{"id":{"repo_id":"umkc","oai_identifier":"oai:mospace.umsystem.edu:10355/112257"},"canonical_url":"https://search.dev.ndltd.org/etd/umkc/oai:mospace.umsystem.edu:10355/112257","repository":{"repo_id":"umkc","name":"University of Missouri - Kansas City","base_url":"https://mospace.umsystem.edu/oai/request"},"display":{"title":"Graph neural network approaches and real-time unsupervised learning for anomaly detection in vehicular networks","abstract":"The growing number of vehicles on modern roads has intensified challenges such as congestion, collisions, and fatalities, with abnormal driving behaviors, reckless, fatigued, or impaired, remaining leading causes. Vehicular networks, as a core component of intelligent transportation systems (ITS), enable real-time vehicle–infrastructure communication through Cooperative Awareness Messages (CAMs), offering opportunities to detect anomalies in both driving behavior and communication patterns.This dissertation proposes a dual-layer anomaly detection framework targeting: (1) unsafe driving behavior, and (2) Denial-of-Service (DoS) attacks in vehicular networks. For behavioral anomaly detection, spatial–temporal vehicle interactions are modeled as dynamic graphs and evaluated using six Graph Neural Network (GNN) architectures: Graph Convolutional Network (GCN), Graph Attention Network (GAT), GraphSAGE, Temporal GCN (T-GCN), Gated Convolutional LSTM (GConvLSTM), and Gated Convolutional GRU (GConvGRU). The GConvLSTM and GConvGRU models achieved the highest precision, recall, and F1-scores, with GraphSAGE and GAT providing competitive performance. To mitigate class imbalance, the Synthetic Minority Over-sampling Technique (SMOTE) improved recall, particularly for GCN and T-GCN. Performance was further enhanced by edge weight learning, which adaptively emphasized critical inter-vehicle relationships, and supervised triplet loss, which improved class separability. For communication-layer anomaly detection, a real-time, unsupervised framework was developed using a modified Online K-Means clustering algorithm integrated with outlier detection methods (One-Class SVM, Local Outlier Factor, Isolation Forest, and Elliptic Envelope). The proposed approach incorporates centroid repulsion, dynamic buffer normalization, and outlier-score-based thresholding, enabling adaptive detection without labeled data. Experiments on seven large-scale vehicular datasets generated with VSimRTI demonstrated that the modified Online K-Means, especially with One-Class SVM, consistently outperformed conventional clustering approaches in accuracy, adaptability, and efficiency. By addressing both behavioral and communication threats, this work advances the development of secure and resilient vehicular networks. The framework’s combination of interpretable GNN-based modeling and scalable online clustering contributes toward safer, more reliable connected and autonomous transportation systems.","abstract_html":"The growing number of vehicles on modern roads has intensified challenges such as congestion, collisions, and fatalities, with abnormal driving behaviors, reckless, fatigued, or impaired, remaining leading causes. Vehicular networks, as a core component of intelligent transportation systems (ITS), enable real-time vehicle–infrastructure communication through Cooperative Awareness Messages (CAMs), offering opportunities to detect anomalies in both driving behavior and communication patterns.This dissertation proposes a dual-layer anomaly detection framework targeting: (1) unsafe driving behavior, and (2) Denial-of-Service (DoS) attacks in vehicular networks. For behavioral anomaly detection, spatial–temporal vehicle interactions are modeled as dynamic graphs and evaluated using six Graph Neural Network (GNN) architectures: Graph Convolutional Network (GCN), Graph Attention Network (GAT), GraphSAGE, Temporal GCN (T-GCN), Gated Convolutional LSTM (GConvLSTM), and Gated Convolutional GRU (GConvGRU). The GConvLSTM and GConvGRU models achieved the highest precision, recall, and F1-scores, with GraphSAGE and GAT providing competitive performance. To mitigate class imbalance, the Synthetic Minority Over-sampling Technique (SMOTE) improved recall, particularly for GCN and T-GCN. Performance was further enhanced by edge weight learning, which adaptively emphasized critical inter-vehicle relationships, and supervised triplet loss, which improved class separability. For