303020606,202303020607], a sequence of time and vehicle numbers can be generated, as shown below: cloud_cars_timing_num = [(202303020605,3),(202303020605,4),(202303020605,4)].
[0132] The get_cars_from_sensors(range) API is called periodically in a time series to represent the number of other vehicles around the first vehicle identified based on the raw sensor data, i.e., the second feature data. Within a time window, for example, if the time values are [202303020605, 202303020606, 202303020607], a sequence of times and vehicle numbers can be generated, as shown below: sensor_cars_timing_num = [(202303020605, 3), (202303020605, 4), (202303020605, 4)].
[0133] Call the get_car_num_distance(cloud_cars_timing_num, sensor_cars_timing_num) interface to calculate the similarity within the time series window. This interface returns the difference between the two time series, timing_num_distance. If timing_num_distance>NUM_DISTANCE_THRESHOLD, that is, the similarity is less than or equal to the second threshold, then GPS spoofing is considered to have occurred.
[0134] In the embodiment of the present application, the sliding window algorithm used in the above S605 and S606 may include, but is not limited to, a piecewise linear representation (PLR) algorithm, a dynamic time warping (DTW) algorithm, etc., and the embodiment of the present application does not limit the implementation of this algorithm. The similarity algorithm may include, but is not limited to, a Euclidean distance algorithm, a cosine similarity algorithm, a Minkowski distance algorithm, etc., and the embodiment of the present application does not limit the implementation of this algorithm.
[0135] S606: The intrusion detection device determines that GPS spoofing exists based on the results of S604 and S605, that is, an intrusion event exists.
[0136] S607: The intrusion detection device sends an alarm message to the intelligent driving system, where the alarm message indicates the intrusion event. The intelligent driving system can implement subsequent control processing based on the alarm message to ensure safe driving of the vehicle.
[0137] S608 (optional): The intrusion detection device sends an alert message to the smart cockpit, indicating the intrusion event. The smart cockpit can receive the alert message from the intrusion detection device and output the alert message through the central control display, head-up display, audio system, seat vibration, lighting, etc. for reference by vehicle occupants (including the driver and other passengers), thereby assisting the driver in controlling the vehicle's safe driving, or enabling other passengers to provide driving assistance to the driver based on the alert message.
[0138] Thus, the above method utilizes the vehicle's various sensors to detect specific static features of the surrounding environment and road conditions for intrusion detection, preventing attackers from blocking the GPS signal receiver and then forging GPS signals to conduct spoofing attacks. Furthermore, the vehicle's various sensors utilize specific dynamic features of the surrounding environment and road conditions for intrusion detection, preventing attackers from forging GPS signals based on locations with similar environmental features. In this method, the GPS signal detection features do not originate from the GPS signal itself, effectively detecting a wide range of GPS signal spoofing attacks. Furthermore, this method relies solely on the sensor and computing equipment already installed in the autonomous driving function, eliminating the need for additional hardware support and incurring no additional hardware costs.
[0139] In other embodiments, the above-described intrusion detection method can also be used as a sub-function of other vehicle functions. For example, in a location-based recommendation system, the above-described method can be implemented to analyze whether an intrusion event has occurred. If an intrusion event has occurred, the GPS signal received by the GPS signal receiving device cannot be directly used as real-time positioning information for recommendation purposes, so as to avoid recommending incorrect items to the user. As an optional implementation, the location prediction value identified based on the raw sensing data of various sensors can be temporarily used as reliable location information for making recommendations to the user. After the intrusion event is resolved, the GPS signal received by the GPS signal receiving device can be reused as real-time positioning information for recommendation purposes.
[0140] The embodiment of the present application also provides an intrusion detection device for executing the method executed by the intrusion detection device in the above method embodiment. The relevant features can be found in the above method embodiment and will not be repeated here.
[0141] As shown in FIG8 , the intrusion detection device 800 may include: a first acquisition unit 801 for acquiring first characteristic data, wherein the first characteristic data describes information about static traffic objects related to the area where the first vehicle is located; a second acquisition unit 802 for acquiring second characteristic data, wherein the second characteristic data describes information about dynamic traffic objects related to the area where the first vehicle is located; a determination unit 803 for determining the occurrence of an intrusion event based on the first characteristic data, the second characteristic data, and an intrusion detection rule, wherein the intrusion detection rule describes a method for detecting an intrusion event associated with the service to be detected of the first vehicle; and a communication unit 804 for sending an alarm message to the intelligent driving system of the first vehicle, wherein the alarm message indicates the intrusion event. For specific implementation methods, please refer to the method steps implemented by the intrusion detection device in the above method embodiment, which will not be repeated here.
