arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.19135cs.CRcs.DCcs.MAcs.NI

网联车辆中的自主网络防御:一种面向V2X安全的多智能体方法

Autonomous Cyber Defense in Connected Vehicles: A Multi-Agent Approach to V2X Security

Krishna Teja Medam

首次发表
浏览论文内容

中文总结 AI 辅助

针对网联车辆V2X安全,提出三层多智能体架构,以SAE标准时序为硬性约束,分层处理消息分类、冲突解决与模型优化,解决现有入侵检测系统的安全-安保冲突问题。

中文摘要 AI 辅助

网联车辆仅有约100毫秒的时间来判断收到的基本安全消息是真实的还是伪造的。如果虚假的紧急制动警报及时到达规划流水线,车辆就会制动——这是由安全故障引发的安全失效。现有的入侵检测系统并非为应对这种耦合情况而设计,它们按单辆车、单条消息运行,采用静态规则,无法识别仅在车队范围内或随时间推移才会显现的攻击模式,也无法识别丢弃可疑消息与丢弃真实紧急警报之间的根本矛盾。我们提出了一种三层多智能体架构,将这一时序约束视为硬性设计要求,而非性能目标。在车辆层面,车载智能体需在10毫秒的预算内将每条传入的V2X消息分类为四种动作之一:接受、丢弃、隔离或升级,在不确定时故意偏向升级,将模糊案例传递给路边边缘智能体,而非冒着丢弃合法警报的风险。边缘智能体在路边单元区域内运行,拥有50毫秒的预算,融合来自多辆车的威胁评估,并利用互补的传感器观测结果解决安全与安保的冲突。云端层通过拜占庭容错联邦学习优化检测模型,并将更新后的权重重新分配给车队。所有时序约束均直接源自SAE J2735和ETSI EN 302 637-2规定的100毫秒基本安全消息周期。目前尚无现有框架能同时为所有三个部署层级分配基于标准的延迟预算,并将安全-安保冲突解决视为首要设计约束。未来工作将探讨剩余的开放问题:边缘处的对抗性投毒,以及自主安全响应监管框架的缺失。

英文摘要

A connected vehicle has roughly 100 milliseconds to decide whether an incoming Basic Safety Message is real or fabricated. If a false emergency braking alert reaches the planning pipeline in time, the car brakes - a safety failure triggered by a security failure. Existing intrusion detection systems are not designed to handle that coupling. They operate per vehicle, per message, with static rules - blind to attack patterns that only emerge across a fleet or over time, and blind to the fundamental tension between dropping a suspicious message and dropping a real emergency alert. We propose a three-tier multi-agent architecture that treats this timing constraint as a hard design requirement, not a performance target. At the vehicle level, an onboard agent classifies each incoming V2X message into one of four actions - Accept, Drop, Quarantine, or Escalate - within a 10-millisecond budget, deliberately biased toward Escalate when uncertain, passing ambiguous cases to the roadside edge agent rather than risking a dropped legitimate alert. The edge agent operates across a roadside unit zone with a 50-millisecond budget, fusing threat assessments from multiple vehicles and resolving safety-security conflicts using complementary sensor observations. The cloud tier refines detection models through Byzantine fault-tolerant federated learning and redistributes updated weights to the fleet. Every timing constraint derives directly from the 100-millisecond Basic Safety Message cycles mandated by SAE J2735 and ETSI EN 302 637-2. No existing framework simultaneously assigns standards-grounded latency budgets to all three deployment tiers while treating safety-security conflict resolution as a first-class design constraint. Remaining open problems - adversarial poisoning at the edge and the absence of regulatory frameworks for autonomous security response - are discussed as future work.

↑