Back to results

Oxford Brookes University

Replay and bogus information attacks : simulation and empirical validation of machine learning-based cybersecurity threat detection in connected and autonomous vehicles

Abstract

dc:description

Vehicle-to-Everything (V2X) communication is an essential technology for modern Intelligent Transportation Systems (ITS), enabling significant enhancements to traffic safety, efficiency, and autonomous driving. However, the increased connectivity and complexity of Vehicular Ad-hoc Networks (VANETs) introduce significant cybersecurity challenges, especially from sophisticated threats such as replay and bogus information attacks. While international standards (e.g., IEEE 1609.2, ETSI TS 103 097) establish baseline security through authentication, encryption, and digital signatures, these controls primarily address external threats; a critical gap remains for insider threats—legitimate, authenticated participants that inject false or misleading data. This research addresses that gap by developing and rigorously evaluating machine-learning (ML) methods to detect subtle, context-dependent replay and bogus-information attacks within Cooperative Awareness Messages (CAMs). Due to limited open datasets, a comprehensive dataset was generated using the Eclipse MOSAIC platform. Models spanning ensembles (GBM/DRF), deep learning (DL), and classical baselines (DT/NB/SVM/LG) were trained in simulation and deployed on Cohda MK6C hardware; Virtual CAN traffic emulated realistic dynamics to assess real-time performance and trade-offs. Results show that ensemble models deliver high precision and low latency on hardware, with GBM/DRF achieving precision 97.89–99.81% at 1.6–1.8 ms per prediction. The DL model improves replay-attack recall, reaching 88.56 ± 2.58% at 2.2–2.3 ms, reflecting a compute/latency trade-off. Compared to published insider/bogus-information attacks baselines reporting F1 ≈ 92.8%, the ensemble detectors achieve F1 ≈ 96–97% on standard CAM traffic, while maintaining near-perfect precision—indicating improved performance under realistic hardware timing. For replay attacks, hardware F1 ≈ 90–92% (precision ≈ 94–100%) is competitive with reports based only on simulations, which do not face hardware and timing variability. The findings also underscore the importance of feature engineering: robust spatial/plausibility features support strong bogus-information detection, whereas replay detection remains limited by the absence of absolute timestamps in CAMs, motivating richer temporal features. Overall, the study provides practical, hardware-validated guidance for selecting and deploying ML-based V2X cyberattack detection, directly addressing insider-threat risks in vehicular networks.

Degree

thesis:*
Grantor dc:publisher
Oxford Brookes University

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Mohamed Iqbal, Safras
Contributors dc:contributor
  • Ball, Peter
  • Kamarudin, Muhammad Hilmi
  • Bradley, Andrew

Rights

dc:rights
Statement dc:rights
  • All rights reserved
Language dc:language
en

Identifiers

dc:identifier.*
OAI identifier oai:identifier
tle:708fd0cd-c64b-49b0-9999-23b6356d282f:d6bd9758-527a-46cd-bfe2-c433766e8fca:1

Chain of custody

source
Harvested from
Oxford Brookes University
Base URL
radar.brookes.ac.uk/radar/oai
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
related terms
citation

Mohamed Iqbal, Safras. Replay and bogus information attacks : simulation and empirical validation of machine learning-based cybersecurity threat detection in connected and autonomous vehicles. Oxford Brookes University, https://doi.org/10.24384/402v-x347