Oxford Brookes University
Replay and bogus information attacks : simulation and empirical validation of machine learning-based cybersecurity threat detection in connected and autonomous vehicles
Abstract
dc:descriptionVehicle-to-Everything (V2X) communication is an essential technology for modern Intelligent Transportation Systems (ITS), enabling significant enhancements to traffic safety, efficiency, and autonomous driving. However, the increased connectivity and complexity of Vehicular Ad-hoc Networks (VANETs) introduce significant cybersecurity challenges, especially from sophisticated threats such as replay and bogus information attacks. While international standards (e.g., IEEE 1609.2, ETSI TS 103 097) establish baseline security through authentication, encryption, and digital signatures, these controls primarily address external threats; a critical gap remains for insider threats—legitimate, authenticated participants that inject false or misleading data. This research addresses that gap by developing and rigorously evaluating machine-learning (ML) methods to detect subtle, context-dependent replay and bogus-information attacks within Cooperative Awareness Messages (CAMs). Due to limited open datasets, a comprehensive dataset was generated using the Eclipse MOSAIC platform. Models spanning ensembles (GBM/DRF), deep learning (DL), and classical baselines (DT/NB/SVM/LG) were trained in simulation and deployed on Cohda MK6C hardware; Virtual CAN traffic emulated realistic dynamics to assess real-time performance and trade-offs. Results show that ensemble models deliver high precision and low latency on hardware, with GBM/DRF achieving precision 97.89–99.81% at 1.6–1.8 ms per prediction. The DL model improves replay-attack recall, reaching 88.56 ± 2.58% at 2.2–2.3 ms, reflecting a compute/latency trade-off. Compared to published insider/bogus-information attacks baselines reporting F1 ≈ 92.8%, the ensemble detectors achieve F1 ≈ 96–97% on standard CAM traffic, while maintaining near-perfect precision—indicating improved performance under realistic hardware timing. For replay attacks, hardware F1 ≈ 90–92% (precision ≈ 94–100%) is competitive with reports based only on simulations, which do not face hardware and timing variability. The findings also underscore the importance of feature engineering: robust spatial/plausibility features support strong bogus-information detection, whereas replay detection remains limited by the absence of absolute timestamps in CAMs, motivating richer temporal features. Overall, the study provides practical, hardware-validated guidance for selecting and deploying ML-based V2X cyberattack detection, directly addressing insider-threat risks in vehicular networks.
Degree
thesis:*- Grantor dc:publisher
- Oxford Brookes University
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Mohamed Iqbal, Safras
- Contributors dc:contributor
-
- Ball, Peter
- Kamarudin, Muhammad Hilmi
- Bradley, Andrew
Rights
dc:rights- Statement dc:rights
-
- All rights reserved
- Language dc:language
- en
Identifiers
dc:identifier.*- DOI dc:identifier
- https://doi.org/10.24384/402v-x347
- OAI identifier oai:identifier
- tle:708fd0cd-c64b-49b0-9999-23b6356d282f:d6bd9758-527a-46cd-bfe2-c433766e8fca:1