{"id":{"repo_id":"rgu","oai_identifier":"oai:rgu-repository.worktribe.com:2801124"},"canonical_url":"https://search.dev.ndltd.org/etd/rgu/oai:rgu-repository.worktribe.com:2801124","repository":{"repo_id":"rgu","name":"Robert Gordon University","base_url":"https://rgu-repository.worktribe.com/oaiprovider"},"display":{"title":"Protecting vehicles from cyberattacks: context aware AI-based intrusion detection for vehicle CAN bus security.","abstract":"Modern automobiles are equipped with a large number of electronic control units (ECUs), which are interconnected through the controller area network (CAN) bus for real-time data exchange. However, the CAN bus lacks security measures, rendering it susceptible to cyberattacks, endangering passenger safety. Although artificial intelligence (AI)-based intrusion detection systems (IDSs) can detect these attacks, achieving higher detection rates in near-real-time poses challenges. This research aims to enhance in-vehicle network (IVN) attack detection by developing a deployable AI-based IDS. First, a lightweight context-aware IDS named CAN-CID is introduced, employing a combination of a gated recurrent unit (GRU)-based recurrent neural network (RNN) model and a time-based model. CAN-CID is designed to detect injection and masquerade attacks on the CAN bus. It achieved an F1 score of over 99% on three publicly available CAN attack datasets for 10 injections and three masquerade attacks, outperforming baseline models. To overcome the challenge of requiring a large dataset for effective attack detection with the GRU-based model for medium and low frequent IDs, CAN-ODTL, a novel on-device transfer learning technique, is introduced. CAN-ODTL outperformed the pre-trained and baseline models with over 99% detection rate for realistic attacks. CAN-ODTL is designed to be trained with a larger dataset compared to CAN-CID model to learn the majority of benign patterns of medium and low-frequency IDs, thus enhancing its ability to detect attacks targeting such IDs. As streaming learning approaches such as CAN-ODTL are susceptible to data poisoning attacks, an anomaly detection method leveraging the Mahalanobis distance is employed to identify and eliminate poisoned data samples before model retraining. Evaluation on a real dataset with varying percentages of data poisoning attacks demonstrates the method's high accuracy of 100% in detecting poisoned samples. While CAN ID-based CAN-ODTL is effective against injection and certain masquerade attacks, it faces challenges in detecting attacks that only alter the payload field. To address this limitation, an improved autoencoder (AE)-based model, known as Latent AE, is introduced for detecting attacks aimed at the payload data. The ensemble of the GRU-based RNN model and Latent AE demonstrated its superiority over baseline models, exhibiting near-real-time detection latency. In response to the current lack of realistic attack datasets, a novel CAN bus dataset is presented. The improved models of proposed CAN-ODTL and Latent AE models are then deployed in a real vehicle and evaluated with real-world attacks. This demonstrated the effectiveness of the proposed IDS by achieving over a 99% attack detection rate for 23 attacks with near-real time detection latency of 25ms. These results highlight the effectiveness of employing multiple IDSs, each utilizing distinct fields of the CAN data, in detecting attacks and achieving near-real-time detection.","abstract_html":"Modern automobiles are equipped with a large number of electronic control units (ECUs), which are interconnected through the controller area network (CAN) bus for real-time data exchange. However, the CAN bus lacks security measures, rendering it susceptible to cyberattacks, endangering passenger safety. Although artificial intelligence (AI)-based intrusion detection systems (IDSs) can detect these attacks, achieving higher detection rates in near-real-time poses challenges. This research aims to enhance in-vehicle network (IVN) attack detection by developing a deployable AI-based IDS. First, a lightweight context-aware IDS named CAN-CID is introduced, employing a combination of a gated recurrent unit (GRU)-based recurrent neural network (RNN) model and a time-based model. CAN-CID is designed to detect injection and masquerade attacks on the CAN bus. It achieved an F1 score of over 99% on three publicly available CAN attack datasets for 10 injections and three masquerade attacks, outperforming baseline models. To overcome the challenge of requiring a large dataset for effective attack detection with the GRU-based model for medium and low frequent IDs, CAN-ODTL, a novel on-device transfer learning technique, is introduced. CAN-ODTL outperformed the pre-trained and baseline models with over 99% detection rate for realistic attacks. CAN-ODTL is designed to be trained with a larger dataset compared to CAN-CID model to learn the majority of benign patterns of medium and low-frequency IDs, thus enhancing its ability to detect attacks targeting such IDs. As streaming learning approaches such as CAN-ODTL are susceptible to data poisoning attacks, an anomaly detection method leveraging the Mahalanobis distance is employed to identify and eliminate poisoned data samples before model retraining. Evaluation