IP Library › Granted Patent US 12,665,916
Granted Patent B2
US 12,665,916 · App. 18/715,263 · Granted Jun 23, 2026

Lightweight real-time abnormality detection method using can message analysis and neural network model

Inventors: Huy Kang Kim (Seoul, KR); Seonghoon Jeong (Seoul, KR); Hwejae Lee (Seoul, KR); Sangho Lee (Seoul, KR); Yeonjae Kang (Namyangju-si, KR); Daekwon Pi (Goyang-si, KR); Gunho Park (Suwon-si, KR)
Assignee: KOREA UNIVERSITY RESEARCH AND BUSINESS FOUNDATION
H04L63/1425G06N3/0495
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,665,916
App. No.
18/715,263
Filed
May 31, 2024
Granted
Jun 23, 2026
Kind
B2
Art Unit
2434
USPC
726/23
Abstract

A method for detecting an anomaly, which is performed by a computing device including one or more processors according to some embodiments of the present disclosure may include: collecting a CAN message generated in a controller area network (CAN); generating first traffic time interval data and first payload data based on the CAN message; obtaining a first latent vector generated by inputting the first traffic time interval data into a first neural network model; obtaining a second latent vector generated by inputting the first payload data into a second neural network model; generating merged data in which the first latent vector and the second latent vector are merged; and determining whether the CAN message is anomalous by inputting the merged data into a third neural network model.

Claims (63)

1 . A method for detecting an anomaly, which is performed by a computing device including one or more processors, the method comprising:

collecting a CAN message generated in a controller area network (CAN);

generating first traffic time interval data and first payload data based on the CAN message;

obtaining a first latent vector generated by inputting the first traffic time interval data into a first neural network model;

obtaining a second latent vector generated by inputting the first payload data into a second neural network model;

generating merged data in which the first latent vector and the second latent vector are merged; and

determining whether the CAN message is anomalous by inputting the merged data into a third neural network model,

wherein the generating of the merged data in which the first latent vector and the second latent vector are merged includes:

generating a first adjusted latent vector in which a first weight is assigned to the first latent vector;

generating a second adjusted latent vector in which a second weight is assigned to the second latent vector; and

generating the merged data in which the first adjusted latent vector and the second adjusted latent vector are merged.

2 . The method of claim 1 , wherein the generating of the first traffic time interval data and the first payload data includes

extracting an Arbitration ID from the CAN message,

extracting a value of a reception time interval of the CAN message from the CAN message, and

generating the first traffic time interval data including the Arbitration ID and the reception time interval value of the CAN message.

3 . The method of claim 1 , wherein the first weight is determined based on a training result of the first neural network model trained based on second traffic time interval data generated based on a normal CAN message.

4 . The method of claim 1 , wherein the second weight is determined based on a training result of the second neural network model trained based on second payload data generated based on the normal CAN message.

5 . The method of claim 1 , further comprising:

wherein at least one of the first neural network model, the second neural network model, or the third neural network model is pre-trained,

performing quantization of converting a floating point arithmetic process performed in at least one of the first neural network model, the second neural network model, or the third neural network model into an integer arithmetic process.

6 . The method of claim 1 , wherein the third neural network model as a model in which Variational Auto-Encoder (VAE) and Generative Adversarial Networks (GAN) are combined is pre-trained so that a posterior distribution of a hidden code vector of the VAE matches a target distribution.

7 . The method of claim 1 , wherein the generating of the first traffic time interval data and the first payload data includes

extracting the Arbitration ID from the CAN message,

extracting a payload from the CAN message,

generating payload analysis data by analyzing the payload, and

generating the first payload data including the Arbitration ID and the payload analysis data.

8 . The method of claim 7 , wherein the generating of the payload analysis data by analyzing the payload includes

checking the amount of change in the payload using at least one of Hamming Distance, Autocorrelation, or Time Series Decomposition,

obtaining payload separation information separated by use or unit by analyzing the amount of change in the payload, and

generating the payload analysis data including the payload separation information.

9 . The method of claim 1 , wherein the third neural network model includes

an encoder unit compressing the input merged data, and generating a third latent vector of which dimension is reduced,

a decoder unit generating first output data in which the third latent vector is converted to a dimension before reduction, and

a discriminator generating second output data based on a target vector extracted from a target distribution, and the third latent vector.

10 . The method of claim 9 , wherein the determining of whether the CAN message is anomalous by inputting the merged data into the third neural network model includes

calculating a loss value of the third neural network model by comparing the merge data and the second output data, and

determining whether the CAN message is anomalous based on the loss value and a predetermined threshold.

