发表机构
Trinity College Dublin(都柏林圣三一学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对车载网络的安全需求,提出双IDS架构,结合量化LSTM和量化自编码器,在FPGA上实现高精度、低延迟的已知与未知攻击检测。
AI 中文摘要
与外部世界日益增长的连接性以及缺乏内置安全机制,使得传统的车内网络容易受到网络攻击。早期研究侧重于最大化对已知和未知攻击的检测准确性,通常使用大型全精度机器学习模型。然而,将入侵检测系统嵌入车辆电子系统还需要低检测延迟、高能效和最小的电子控制单元(ECU)资源开销,以处理约2000帧/秒的CAN总线流量。轻量级模型必须在准确性上平衡这些部署约束。我们提出了一种双入侵检测系统框架,包含基于监督和无监督学习的解决方案,各自针对实时、资源受限的汽车平台进行了优化。基于量化的LSTM的入侵检测系统(QLSTM-IDS)在两种广泛使用的数据集上,使用单一模型架构,对拒绝服务(DoS)/洪泛、模糊测试和欺骗/故障攻击实现了超过99.9%的检测准确率。该模型使用Brevitas量化感知训练库进行训练,转换为与AMD的FINN工具链兼容的自定义块的数据流加速器,并使用Vitis HLS进行综合。作为补充,一个8比特量化的卷积自编码器入侵检测系统(QCAE-IDS),使用AMD的Vitis-AI工具链进行量化,能够检测改变CAN-ID序列模式的未知异常,准确率超过99%。一种集成架构使两种模型能够在单个FPGA上运行,桥接网络接口IP和处理系统,以最小化软件开销。QLSTM-IDS实现了每条消息0.25毫秒的推理延迟和0.8毫焦耳的能耗,而QCAE-IDS每个块实现了0.42毫秒和1.1毫焦耳。两种解决方案均在ZCU104 SoC(XCZU7EV FPGA)上部署和评估,展示了针对高速CAN总线上的已知和未知攻击的实时检测的灵活软硬件协同设计。
英文摘要
Increasing connectivity to the outside world and the lack of inbuilt security mechanisms have made legacy intra-vehicular networks vulnerable to cyberattacks. Initial research focused on maximising detection accuracy for known and unknown attacks, often using large, full-precision machine learning models. However, embedding IDSs into vehicular electronic systems also requires low detection latency, energy efficiency and minimal electronic control unit (ECU) resource overhead to process about 2,000 CAN frames/s. Lightweight models must balance accuracy with these deployment constraints. We propose a dual IDS framework comprising supervised and unsupervised learning-based solutions, each optimised for real-time, resource-constrained automotive platforms. A quantised LSTM-based IDS (QLSTM-IDS) achieves over 99.9% detection accuracy for DoS/Flooding, Fuzzing and Spoofing/Malfunction attacks using a single model architecture evaluated on two widely used datasets. The model is trained using the Brevitas quantisation-aware training library, transformed into a dataflow accelerator with custom blocks compatible with AMD's FINN toolchain, and synthesised using Vitis HLS. Complementing this, an 8-bit quantised convolutional autoencoder-based IDS (QCAE-IDS), quantised using AMD's Vitis-AI toolchain, detects previously unseen anomalies that alter CAN-ID sequence patterns with over 99% accuracy. An integration architecture enables both models to operate on a single FPGA, bridging the network interface IP and processing system to minimise software overhead. QLSTM-IDS achieves 0.25 ms inference latency and 0.8 mJ energy consumption per message, while QCAE-IDS achieves 0.42 ms and 1.1 mJ per block. Both solutions are deployed and evaluated on the ZCU104 SoC (XCZU7EV FPGA), demonstrating a flexible hardware/software co-design for real-time detection of known and unknown attacks on high-speed CAN buses.
Comments30 pages, 9 figures, 11 tables, ACM Transactions on Embedded Computing Systems