arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.19791cs.CR

Sybil-TraceGuard:基于动态半监督GNN的网联自动驾驶汽车可追溯性增强型女巫攻击防护机制

Sybil-TraceGuard: Traceability-enhanced Sybil Guardian for Connected and Autonomous Vehicles Using Dynamic Semi-supervised GNN

Qian Xu, Jiaxun Zhang, Chengyue Wang, Zhenning Li

首次发表
浏览论文内容

中文总结 AI 辅助

针对网联自动驾驶汽车中女巫攻击身份碎片化且标签稀缺的问题,提出动态半监督时空GNN框架Sybil-TraceGuard,通过四个耦合模块实现碎片化假名到源攻击者的追溯,在多种攻击场景下优于现有基线。

中文摘要 AI 辅助

网联自动驾驶汽车(CAVs)面临严重的女巫攻击(Sybil攻击),攻击者利用保护隐私的假名切换机制,在伪造基本安全消息(BSMs)的同时异常交替身份。尽管现有方案能够标记可疑行为,但这些时间上碎片化的女巫身份使得传统的单点式和基于序列的深度学习方法失效。将这些碎片化身份追溯到源攻击者对于根因消除至关重要,尤其是在极端标签稀缺的情况下。为此,提出Sybil-TraceGuard,作为一种用于女巫防护的动态半监督时空图神经网络(GNN)框架,优先关注“谁负责”而非“是否正在发生攻击”。该框架包含四个紧密耦合的模块:增量流攻击检测(ISAD)用于高效的女巫攻击预筛选;动态拓扑感知构造器(DTC)用于构建时空动态图;具有多头注意力的空间GAT编码器(SGEM)用于捕获空间交互中的多身份逻辑冲突;以及多尺度时空审计(MSTA)用于审计短期和长期的时间不一致性。这些模块在基于特征-边洗牌扰动的半监督均值教师(Mean-Teacher)框架内进行优化,利用极少量标签对潜在特征空间进行正则化。在四种女巫攻击场景下的实验表明,Sybil-TraceGuard能够有效地将碎片化假名链接到源攻击者。在未标记比例为0.70-0.95的情况下,它优于最先进的基线方法,并且在极端类别不平衡和不同超参数设置下保持高稳定性和敏感性。

英文摘要

Connected and autonomous vehicles (CAVs) face severe Sybil attacks, where attackers exploit privacy-preserving pseudonym-switching mechanisms to anomaly alternate identities while forging Basic Safety Messages (BSMs). Although existing schemes can flag suspicious behaviors, these temporally fragmented Sybil identities render traditional single-point and sequence-based deep learning methods ineffective. Linking these fragmented identities back to the source attacker is essential for root-cause elimination, particularly under extreme label scarcity. Therefore, the Sybil-TraceGuard is proposed as a dynamic semi-supervised spatio-temporal GNN framework for Sybil Guardian, prioritizing "who is responsible" over "whether an attack is happening". It comprises four tightly coupled modules: Incremental Stream Attack Detection (ISAD) for efficient Sybil attack pre-screening; the Dynamic Topology-aware Constructor (DTC) for constructing spatio-temporal dynamic graphs; the Spatial GAT-Encoder with Multi-head Attention (SGEM) to capture multi-identity logical conflicts in spatial interactions; and the Multi-scale Spatio-Temporal Audit (MSTA) to audit short-term and long-term temporal inconsistencies. These modules are optimized within a semi-supervised Mean-Teacher framework via feature-edge shuffling perturbations, regularizing the latent feature space using minimal labels. Experiments across four Sybil attack scenarios demonstrate that Sybil-TraceGuard effectively links fragmented pseudonyms to source attackers. It outperforms state-of-the-art baselines across unlabeled ratios of 0.70-0.95, maintaining high stability and sensitivity despite extreme class imbalance and varying hyperparameter settings.

发表机构

  • University of Macau(澳门大学)
  • State Key Laboratory of Internet of Things for Smart City, University of Macau(澳门大学物联网与智慧城市重点实验室)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