[0142] It should be understood that the division of the various units in the above device is only a division of logical functions. In actual implementation, they can be fully or partially integrated into a physical entity, or they can be physically separated. In addition, the units in the device can be implemented in the form of a processor calling software; for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or realize the functions of the various units of the device, where the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units can be realized by designing the hardware circuits. The hardware circuit can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), which realizes the functions of some or all of the above units by designing the logical relationship of the components in the circuit. For another example, in another implementation, the hardware circuit can be implemented by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units. All units of the above devices can be implemented in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.
[0143] In an embodiment of the present application, a processor is a circuit with a signal processing capability. In one implementation, the processor may be a circuit with an instruction reading and execution capability, such as a CPU, a microprocessor, a graphics processing unit (GPU) (which may be understood as a microprocessor), or a digital signal processor (DSP); in another implementation, the processor may implement certain functions through the logical relationship of a hardware circuit, and the logical relationship of the hardware circuit may be fixed or reconfigurable, such as a hardware circuit implemented by an ASIC or PLD, such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and implementing the hardware circuit configuration may be understood as the process of the processor loading instructions to implement the functions of some or all of the above units. In addition, it may also be a hardware circuit designed for artificial intelligence, which may be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.
[0144] It can be seen that each unit in the above device can be one or more processors (or processing circuits) configured to implement the above method, such as: CPU, GPU, NPU, TPU, DPU, microprocessor, DSP, ASIC, FPGA, or a combination of at least two of these processor forms.
[0145] In addition, the various units in the above apparatus may be fully or partially integrated together, or may be implemented independently. In one implementation, these units are integrated together and implemented in the form of a system-on-chip (SoC). The SoC may include at least one processor for implementing any of the above methods or implementing the functions of the various units of the apparatus. The at least one processor may be of different types, for example, including a CPU and an FPGA, a CPU and an artificial intelligence processor, a CPU and a GPU, etc.
[0146] In a simple embodiment, those skilled in the art may imagine that the intrusion detection devices in the above embodiments may all adopt the form shown in FIG. 9 .
[0147] The apparatus 900 shown in FIG9 includes at least one processor 910 and a communication interface 930. In an optional design, a memory 920 may also be included.
[0148] The embodiment of the present application does not limit the specific connection medium between the processor 910 and the memory 920.
[0149] In the apparatus shown in FIG. 9 , the processor 910 may transmit data through the communication interface 930 when communicating with other devices.
[0150] When the communication device adopts the form shown in FIG. 9 , the processor 910 in FIG. 9 can call the computer-executable instructions stored in the memory 920 so that the device 900 can execute any of the above method embodiments.
[0151] The present application also provides a vehicle, the structure of which is shown in FIG2 , wherein the intrusion detection device has the structure shown in FIG8 or FIG9 .
[0152] An embodiment of the present application also relates to a chip system, which includes a processor for calling a computer program or computer instructions stored in a memory so that the processor executes the method of any of the above embodiments.
[0153] In a possible implementation, the processor may be coupled to the memory through an interface.
[0154] In a possible implementation, the chip system may also directly include a memory, in which a computer program or computer instructions are stored.
[0155] For example, the memory may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. The non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache memory. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0156] An embodiment of the present application further relates to a processor, which is used to call a computer program or computer instruction stored in a memory so that the processor executes the method described in any of the above embodiments.
[0157] For example, in the embodiments of the present application, the processor is an integrated circuit chip with signal processing capabilities. For example, the processor can be an FPGA, a general-purpose processor, a DSP, an ASIC or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, an SoC, a CPU, a network processor (NP), a microcontroller unit (MCU), a PLD or other integrated chip, which can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory or electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
[0158] It should be understood that the embodiments of the present application may be provided as methods, systems, or computer program products.
[0159] In one possible implementation, an embodiment of the present application provides a computer-readable storage medium, which stores program code. When the program code runs on the computer, the computer executes the above method embodiment.
[0160] In a possible implementation, an embodiment of the present application provides a computer program product. When the computer program product is run on a computer, the computer is caused to execute the above method embodiment.
[0161] Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0162] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0163] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0164] Obviously, those skilled in the art can make various changes and modifications to the embodiments of the present application without departing from the scope of the embodiments of the present application. Thus, if these modifications and variations of the embodiments of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these changes and variations. In the various embodiments of the present application, unless otherwise specified or logically conflicting, the terms and / or descriptions between the various embodiments are consistent and can be referenced to each other, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
Claims
1. An intrusion detection method, characterized in that: include: Acquire first characteristic data, where the first characteristic data describes information of static traffic objects related to an area where the first vehicle is located; Acquire second characteristic data, where the second characteristic data describes information about dynamic traffic objects related to an area where the first vehicle is located; Determining that an intrusion event occurs according to the first feature data, the second feature data, and an intrusion detection rule, wherein the intrusion detection rule describes a method for detecting an intrusion event associated with a to-be-detected service of the first vehicle; Sending a warning message to the intelligent driving system of the first vehicle, where the warning message indicates the intrusion event.
