发表机构
Clemson University(克莱姆森大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究开发了基于共享编码器LSTM数字孪生的入侵检测系统,可检测保留正常CAN通信模式的隐秘有效载荷攻击,检测率优于基线模型,但假阳性率较高。
AI 中文摘要
现有针对控制器局域网(CAN)的汽车入侵检测系统(IDS)大多针对消息时序、频率或序列的异常,无法检测那些在保留这些属性的同时操纵有效载荷的攻击。数字孪生(DT)已被用于模拟CAN流量并生成攻击场景以评估IDS,但其在入侵检测中的应用仍未被探索。本研究开发了一种基于DT的IDS,该模型联合对解码后的动力总成信号之间的物理关系进行建模,并通过预测行为与观测行为之间的残差来识别攻击。采用共享编码器LSTM DT,基于现代Hyundai/Kia真实CAN日志中的17个解码信号进行训练,以在24步窗口内联合预测7个数值型和2个分类型挡位信号。当残差超过校准阈值时,时间步会被标记,而自适应展开机制可保护孪生模型的输入历史免受持续污染。针对孪生模型和范围-合理性基线评估了4种攻击(平台攻击、持续漂移攻击、伪装攻击和挡位伪装攻击)。DT在所有攻击上的表现均优于基线,对持续漂移攻击的检测率达94.6%,对伪装攻击的检测率达89.2%,而基线几乎未检测到任何伪造的有效载荷攻击。这些结果表明,耦合车辆动力学学习能够检测保留正常CAN通信模式的隐秘有效载荷操纵。假阳性率达39.6%,凸显了在持续攻击下提高鲁棒性的必要性。基于DT的IDS在检测保留正常通信模式的隐秘有效载荷级CAN攻击方面展现出潜力,为联网与自动驾驶汽车的基于行为的网络安全提供支持。
英文摘要
Existing automotive intrusion detection systems (IDSs) for the Controller Area Network (CAN) largely target discrepancies in message timing, frequency, or sequencing and cannot detect attacks that preserve these properties while manipulating the payload. Digital twins (DTs) have been used to emulate CAN traffic and generate attack scenarios for IDS evaluation, but their use for intrusion detection remains unexplored. This study develops a DT-based IDS that jointly models physical relationships among decoded powertrain signals and identifies attacks through residuals between predicted and observed behavior. A shared-encoder LSTM DT was trained on 17 decoded signals from a real Hyundai/Kia CAN log to jointly predict seven numeric and two categorical gear signals over a 24-step window. A timestep is flagged when a residual exceeds a calibrated threshold, while adaptive rollout protects the twin's input history from sustained contamination. Four attacks (plateau, continuous drift, masquerade, and gear masquerade) were evaluated against the twin and a range-and-plausibility baseline. The DT outperformed the baseline across all attacks, achieving detection rates of 94.6% for continuous drift and 89.2% for masquerade, while the baseline detected almost none of the fabricated payload attacks. These results demonstrate that learning coupled vehicle dynamics enables detection of stealthy payload manipulations that preserve normal CAN communication patterns. False positive rates reached 39.6%, highlighting the need for improved robustness under sustained attacks. The DT-based IDS shows promise for detecting stealthy payload-level CAN attacks that preserve normal communication patterns, supporting behavior-based cybersecurity for connected and automated vehicles.
Comments20 pages, 4 figures Paper submitted for presentation at the Transportation Research Board Annual Meeting and publication in Transportation Research Record. Under review for both cases