11 . A non-transitory computer readable storage medium storing a computer program comprising instructions executed by a processor of a computing device for detecting an anomaly to perform the following steps, the steps comprising:

collecting a CAN message generated in a controller area network (CAN);

generating first traffic time interval data and first payload data based on the CAN message;

obtaining a first latent vector generated by inputting the first traffic time interval data into a first neural network model;

obtaining a second latent vector generated by inputting the first payload data into a second neural network model;

generating merged data in which the first latent vector and the second latent vector are merged; and

determining whether the CAN message is anomalous by inputting the merged data into a third neural network model,

wherein the generating of the merged data in which the first latent vector and the second latent vector are merged includes:

generating a first adjusted latent vector in which a first weight is assigned to the first latent vector;

generating a second adjusted latent vector in which a second weight is assigned to the second latent vector; and

generating the merged data in which the first adjusted latent vector and the second adjusted latent vector are merged.

12 . A computing device for detecting an anomaly, comprising:

a processor including at least one core;

a memory for storing computer programs executable by the processor; and

a network unit,

wherein the processor is configured to

collect a CAN message generated in a controller area network (CAN),

generate first traffic time interval data and first payload data based on the CAN message,

obtain a first latent vector generated by inputting the first traffic time interval data into a first neural network model,

obtain a second latent vector generated by inputting the first payload data into a second neural network model,

generate merged data in which the first latent vector and the second latent vector are merged, and

determine whether the CAN message is anomalous by inputting the merged data into a third neural network model,

wherein the processor is further configured to:

generate a first adjusted latent vector in which a first weight is assigned to the first latent vector;

generate a second adjusted latent vector in which a second weight is assigned to the second latent vector; and