on a real dataset with varying percentages of data poisoning attacks demonstrates the method&#x27;s high accuracy of 100% in detecting poisoned samples. While CAN ID-based CAN-ODTL is effective against injection and certain masquerade attacks, it faces challenges in detecting attacks that only alter the payload field. To address this limitation, an improved autoencoder (AE)-based model, known as Latent AE, is introduced for detecting attacks aimed at the payload data. The ensemble of the GRU-based RNN model and Latent AE demonstrated its superiority over baseline models, exhibiting near-real-time detection latency. In response to the current lack of realistic attack datasets, a novel CAN bus dataset is presented. The improved models of proposed CAN-ODTL and Latent AE models are then deployed in a real vehicle and evaluated with real-world attacks. This demonstrated the effectiveness of the proposed IDS by achieving over a 99% attack detection rate for 23 attacks with near-real time detection latency of 25ms. These results highlight the effectiveness of employing multiple IDSs, each utilizing distinct fields of the CAN data, in detecting attacks and achieving near-real-time detection.","abstract_has_math":false,"creators":["Rajapaksha, Sampath"],"institution":"Robert Gordon University","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":["H. Kalutarage, O. Al-Kadri, A. Petrovski, G. Madzudzo and M. Cheah"],"committee_chairs":[],"committee_members":[],"year":2024,"date_issued":"2024","date_published":"2024","updated_at":"2026-07-24T04:10:09Z","subjects":["Vehicle systems","Controller area networks (CANs)","Cybersecurity","Systems security","Intrusion detection"],"languages":["en"],"rights":[],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier","label":"Identifier","values":["oai:rgu-repository.worktribe.com:2801124","https://doi.org/10.48526/rgu-wt-2801124"],"render_values":[{"text":"oai:rgu-repository.worktribe.com:2801124","href":null,"code":true},{"text":"https://doi.org/10.48526/rgu-wt-2801124","href":"https://doi.org/10.48526/rgu-wt-2801124","code":true}]}]},"links":{"outbound_url":"https://rgu-repository.worktribe.com/2801124/1/RAJAPAKSHA%202024%20Protecting%20vehicles%20from%20cyberattacks","outbound_label":"Repository record","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["H. Kalutarage, O. Al-Kadri, A. Petrovski, G. Madzudzo and M. Cheah"]},{"key":"dc:contributor.sponsor","label":"Sponsor","values":["HORIBA MIRA Ltd"]},{"key":"dc:creator","label":"Author","values":["Rajapaksha, Sampath"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2024-08-31"]},{"key":"dc:date.issued","label":"Date","values":["2024"]},{"key":"dc:publisher.institution","label":"Dc Publisher Institution","values":["Robert Gordon University"]},{"key":"dc:relation.isreferencedby","label":"Dc Relation Isreferencedby","values":["https://rgu-repository.worktribe.com/output/2801124"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Vehicle systems","Controller area networks (CANs)","Cybersecurity","Systems security","Intrusion detection"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["oai:rgu-repository.worktribe.com:2801124","https://doi.org/10.48526/rgu-wt-2801124"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://rgu-repository.worktribe.com/2801124/1/RAJAPAKSHA%202024%20Protecting%20vehicles%20from%20cyberattacks"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Modern automobiles are equipped with a large number of electronic control units (ECUs), which are interconnected through the controller area network (CAN) bus for real-time data exchange. However, the CAN bus lacks security measures, rendering it susceptible to cyberattacks, endangering passenger safety. Although artificial intelligence (AI)-based intrusion detection systems (IDSs) can detect these attacks, achieving higher detection rates in near-real-time poses challenges. This research aims to enhance in-vehicle network (IVN) attack detection by developing a deployable AI-based IDS. First, a lightweight context-aware IDS named CAN-CID is introduced, employing a combination of a gated recurrent unit (GRU)-based recurrent neural network (RNN) model and a time-based model. CAN-CID is designed to detect injection and masquerade attacks on the CAN bus. It achieved an F1 score of over 99% on three publicly available CAN attack datasets for 10 injections and three masquerade attacks, outperforming baseline models. To overcome the challenge of requiring a large dataset for effective attack detection with the GRU-based model for medium and low frequent IDs, CAN-ODTL, a novel on-device transfer learning technique, is introduced. CAN-ODTL outperformed the pre-trained and baseline models with over 99% detection rate for realistic attacks. CAN-ODTL is designed to be trained with a larger dataset compared to CAN-CID model to learn the majority of benign patterns of medium and low-frequency IDs, thus enhancing its ability to detect attacks targeting such IDs. As streaming learning approaches such as CAN-ODTL are susceptible to data poisoning attacks, an anomaly detection method leveraging the Mahalanobis distance is employed to identify and eliminate poisoned data samples before model retraining. Evaluation on a real dataset with varying percentages of data