IP Library › Granted Patent US 12,001,553
Granted Patent B2
US 12,001,553 · App. 17/404,759 · Granted Jun 4, 2024

Detecting vehicle malfunctions and cyber attacks using machine learning

Inventors: Dror Cohen (Bet Hanan, IL); Alexander Kreines (Jerusalem, IL); Shachar Mendelowitz (Tel Aviv, IL)
Assignee: Red Bend Ltd.
G06F21/566G07C5/0808G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,001,553
App. No.
17/404,759
Granted
Jun 4, 2024
Kind
B2
Abstract

Techniques for detecting anomalies or cyber attacks on a vehicle. A computer-implemented method for anomaly or attack detection includes determining, using a first model, a first predicted value of a first variable message associated with a vehicle, determining, using a second model, a second predicted value of the first variable message associated with the vehicle, determining, based on a difference between an actual value of the first variable message and the first predicted value of the first variable message and on a difference between the actual value of the first variable message and the second predicted value of the first variable message, a vector, and determining, using a third model, an output value based on the vector, the output value corresponding to at least one of a likelihood that an anomaly or an attack is occurring or a type of the anomaly or the attack.

Claims (36)

1. A computer-implemented method for anomaly or attack detection, the method comprising:

determining, using a first model, a first predicted value of a first variable message associated with a vehicle;

determining, using a second model different from the first model, a second predicted value of the first variable message associated with the vehicle, wherein the first model and the second model are selected based on resilience to one or more types of cyber attacks;

determining, based on a difference between an actual value of the first variable message and the first predicted value of the first variable message and on a difference between the actual value of the first variable message and the second predicted value of the first variable message, a vector; and

determining, using a third model, an output value based on the vector, the output value corresponding to at least one of a likelihood that an anomaly or an attack is occurring or a type of the anomaly or the attack.

2. The method of claim 1 , wherein the first variable message comprises a continuous variable message associated with a first operational parameter of the vehicle.

3. The method of claim 2 , wherein the first predicted value of the first variable message comprises a predicted value of the first operational parameter.

4. The method of claim 1 , wherein the first variable message comprises a categorical variable message associated with a first operational parameter of the vehicle.

5. The method of claim 4 , wherein the first predicted value of the first variable message comprises a predicted probability associated with the first operational parameter.

6. The method of claim 1 , wherein the first model comprises a time series model.

7. The method of claim 1 , wherein the second model comprises a regression model.

8. The method of claim 1 , wherein the vector comprises a vector of errors or residuals.

9. The method of claim 1 , wherein the vector comprises a vector of probabilities.

10. The method of claim 1 , further comprising determining, using a fourth model, a third predicted value of a second variable message associated with the vehicle.

11. The method of claim 1 , further comprising:

determining, using a fourth model, a second output value based on the vector; and

combining the output value and the second output value, the combined output value corresponding to at least one of the likelihood that the anomaly or the attack is occurring or the type of the anomaly or the attack.

12. The method of claim 1 , wherein the third model comprises a meta model.

13. The method of claim 1 , further comprising determining, using the first model, a third predicted value of a second variable message associated with the vehicle.

14. The method of claim 1 , wherein determining, using the first model, the first predicted value of the first variable message associated with the vehicle comprises determining the first predicted value using at least one second variable messages associated with the vehicle, wherein the at least one second variable message is correlated with the first variable message.

15. One or more non-transitory computer-readable storage media including instructions that, when executed by one or more processors, cause the one or more processors to perform the steps of:

determining, using a first model, a first predicted value of a first variable message associated with a vehicle;

determining, using a second model different from the first model, a second predicted value of the first variable message associated with the vehicle, wherein the first model and the second model are selected based on resilience to one or more types of cyber attacks;

determining, based on a difference between an actual value of the first variable message and the first predicted value of the first variable message and on a difference between the actual value of the first variable message and the second predicted value of the first variable message, a vector; and

determining, using a third model, an output value based on the vector, the output value corresponding to at least one of a likelihood that an anomaly or an attack is occurring or a type of the anomaly or the attack.

16. The one or more non-transitory computer-readable storage media of claim 15 , wherein the first model comprises a time series model, and the second model comprises a regression model.

17. The one or more non-transitory computer-readable storage media of claim 15 , wherein the first model comprises a first time series model, and the second model comprises a second time series model.

18. The one or more non-transitory computer-readable storage media of claim 15 , wherein the first model comprises a first regression model, and the second model comprises a second regression model.

19. A system, comprising:

a memory storing an application; and

one or more processors that, when executing the application, is configured to:

determine, using a first model, a first predicted value of a first variable message associated with a vehicle;

determine, using a second model different from the first model, a second predicted value of a second variable message associated with the vehicle, wherein the first model and the second model are selected based on resilience to one or more types of cyber attacks;

determine, based on a difference between an actual value of the first variable message and the first predicted value of the first variable message and on a difference between an actual value of the second variable message and the second predicted value of the second variable message, a vector; and

determine, using a third model, an output value based on the vector, the output value corresponding to at least one of a likelihood that an anomaly or an attack is occurring or a type of the anomaly or the attack.

20. The system of claim 19 , wherein the one or more processors, when executing the application, is further configured to determine, using the first model, a third predicted value of a third variable message associated with the vehicle.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2021
From: COHEN, DROR; KREINES, ALEXANDER; MENDELOWITZ, SHACHAR
To: RED BEND, LTD
Reel/Frame 057325/0657 →
Continuity (2)
Provisional Application 63068250 · Aug 20, 2020
Related Publication 20230054575A1 · Feb 23, 2023