IP Library › Granted Patent US 12,530,276
Granted Patent B2
US 12,530,276 · App. 18/564,803 · Granted Jan 20, 2026

Computer-implemented method and system for learning-based anomaly detection in order to determine a software error in a networked vehicle

Inventors: Alexander Frickenstein (Inning a. Ammersee, DE); Maik Kowol (Sankt Wolfgang, DE)
Assignee: Bayerische Motoren Werke Aktiengesellschaft
G06F11/3636G06F11/3608G06N3/042G06N3/09
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,530,276
App. No.
18/564,803
Granted
Jan 20, 2026
Kind
B2
Abstract

Systems, methods, and apparatuses are provided for learning-based anomaly detection to determine a software error in a networked vehicle. Trace lines are translated using a controller of the vehicle. A node list with weighted links is input into a graph neural network. Similarities and dependencies of each node are output as embedded features in a floating-point format with respect to other nodes of the node list in an embedded representation and for each node of the node list. Embedded features of nodes are sorted into a temporal sequence based on a timestamp of each translated trace line. The embedded features of the nodes are augmented with similar embedded features of nodes determined using a distance metric. Similar embedded features are input into a deep neural network together with the embedded features. A time of an error probability and/or error class of an anomaly is output to determine the software error.

Claims (44)

1 . A computer-implemented method for learning-based anomaly detection in order to determine a software error in a networked vehicle, comprising:

translating trace lines of a trace available in a diagnostic log and trace (DLT) format as a file using a temporal sequence of function calls of software components of a controller of the vehicle;

outputting, by the controller of the vehicle, a graph representation of an undirected graph;

providing a node list with weighted links between nodes, wherein

each weighted link represents individual data segments of the translated trace lines;

inputting the node list into a graph neural network;

outputting, as embedded features in a floating-point format, similarities and dependencies of each node with respect to other nodes of the node list in an embedded representation and for each node of the node list;

sorting the embedded features of nodes of a plurality of temporally successive trace lines into a temporal sequence based on a timestamp of each translated trace line and augmenting the embedded features of the nodes of the plurality of temporally successive trace lines with similar embedded features of nodes determined using a distance metric proceeding from the nodes of at least one of the plurality of temporally successive trace lines;

inputting the similar embedded features into a deep neural network together with the embedded features of the nodes of the plurality of temporally successive trace lines; and

outputting a time of an error probability and/or error class of an anomaly in the plurality of temporally successive trace lines to determine the software error.

2 . The computer-implemented method according to claim 1 , wherein

the distance metric is provided as a cosine similarity, Euclidean distance metric, or weighted Euclidean distance metric.

3 . The computer-implemented method according to claim 1 , further comprising:

using N temporally successive trace lines and the similar embedded features of M nodes in a sliding window for input into the deep neural network.

4 . The computer-implemented method according to claim 3 , wherein

of the N temporally successive trace lines of the sliding window, only the trace line with the most recent timestamp is used to determine the similar embedded features, wherein

the similar embedded features of the M nodes are determined using the distance metric proceeding from the nodes of the trace line with the most recent timestamp.

5 . The computer-implemented method according to claim 3 , wherein

M is equal to N,

M is set equal to 3, 10, or 64.

6 . The computer-implemented method according to claim 1 , wherein

the node list with the weighted links between two nodes is complemented by a lookup table in which each node of the translated trace lines is denoted by a running integer index and is assigned a distinguishable label of numbers and/or letters.

7 . The computer-implemented method according to claim 1 , further comprising:

outputting the anomaly in the plurality of temporally successive trace lines for determining the software error in the form of a graphic representation of a regression problem and/or classification problem.

8 . The computer-implemented method according to claim 1 , further comprising:

training, within an upstream step, the graph neural network and/or the deep neural network with trace lines of an intended behavior and/or trace lines of known software errors as ground truth for supervised learning.

9 . The computer-implemented method according to claim 1 , further comprising:

translating, in addition to trace lines of the trace output by the controller of the vehicle, trace lines of further traces from a backend into the graph representation.

10 . The computer-implemented method according to claim 1 , further comprising:

retraining, in a downstream step, the graph neural network and/or the deep neural network using trace lines of traces of a test fleet of further vehicles.

11 . The computer-implemented method according to claim 6 , further comprising:

determining, from the time of the anomaly in the plurality of temporally successive trace lines as the output of the deep neural network, trace lines connected to the software error using an evaluation of the embedded representation, the node list, the lookup table, and the graph representation; and

using the trace lines connected to the software error are used to:

identify the software error,

create an availability map of services in the vehicle, and/or

determine trace lines which are connected to a potential software error.

12 . The computer-implemented method according to claim 1 , wherein

the graph neural network is designed as DeepWalk, and

the deep neural network is designed as a long short-term memory (LSTM).

13 . The computer-implemented method according to claim 1 , further comprising:

carrying out a temporal evaluation of the translated trace lines to determine the software error, and

using the graph neural network to determine a relationship between the translated trace lines using a semantic of the translated trace lines.

14 . A non-transitory computer-readable medium comprising instructions operable, when executed by one or more computing systems, to:

perform the method of claim 1 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2023
From: FRICKENSTEIN, ALEXANDER; KOWOL, MAIK
To: BAYERISCHE MOTOREN WERKE AKTIENGESELLSCHAFT
Reel/Frame 065686/0090 →
Priority Claims (1)
DE 10 2021 118 972.1 · Jul 22, 2021 · national
Continuity (1)
Related Publication 20240378137A1 · Nov 14, 2024
References Cited (9)
US 10977561B2 · Sun · 2021 [cited by examiner]
US 20190036760A1 · Tee et al. · 2019 [cited by applicant]
US 20190340392A1 · Khorrami · 2019 [cited by examiner]
US 20200331465A1 · Herman · 2020 [cited by examiner]
DE 202017005070U1 · 2017 [cited by applicant]
International Search Report (PCT/lSA/210) issued in PCT Application No. PCT/EP2022/059601 dated Jul. 20, 2022 with English translation (4 pages). [cited by applicant]
German-language Written Opinion (PCT/lSA/237) issued in PCT Application No. PCT/EP2022/059601 dated Jul. 20, 2022 with English translation (10 pages). [cited by applicant]
German-language Office Action issued in German Application No. 10 2021 118 972.1 dated Nov. 22, 2021 (6 pages). [cited by applicant]
Jia, T. et al.; “An Approach for Anomaly Diagnosis Based on Hybrid Graph Model with Logs for Distributed Services”, 2017 IEEE 24 [cited by applicant]