poisoning attacks demonstrates the method's high accuracy of 100% in detecting poisoned samples. While CAN ID-based CAN-ODTL is effective against injection and certain masquerade attacks, it faces challenges in detecting attacks that only alter the payload field. To address this limitation, an improved autoencoder (AE)-based model, known as Latent AE, is introduced for detecting attacks aimed at the payload data. The ensemble of the GRU-based RNN model and Latent AE demonstrated its superiority over baseline models, exhibiting near-real-time detection latency. In response to the current lack of realistic attack datasets, a novel CAN bus dataset is presented. The improved models of proposed CAN-ODTL and Latent AE models are then deployed in a real vehicle and evaluated with real-world attacks. This demonstrated the effectiveness of the proposed IDS by achieving over a 99% attack detection rate for 23 attacks with near-real time detection latency of 25ms. These results highlight the effectiveness of employing multiple IDSs, each utilizing distinct fields of the CAN data, in detecting attacks and achieving near-real-time detection."]},{"key":"dc:title","label":"Title","values":["Protecting vehicles from cyberattacks: context aware AI-based intrusion detection for vehicle CAN bus security."]}]}],"canonical_facts":{"dc:contributor.advisor":["H. Kalutarage, O. Al-Kadri, A. Petrovski, G. Madzudzo and M. Cheah"],"dc:contributor.sponsor":["HORIBA MIRA Ltd"],"dc:creator":["Rajapaksha, Sampath"],"dc:date":["2024-08-31"],"dc:date.issued":["2024"],"dc:description.abstract":["Modern automobiles are equipped with a large number of electronic control units (ECUs), which are interconnected through the controller area network (CAN) bus for real-time data exchange. However, the CAN bus lacks security measures, rendering it susceptible to cyberattacks, endangering passenger safety. Although artificial intelligence (AI)-based intrusion detection systems (IDSs) can detect these attacks, achieving higher detection rates in near-real-time poses challenges. This research aims to enhance in-vehicle network (IVN) attack detection by developing a deployable AI-based IDS. First, a lightweight context-aware IDS named CAN-CID is introduced, employing a combination of a gated recurrent unit (GRU)-based recurrent neural network (RNN) model and a time-based model. CAN-CID is designed to detect injection and masquerade attacks on the CAN bus. It achieved an F1 score of over 99% on three publicly available CAN attack datasets for 10 injections and three masquerade attacks, outperforming baseline models. To overcome the challenge of requiring a large dataset for effective attack detection with the GRU-based model for medium and low frequent IDs, CAN-ODTL, a novel on-device transfer learning technique, is introduced. CAN-ODTL outperformed the pre-trained and baseline models with over 99% detection rate for realistic attacks. CAN-ODTL is designed to be trained with a larger dataset compared to CAN-CID model to learn the majority of benign patterns of medium and low-frequency IDs, thus enhancing its ability to detect attacks targeting such IDs. As streaming learning approaches such as CAN-ODTL are susceptible to data poisoning attacks, an anomaly detection method leveraging the Mahalanobis distance is employed to identify and eliminate poisoned data samples before model retraining. Evaluation on a real dataset with varying percentages of data poisoning attacks demonstrates the method's high accuracy of 100% in detecting poisoned samples. While CAN ID-based CAN-ODTL is effective against injection and certain masquerade attacks, it faces challenges in detecting attacks that only alter the payload field. To address this limitation, an improved autoencoder (AE)-based model, known as Latent AE, is introduced for detecting attacks aimed at the payload data. The ensemble of the GRU-based RNN model and Latent AE demonstrated its superiority over baseline models, exhibiting near-real-time detection latency. In response to the current lack of realistic attack datasets, a novel CAN bus dataset is presented. The improved models of proposed CAN-ODTL and Latent AE models are then deployed in a real vehicle and evaluated with real-world attacks. This demonstrated the effectiveness of the proposed IDS by achieving over a 99% attack detection rate for 23 attacks with near-real time detection latency of 25ms. These results highlight the effectiveness of employing multiple IDSs, each utilizing distinct fields of the CAN data, in detecting attacks and achieving near-real-time detection."],"dc:identifier":["oai:rgu-repository.worktribe.com:2801124","https://doi.org/10.48526/rgu-wt-2801124"],"dc:identifier.uri":["https://rgu-repository.worktribe.com/2801124/1/RAJAPAKSHA%202024%20Protecting%20vehicles%20from%20cyberattacks"],"dc:language":["en"],"dc:publisher.institution":["Robert Gordon University"],"dc:relation.isreferencedby":["https://rgu-repository.worktribe.com/output/2801124"],"dc:subject":["Vehicle systems","Controller area networks (CANs)","Cybersecurity","Systems security","Intrusion detection"],"dc:title":["Protecting vehicles from cyberattacks: context aware AI-based intrusion detection for vehicle CAN bus security."],"dc:type":["Thesis"]},"updated_at":"2026-07-24T04:10:09Z"}