X-SPUR:面向汽车以太网入侵检测的可解释、基于惊异度、协议感知的无监督推理
X-SPUR: Explainable Surprisal-Based Protocol-Aware Unsupervised Reasoning for Automotive Ethernet Intrusion Detection
- Sookmyung Women’s University(淑明女子大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
X-SPUR提出基于惊异度的协议感知无监督推理框架,以令牌序列表示数据包,结合双模态融合与双top-k%校准,在TOW-IDS上AUC达0.9987,并消除手工特征工程。
AI中文摘要:
汽车以太网在现代车载网络中承载异构多协议流量,其中带标签的攻击数据很少,且最强的现有无监督检测器仍依赖手工设计的流量特征。本文提出X-SPUR,一个可解释的、基于惊异度的、协议感知的无监督推理框架,该框架将原始数据包字段表示为令牌序列,通过因果语言建模学习良性流量模式,并从每个令牌的交叉熵惊异度中检测异常。为纳入时间上下文,我们引入一种双模态融合架构,通过加法融合和Hadamard交互将负载令牌嵌入与数据包间时序相结合。为处理不同协议族异构的分数分布,我们进一步提出一种双top-k%每协议Z分数校准方法,以联合捕获中等分布和稀疏的异常特征。在TOW-IDS数据集上,X-SPUR实现了0.9987的AUC,略高于AERO报告的0.9969。X-SPUR还消除了手工特征工程。我们使用相同架构和训练超参数训练了一个独立的CarDS模型,该模型在第二个汽车以太网数据集上保持了强劲性能。在检测之外,逐令牌惊异度通过将异常分数归因于特定协议字段提供了细粒度的可解释性,支持异构车载网络中可解释的安全分析。
英文摘要:
Automotive Ethernet carries heterogeneous multi-protocol traffic in modern in-vehicle networks, where labeled attack data are rarely available and the strongest prior unsupervised detector still relies on handcrafted traffic features. This article presents X-SPUR, an explainable, surprisal-based, protocol-aware unsupervised reasoning framework that instead represents raw packet fields as token sequences, learns benign traffic patterns through causal language modeling, and detects anomalies from per-token cross-entropy surprisal. To incorporate temporal context, we introduce a bimodal fusion architecture that combines payload-token embeddings with inter-packet timing through additive fusion and a Hadamard interaction. To handle the heterogeneous score distributions of different protocol families, we further propose a dual top-$k$% per-protocol $Z$-score calibration that jointly captures moderately distributed and sparse anomaly signatures. On the TOW-IDS dataset, X-SPUR achieves an AUC of 0.9987. This is marginally higher than the 0.9969 reported for AERO. X-SPUR also eliminates handcrafted feature engineering. We train a separate CarDS model using the same architecture and training hyperparameters. This model retains strong performance on the second automotive Ethernet dataset. Beyond detection, per-token surprisal provides fine-grained explainability by attributing anomaly scores to specific protocol fields, supporting interpretable security analysis in heterogeneous in-vehicle networks.