{"id":{"repo_id":"oxford-brookes","oai_identifier":"tle:708fd0cd-c64b-49b0-9999-23b6356d282f:d6bd9758-527a-46cd-bfe2-c433766e8fca:1"},"canonical_url":"https://search.dev.ndltd.org/etd/oxford-brookes/tle:708fd0cd-c64b-49b0-9999-23b6356d282f:d6bd9758-527a-46cd-bfe2-c433766e8fca:1","repository":{"repo_id":"oxford-brookes","name":"Oxford Brookes University","base_url":"https://radar.brookes.ac.uk/radar/oai"},"display":{"title":"Replay and bogus information attacks : simulation and empirical validation of machine learning-based cybersecurity threat detection in connected and autonomous vehicles","abstract":"Vehicle-to-Everything (V2X) communication is an essential technology for modern Intelligent Transportation Systems (ITS), enabling significant enhancements to traffic safety, efficiency, and autonomous driving. However, the increased connectivity and complexity of Vehicular Ad-hoc Networks (VANETs) introduce significant cybersecurity challenges, especially from sophisticated threats such as replay and bogus information attacks. While international standards (e.g., IEEE 1609.2, ETSI TS 103 097) establish baseline security through authentication, encryption, and digital signatures, these controls primarily address external threats; a critical gap remains for insider threats—legitimate, authenticated participants that inject false or misleading data. This research addresses that gap by developing and rigorously evaluating machine-learning (ML) methods to detect subtle, context-dependent replay and bogus-information attacks within Cooperative Awareness Messages (CAMs). Due to limited open datasets, a comprehensive dataset was generated using the Eclipse MOSAIC platform. Models spanning ensembles (GBM/DRF), deep learning (DL), and classical baselines (DT/NB/SVM/LG) were trained in simulation and deployed on Cohda MK6C hardware; Virtual CAN traffic emulated realistic dynamics to assess real-time performance and trade-offs. Results show that ensemble models deliver high precision and low latency on hardware, with GBM/DRF achieving precision 97.89–99.81% at 1.6–1.8 ms per prediction. The DL model improves replay-attack recall, reaching 88.56 ± 2.58% at 2.2–2.3 ms, reflecting a compute/latency trade-off. Compared to published insider/bogus-information attacks baselines reporting F1 ≈ 92.8%, the ensemble detectors achieve F1 ≈ 96–97% on standard CAM traffic, while maintaining near-perfect precision—indicating improved performance under realistic hardware timing. For replay attacks, hardware F1 ≈ 90–92% (precision ≈ 94–100%) is competitive with reports based only on simulations, which do not face hardware and timing variability. The findings also underscore the importance of feature engineering: robust spatial/plausibility features support strong bogus-information detection, whereas replay detection remains limited by the absence of absolute timestamps in CAMs, motivating richer temporal features. Overall, the study provides practical, hardware-validated guidance for selecting and deploying ML-based V2X cyberattack detection, directly addressing insider-threat risks in vehicular networks.","abstract_html":"Vehicle-to-Everything (V2X) communication is an essential technology for modern Intelligent Transportation Systems (ITS), enabling significant enhancements to traffic safety, efficiency, and autonomous driving. However, the increased connectivity and complexity of Vehicular Ad-hoc Networks (VANETs) introduce significant cybersecurity challenges, especially from sophisticated threats such as replay and bogus information attacks. While international standards (e.g., IEEE 1609.2, ETSI TS 103 097) establish baseline security through authentication, encryption, and digital signatures, these controls primarily address external threats; a critical gap remains for insider threats—legitimate, authenticated participants that inject false or misleading data. This research addresses that gap by developing and rigorously evaluating machine-learning (ML) methods to detect subtle, context-dependent replay and bogus-information attacks within Cooperative Awareness Messages (CAMs). Due to limited open datasets, a comprehensive dataset was generated using the Eclipse MOSAIC platform. Models spanning ensembles (GBM/DRF), deep learning (DL), and