generate the merged data in which the first adjusted latent vector and the second adjusted latent vector are merged.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2024
From: KIM, HUY KANG; JEONG, SEONGHOON; LEE, HWEJAE; LEE, SANGHO; KANG, YEONJAE; PI, DAEKWON; PARK, GUNHO
To: KOREA UNIVERSITY RESEARCH AND BUSINESS FOUNDATION
Reel/Frame 067580/0517 →
Priority Claims (1)
KR 10-2021-0174328 · Dec 8, 2021 · national
Continuity (1)
Related Publication 20250039206A1 · Jan 30, 2025
References Cited (77)
US 9843594B1 · Evans · 2017 [cited by examiner]
US 10015462B1 · Quach · 2018 [cited by examiner]
US 10482334B1 · Chen · 2019 [cited by examiner]
US 10484401B2 · Jung et al. · 2019 [cited by applicant]
US 11095618B2 · Doshi · 2021 [cited by examiner]
US 11294756B1 · Sadrieh · 2022 [cited by examiner]
US 11438248B2 · Park et al. · 2022 [cited by applicant]
US 11483327B2 · Hen · 2022 [cited by examiner]
US 11606376B2 · Wee · 2023 [cited by examiner]
US 11610098B2 · Dong · 2023 [cited by examiner]
US 11700270B2 · Mozumdar · 2023 [cited by examiner]
US 11973769B1 · Le · 2024 [cited by examiner]
US 12266144B2 · Mustikovela · 2025 [cited by examiner]
US 12406023B1 · Alvarez Lopez · 2025 [cited by examiner]
US 20030177391A1 · Ofek · 2003 [cited by examiner]
US 20160188396A1 · Sonalker · 2016 [cited by examiner]
US 20170126711A1 · Jung · 2017 [cited by examiner]
US 20180336436A1 · Cheng · 2018 [cited by examiner]
US 20190102840A1 · Perl · 2019 [cited by examiner]
US 20190135300A1 · Gonzalez Aguirre · 2019 [cited by examiner]
US 20190303759A1 · Farabet · 2019 [cited by examiner]
US 20190385057A1 · Litichever · 2019 [cited by examiner]
US 20200076840A1 · Peinador · 2020 [cited by examiner]
US 20200090426A1 · Barnes · 2020 [cited by examiner]
US 20200143053A1 · Gutierrez · 2020 [cited by examiner]
US 20200145433A1 · Gutierrez · 2020 [cited by examiner]
US 20200204571A1 · Neznal · 2020 [cited by examiner]
US 20200234101A1 · Hanselmann · 2020 [cited by examiner]
US 20200267171A1 · Mozumdar et al. · 2020 [cited by applicant]
US 20200287926A1 · Liu · 2020 [cited by examiner]
US 20200389469A1 · Litichever · 2020 [cited by examiner]
US 20210051085A1 · Park · 2021 [cited by examiner]
US 20210150230A1 · Smolyanskiy · 2021 [cited by examiner]
US 20210178995A1 · Koyama · 2021 [cited by examiner]
US 20210185066A1 · Shah · 2021 [cited by examiner]
US 20210188252A1 · Lu · 2021 [cited by examiner]
US 20220038903A1 · Fu · 2022 [cited by examiner]
US 20220044121A1 · Pituwalakankanamge · 2022 [cited by examiner]
US 20220046114A1 · Entelis · 2022 [cited by examiner]
US 20220084371A1 · Semichev · 2022 [cited by examiner]
US 20220150141A1 · Reinert · 2022 [cited by examiner]
US 20220166782A1 · Zoldi · 2022 [cited by examiner]
US 20220269937A1 · Kim · 2022 [cited by examiner]
US 20220303362A1 · Kamir · 2022 [cited by examiner]
US 20220309336A1 · Minkin · 2022 [cited by examiner]
US 20220318678A1 · Kranski · 2022 [cited by examiner]
US 20220366734A1 · Jung · 2022 [cited by examiner]
US 20220374515A1 · Bridges · 2022 [cited by examiner]
US 20220374657A1 · Pandey · 2022 [cited by examiner]
US 20220383421A1 · Grivel · 2022 [cited by examiner]
US 20230054575A1 · Cohen · 2023 [cited by examiner]
US 20230114810A1 · Li · 2023 [cited by examiner]
US 20230182725A1 · Li · 2023 [cited by examiner]
US 20230188553A1 · Wee · 2023 [cited by examiner]
US 20230283622A1 · Vu · 2023 [cited by examiner]
US 20240411864A2 · Stein · 2024 [cited by examiner]
US 20250216934A1 · Kim · 2025 [cited by examiner]
JP 6740247B2 · 2020 [cited by applicant]
KR 101428989B1 · 2014 [cited by applicant]
KR 101714520B1 · 2017 [cited by applicant]
KR 102181762B1 · 2020 [cited by applicant]
KR 102204656B1 · 2021 [cited by applicant]
KR 102232871B1 · 2021 [cited by applicant]
KR 1020210043053A · 2021 [cited by applicant]
Paul et al.; An Artificial Neural Network Based Anomaly Detection Method in CAN Bus Messages in Vehicles; 2021 International Conference on Automation, Control and Mechatronics for Industry 4.0 (ACMI), Jul. 8-9, 2021, Ra… [cited by examiner]
Andrew John Tomlinson; Detecting Cyber Attacks on the Automotive Controller Area Network; Faculty of Engineering, Environment and Computing Institute for Future Transport and Cities; (Year: 2019). [cited by examiner]
Zhou et al., Anomaly Detection of CAN Bus Messages Using a Deep Neural Network for Autonomous Vehicles; (Year: 2019). [cited by examiner]
Vinayak Tanksale; Anomaly Detection for Controller Area Networks Using Long Short-Term Memory; (Year: 2020). [cited by examiner]
Tahsn C. M. Dönmez; Anomaly Detection in Vehicular CAN Bus Using Message Identifier Sequences; (Year: 2021). [cited by examiner]
Qin et al; Application of Controller Area Network (CAN) bus anomaly detection based on time series prediction; (Year: 2021). [cited by examiner]
Novikova et al.; Autoencoder Anomaly Detection on Large CAN Bus Data (Year: 2020). [cited by examiner]
Tariq et al.; CANTransfer—Transfer Learning based Intrusion Detection on a Controller Area Network using Convolutional LSTM Network (Year: 2020). [cited by examiner]
Zhu et al.; Mobile Edge Assisted Literal Multi-Dimensional Anomaly Detection of In-Vehicle Network Using LSTM; IEEE Transactions on Vehicular Technology, vol. 68, No. 5, May 2019 (Year: 2019). [cited by examiner]
International Search Report issued on Feb. 8, 2023 for corresponding International Patent Application No. PCT/KR2022/017082, along with an English translation (4 pages). [cited by applicant]
Written Opinion issued on Feb. 8, 2023 for corresponding International Patent Application No. PCT/KR2022/017082 (3 pages). [cited by applicant]
Seunghyun Park et al., “Hierarchical Anomaly Detection Model for In-Vehicle Networks Using Machine Learning Algorithms”, Sensors, vol. 20, Jul. 15, 2020, pp. 1-21. [cited by applicant]
Markus Hanselmann, “CANet: An Unsupervised Intrusion Detection System for High Dimensional CAN Bus Data”, IEEE Access, vol. 8, Mar. 23, 2020, pp. 58194-58205. [cited by applicant]