communication-layer anomaly detection, a real-time, unsupervised framework was developed using a modified Online K-Means clustering algorithm integrated with outlier detection methods (One-Class SVM, Local Outlier Factor, Isolation Forest, and Elliptic Envelope). The proposed approach incorporates centroid repulsion, dynamic buffer normalization, and outlier-score-based thresholding, enabling adaptive detection without labeled data. Experiments on seven large-scale vehicular datasets generated with VSimRTI demonstrated that the modified Online K-Means, especially with One-Class SVM, consistently outperformed conventional clustering approaches in accuracy, adaptability, and efficiency. By addressing both behavioral and communication threats, this work advances the development of secure and resilient vehicular networks. The framework’s combination of interpretable GNN-based modeling and scalable online clustering contributes toward safer, more reliable connected and autonomous transportation systems.","abstract_has_math":false,"creators":["Razzazi, Harir"],"institution":"University of Missouri--Kansas City","degree_name":"Ph.D. (Doctor of Philosophy)","degree_level":"Doctoral","degree_discipline":"Computer Science (UMKC)","degree_department":null,"school":null,"contributors":[],"advisors":["Nait-Abdesselam, Farid"],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025","date_published":"2025","updated_at":"2026-07-24T05:17:24Z","subjects":[],"languages":["en_US"],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/10355/112257","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Nait-Abdesselam, Farid"]},{"key":"dc:creator","label":"Author","values":["Razzazi, Harir"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2026-05-26T16:04:38Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2026-05-26T16:04:38Z"]},{"key":"dc:date.issued","label":"Date","values":["2025"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science (UMKC)"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Doctoral"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D. (Doctor of Philosophy)"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Missouri--Kansas City"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en_US"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10355/112257"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Title from PDF of title page, viewed May 28, 2026","Dissertation advisor: Farid Nait-Abdesselam","Vita","Includes bibliographical references (pages 124-137)","Dissertation (Ph.D)--Department of Computer Science and Electrical Engineering. University of Missouri--Kansas City, 2025"]},{"key":"dc:description.abstract","label":"Abstract","values":["The growing number of vehicles on modern roads has intensified challenges such as congestion, collisions, and fatalities, with abnormal driving behaviors, reckless, fatigued, or impaired, remaining leading causes. Vehicular networks, as a core component of intelligent transportation systems (ITS), enable real-time vehicle–infrastructure communication through Cooperative Awareness Messages (CAMs), offering opportunities to detect anomalies in both driving behavior and communication patterns.This dissertation proposes a dual-layer anomaly detection framework targeting: (1) unsafe driving behavior, and (2) Denial-of-Service (DoS) attacks in vehicular networks. For behavioral anomaly detection, spatial–temporal vehicle interactions are modeled as dynamic graphs and evaluated using six Graph Neural Network (GNN) architectures: Graph Convolutional Network (GCN), Graph Attention Network (GAT), GraphSAGE, Temporal GCN (T-GCN), Gated Convolutional LSTM (GConvLSTM), and Gated Convolutional GRU (GConvGRU). The GConvLSTM and GConvGRU models achieved the highest precision, recall, and F1-scores, with GraphSAGE and GAT providing competitive performance. To mitigate class imbalance, the Synthetic Minority Over-sampling Technique (SMOTE) improved recall, particularly for GCN and T-GCN. Performance was further enhanced by edge weight learning, which adaptively emphasized critical inter-vehicle relationships, and supervised triplet loss, which improved class separability. For communication-layer anomaly detection, a real-time, unsupervised framework was developed using a modified Online K-Means clustering algorithm integrated with outlier detection methods (One-Class SVM, Local Outlier Factor, Isolation Forest, and Elliptic