classical baselines (DT/NB/SVM/LG) were trained in simulation and deployed on Cohda MK6C hardware; Virtual CAN traffic emulated realistic dynamics to assess real-time performance and trade-offs. Results show that ensemble models deliver high precision and low latency on hardware, with GBM/DRF achieving precision 97.89–99.81% at 1.6–1.8 ms per prediction. The DL model improves replay-attack recall, reaching 88.56 ± 2.58% at 2.2–2.3 ms, reflecting a compute/latency trade-off. Compared to published insider/bogus-information attacks baselines reporting F1 ≈ 92.8%, the ensemble detectors achieve F1 ≈ 96–97% on standard CAM traffic, while maintaining near-perfect precision—indicating improved performance under realistic hardware timing. For replay attacks, hardware F1 ≈ 90–92% (precision ≈ 94–100%) is competitive with reports based only on simulations, which do not face hardware and timing variability. The findings also underscore the importance of feature engineering: robust spatial/plausibility features support strong bogus-information detection, whereas replay detection remains limited by the absence of absolute timestamps in CAMs, motivating richer temporal features. Overall, the study provides practical, hardware-validated guidance for selecting and deploying ML-based V2X cyberattack detection, directly addressing insider-threat risks in vehicular networks.","abstract_has_math":false,"creators":["Mohamed Iqbal, Safras"],"institution":"Oxford Brookes University","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":["Ball, Peter","Kamarudin, Muhammad Hilmi","Bradley, Andrew"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":null,"date_issued":"","date_published":null,"updated_at":"2026-07-24T03:42:06Z","subjects":[],"languages":["en"],"rights":["All rights reserved"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://doi.org/10.24384/402v-x347","outbound_label":"DOI","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Ball, Peter","Kamarudin, Muhammad Hilmi","Bradley, Andrew"]},{"key":"dc:creator","label":"Author","values":["Mohamed Iqbal, Safras"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:publisher","label":"Institution","values":["Oxford Brookes University"]},{"key":"dc:type","label":"Dc Type","values":["thesis"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["All rights reserved"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://doi.org/10.24384/402v-x347","https://radar.brookes.ac.uk/radar/file/708fd0cd-c64b-49b0-9999-23b6356d282f/1/Iqbal2025ReplayBogusInformationAttacks.pdf"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Vehicle-to-Everything (V2X) communication is an essential technology for modern Intelligent Transportation Systems (ITS), enabling significant enhancements to traffic safety, efficiency, and autonomous driving. However, the increased connectivity and complexity of Vehicular Ad-hoc Networks (VANETs) introduce significant cybersecurity challenges, especially from sophisticated threats such as replay and bogus information attacks. While international standards (e.g., IEEE 1609.2, ETSI TS 103 097) establish baseline security through authentication, encryption, and digital signatures, these controls primarily address external threats; a critical gap remains for insider threats—legitimate, authenticated participants that inject false or misleading data. This research addresses that gap by developing and rigorously evaluating machine-learning (ML) methods to detect subtle, context-dependent replay and bogus-information attacks within Cooperative Awareness Messages (CAMs). Due to limited open datasets, a comprehensive dataset was generated using the Eclipse MOSAIC platform. Models spanning ensembles (GBM/DRF), deep learning (DL), and classical baselines (DT/NB/SVM/LG) were trained in simulation and deployed on Cohda MK6C hardware; Virtual CAN traffic emulated realistic dynamics to assess real-time performance and trade-offs. Results show that ensemble models deliver high precision and low latency on hardware, with GBM/DRF achieving precision 97.89–99.81% at 1.6–1.8 ms per prediction. The DL model improves replay-attack recall, reaching 88.56 ± 2.58% at 2.2–2.3 ms, reflecting a compute/latency trade-off. Compared to published insider/bogus-information attacks baselines