Neural Network Segmentation for Automotive Ethernet Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for anomaly detection in vehicle networks, such as CAN and automotive Ethernet, face challenges due to high temporal and data variability, making it difficult for artificial neural networks to effectively learn and detect anomalies, especially in dynamic and complex network traffic.

Innovation Solution

A tailored artificial neural network architecture that assigns specific input models to message types, allowing for efficient classification and anomaly detection without pre-selecting messages, and can be trained unsupervised using normal data to detect new and unknown anomalies, making it robust and difficult for attackers to deceive.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single artificial neural network is used to process all message types, then the network can learn general patterns, but it becomes too large and complex to handle the high variability in message structures and temporal sequences

Engineering Contradiction:
Improveability to handle different message typesVSAvoidsize of artificial neural network
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the single large neural network into multiple smaller input models, each dedicated to a specific message type. This segmentation allows each model to be specialized and compact while collectively handling all message types through parallel processing. The selection device routes messages to appropriate input models based on their type, avoiding the need for one large generic network.

Inventive Principle:
Principle #1Segmentation

2Productivity

If messages are pre-selected and limited in number for training, then the neural network can be trained more efficiently, but the system cannot detect new or unknown anomalies that were not present in the training data

Engineering Contradiction:
Improvetraining efficiencyVSAvoidability to detect new anomalies
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent creates input models that are universally applicable to all message types through parallel processing. Each input model is designed to handle its specific message type with the same architectural pattern, allowing the system to generalize to new message types and anomalies. The selection device ensures all message types are routed to appropriate models, enabling comprehensive coverage without limiting training data selection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If rule-based intrusion detection systems are used, then the system is easier to implement and interpret, but attackers can more easily deceive the system by replicating known functional relationships

Engineering Contradiction:
Improveease of implementationVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the mechanical rule-based system with an artificial neural network that learns patterns automatically from data. Instead of manually defining rules that attackers can analyze and exploit, the neural network discovers complex, non-linear relationships in the data that are much harder for attackers to replicate. The system substitutes explicit rule-based logic with implicit pattern recognition through machine learning.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3684015B1Device and method for classifying data in particular for a controller area network or an automotive ethernet network
Publication Date: 2024.01.03 ROBERT BOSCH GMBH
  • EP3684015B1 patent drawingFigure 1~2
  • EP3684015B1 patent drawingFigure 3
  • EP3684015B1 patent drawingFigure 4~5

AI summary

Device and computer-implemented method for classifying data, in particular for a controller area network or an automotive Ethernet network, wherein a plurality of messages is received from a communication network (502), wherein a message having a predefined message type is selected for an input variable for an input model of a plurality of input models of an artificial neural network (504) that is associated with the predefined message type, wherein the input variable is determined depending on the message (506), wherein a prediction is output in an output area of ​​the artificial neural network which is usable for classifying the message depending on the input variable, or a reconstruction of an input variable is output which is usable for classifying the message depending on this input variable (510).