Envelope). The proposed approach incorporates centroid repulsion, dynamic buffer normalization, and outlier-score-based thresholding, enabling adaptive detection without labeled data. Experiments on seven large-scale vehicular datasets generated with VSimRTI demonstrated that the modified Online K-Means, especially with One-Class SVM, consistently outperformed conventional clustering approaches in accuracy, adaptability, and efficiency. By addressing both behavioral and communication threats, this work advances the development of secure and resilient vehicular networks. The framework’s combination of interpretable GNN-based modeling and scalable online clustering contributes toward safer, more reliable connected and autonomous transportation systems."]},{"key":"dc:title","label":"Title","values":["Graph neural network approaches and real-time unsupervised learning for anomaly detection in vehicular networks"]}]}],"canonical_facts":{"dc:contributor.advisor":["Nait-Abdesselam, Farid"],"dc:creator":["Razzazi, Harir"],"dc:date.accessioned":["2026-05-26T16:04:38Z"],"dc:date.available":["2026-05-26T16:04:38Z"],"dc:date.issued":["2025"],"dc:description":["Title from PDF of title page, viewed May 28, 2026","Dissertation advisor: Farid Nait-Abdesselam","Vita","Includes bibliographical references (pages 124-137)","Dissertation (Ph.D)--Department of Computer Science and Electrical Engineering. University of Missouri--Kansas City, 2025"],"dc:description.abstract":["The growing number of vehicles on modern roads has intensified challenges such as congestion, collisions, and fatalities, with abnormal driving behaviors, reckless, fatigued, or impaired, remaining leading causes. Vehicular networks, as a core component of intelligent transportation systems (ITS), enable real-time vehicle–infrastructure communication through Cooperative Awareness Messages (CAMs), offering opportunities to detect anomalies in both driving behavior and communication patterns.This dissertation proposes a dual-layer anomaly detection framework targeting: (1) unsafe driving behavior, and (2) Denial-of-Service (DoS) attacks in vehicular networks. For behavioral anomaly detection, spatial–temporal vehicle interactions are modeled as dynamic graphs and evaluated using six Graph Neural Network (GNN) architectures: Graph Convolutional Network (GCN), Graph Attention Network (GAT), GraphSAGE, Temporal GCN (T-GCN), Gated Convolutional LSTM (GConvLSTM), and Gated Convolutional GRU (GConvGRU). The GConvLSTM and GConvGRU models achieved the highest precision, recall, and F1-scores, with GraphSAGE and GAT providing competitive performance. To mitigate class imbalance, the Synthetic Minority Over-sampling Technique (SMOTE) improved recall, particularly for GCN and T-GCN. Performance was further enhanced by edge weight learning, which adaptively emphasized critical inter-vehicle relationships, and supervised triplet loss, which improved class separability. For communication-layer anomaly detection, a real-time, unsupervised framework was developed using a modified Online K-Means clustering algorithm integrated with outlier detection methods (One-Class SVM, Local Outlier Factor, Isolation Forest, and Elliptic Envelope). The proposed approach incorporates centroid repulsion, dynamic buffer normalization, and outlier-score-based thresholding, enabling adaptive detection without labeled data. Experiments on seven large-scale vehicular datasets generated with VSimRTI demonstrated that the modified Online K-Means, especially with One-Class SVM, consistently outperformed conventional clustering approaches in accuracy, adaptability, and efficiency. By addressing both behavioral and communication threats, this work advances the development of secure and resilient vehicular networks. The framework’s combination of interpretable GNN-based modeling and scalable online clustering contributes toward safer, more reliable connected and autonomous transportation systems."],"dc:identifier.uri":["https://hdl.handle.net/10355/112257"],"dc:language.iso":["en_US"],"dc:title":["Graph neural network approaches and real-time unsupervised learning for anomaly detection in vehicular networks"],"dc:type":["Thesis"],"thesis:degree_discipline":["Computer Science (UMKC)"],"thesis:degree_level":["Doctoral"],"thesis:degree_name":["Ph.D. (Doctor of Philosophy)"],"thesis:institution_name":["University of Missouri--Kansas City"]},"updated_at":"2026-07-24T05:17:24Z"}