reporting F1 ≈ 92.8%, the ensemble detectors achieve F1 ≈ 96–97% on standard CAM traffic, while maintaining near-perfect precision—indicating improved performance under realistic hardware timing. For replay attacks, hardware F1 ≈ 90–92% (precision ≈ 94–100%) is competitive with reports based only on simulations, which do not face hardware and timing variability. The findings also underscore the importance of feature engineering: robust spatial/plausibility features support strong bogus-information detection, whereas replay detection remains limited by the absence of absolute timestamps in CAMs, motivating richer temporal features. Overall, the study provides practical, hardware-validated guidance for selecting and deploying ML-based V2X cyberattack detection, directly addressing insider-threat risks in vehicular networks."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Replay and bogus information attacks : simulation and empirical validation of machine learning-based cybersecurity threat detection in connected and autonomous vehicles"]}]}],"canonical_facts":{"dc:contributor":["Ball, Peter","Kamarudin, Muhammad Hilmi","Bradley, Andrew"],"dc:creator":["Mohamed Iqbal, Safras"],"dc:description":["Vehicle-to-Everything (V2X) communication is an essential technology for modern Intelligent Transportation Systems (ITS), enabling significant enhancements to traffic safety, efficiency, and autonomous driving. However, the increased connectivity and complexity of Vehicular Ad-hoc Networks (VANETs) introduce significant cybersecurity challenges, especially from sophisticated threats such as replay and bogus information attacks. While international standards (e.g., IEEE 1609.2, ETSI TS 103 097) establish baseline security through authentication, encryption, and digital signatures, these controls primarily address external threats; a critical gap remains for insider threats—legitimate, authenticated participants that inject false or misleading data. This research addresses that gap by developing and rigorously evaluating machine-learning (ML) methods to detect subtle, context-dependent replay and bogus-information attacks within Cooperative Awareness Messages (CAMs). Due to limited open datasets, a comprehensive dataset was generated using the Eclipse MOSAIC platform. Models spanning ensembles (GBM/DRF), deep learning (DL), and classical baselines (DT/NB/SVM/LG) were trained in simulation and deployed on Cohda MK6C hardware; Virtual CAN traffic emulated realistic dynamics to assess real-time performance and trade-offs. Results show that ensemble models deliver high precision and low latency on hardware, with GBM/DRF achieving precision 97.89–99.81% at 1.6–1.8 ms per prediction. The DL model improves replay-attack recall, reaching 88.56 ± 2.58% at 2.2–2.3 ms, reflecting a compute/latency trade-off. Compared to published insider/bogus-information attacks baselines reporting F1 ≈ 92.8%, the ensemble detectors achieve F1 ≈ 96–97% on standard CAM traffic, while maintaining near-perfect precision—indicating improved performance under realistic hardware timing. For replay attacks, hardware F1 ≈ 90–92% (precision ≈ 94–100%) is competitive with reports based only on simulations, which do not face hardware and timing variability. The findings also underscore the importance of feature engineering: robust spatial/plausibility features support strong bogus-information detection, whereas replay detection remains limited by the absence of absolute timestamps in CAMs, motivating richer temporal features. Overall, the study provides practical, hardware-validated guidance for selecting and deploying ML-based V2X cyberattack detection, directly addressing insider-threat risks in vehicular networks."],"dc:format":["application/pdf"],"dc:identifier":["https://doi.org/10.24384/402v-x347","https://radar.brookes.ac.uk/radar/file/708fd0cd-c64b-49b0-9999-23b6356d282f/1/Iqbal2025ReplayBogusInformationAttacks.pdf"],"dc:language":["en"],"dc:publisher":["Oxford Brookes University"],"dc:rights":["All rights reserved"],"dc:title":["Replay and bogus information attacks : simulation and empirical validation of machine learning-based cybersecurity threat detection in connected and autonomous vehicles"],"dc:type":["thesis"]},"updated_at":"2026-07-24T03:42:06Z"}