2. The method according to claim 1, characterized in that: The obtaining of the first characteristic data comprises: The first characteristic data is filtered from N types of third characteristic data, wherein the N types of third characteristic data are obtained after perceptual processing of N types of perception data, and the N types of perception data are original perception data collected by N sensors associated with the first vehicle, and N is greater than or equal to 1.
3. The method according to claim 2, characterized in that The perception processing includes multi-target detection processing, the N types of third feature data include labels of identified traffic objects, and the screening of the first feature data from the N types of third feature data includes: The first characteristic data is filtered from N types of third characteristic data according to the label, wherein the label associated with the first characteristic data is used to describe the static traffic object.
4. The method according to any one of claims 1 to 3, characterized in that The dynamic traffic objects include other vehicles within a first range around the first vehicle, and acquiring the second characteristic data includes: The second characteristic data is obtained according to N kinds of third characteristic data, wherein the second characteristic data includes the number of the other vehicles, the N kinds of third characteristic data are obtained after perception processing of N kinds of perception data, and the N kinds of perception data are original perception data collected by N sensors associated with the first vehicle, and N is greater than or equal to 1.
5. The method according to any one of claims 1 to 4, characterized in that The service to be detected is associated with the location information of the first vehicle, the intrusion detection rule includes analyzing the difference of information obtained in different ways, and the method further includes: Acquiring first position information of the first vehicle through a positioning component of the first vehicle; Acquire fourth characteristic data of the first vehicle from a map server, where the fourth characteristic data is information of surrounding vehicles of the first vehicle provided by the map server; The determining, according to the first characteristic data, the second characteristic data and the intrusion detection rule, that an intrusion event occurs includes: When the difference between the location information determined according to the first feature data and the first location information meets a first condition, and the difference between the second feature data and the fourth feature data meets a second condition, it is determined that a positioning intrusion event occurs.
6. The method according to claim 5, characterized in that The first condition includes: the similarity between the location information determined according to the first feature data and the first location information is less than or equal to a first threshold, and the method further includes: Inputting feature data associated with different sensors in the first feature data into M position prediction models to obtain M position prediction values, where M is greater than 1; Obtaining the location information determined according to the first feature data by weighting the M location prediction values; Each of the M position prediction models is used to predict a position information based on feature data obtained by a sensor.
7. The method according to claim 6, characterized in that The M location prediction models include a supervised learning model corresponding to at least one of the following sensors: Camera, LiDAR sensor, millimeter wave radar sensor or ultrasonic radar sensor.
8. The method according to any one of claims 5 to 7, characterized in that: The fourth feature data includes a reference number of other vehicles within a first range around the first vehicle; The second condition includes: a similarity between the number of other vehicles indicated by the second feature data and a reference number of other vehicles indicated by the fourth feature data is less than or equal to a second threshold.
9. An intrusion detection device, characterized in that: include: A first acquisition unit, configured to acquire first characteristic data, wherein the first characteristic data describes information of static traffic objects related to an area where the first vehicle is located; A second acquisition unit, configured to acquire second characteristic data, wherein the second characteristic data describes information of dynamic traffic objects related to an area where the first vehicle is located; a determination unit, configured to determine that an intrusion event occurs according to the first characteristic data, the second characteristic data, and an intrusion detection rule, wherein the intrusion detection rule describes a detection method of an intrusion event associated with a to-be-detected service of the first vehicle; A communication unit is used to send a warning message to the intelligent driving system of the first vehicle, where the warning message indicates the intrusion event.
10. A communication device, characterized in that: The method comprises at least one processor and an interface circuit, wherein the interface circuit is used to provide data or code instructions to the at least one processor, and the at least one processor is used to implement the method according to any one of claims 1 to 8 through a logic circuit or by executing code instructions.
11. A vehicle, characterized in that: The method comprises a module for implementing the method according to any one of claims 1 to 8 or comprises the intrusion detection device according to claim 9.
12. A computer-readable storage medium, characterized in that: The computer-readable medium stores a program code, and when the program code is executed on a computer, the computer is caused to execute the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Automatic driving vehicle, and dynamic planning method and system of motion trail thereof
CN111829545A
Vehicle intrusion detection method and defense system
CN112822684A
Intrusion detection method and device based on automatic driving and electronic equipment
CN115348091A
Information safety method of intelligent driving vehicle system
CN116708014A
Vehicle safety protection method and device, computer equipment and storage medium
CN116866033A