用遗传算法优化级联结构,提升车载网络异常检测全面性
An Optimal Cascade Feature-Level Spatiotemporal Fusion Strategy for Anomaly Detection in CAN Bus
- 通过两级遗传算法优化级联架构融合时空特征
- 在CAR-HACKING数据集上实现100%攻击类型检测准确率
- 适合车联网安全防护与工业控制系统异常检测场景
智能交通系统在现代基础设施中至关重要,但车载控制器局域网(CAN)的广播特性带来安全风险。尽管已有大量机器学习模型用于检测CAN异常,现有方法缺乏鲁棒性评估,且因仅关注部分主导异常结构而无法全面检测攻击。为此,本文提出一种级联特征级时空融合框架,通过双参数遗传算法(2P-GA)优化的级联架构,整合空间与时间特征,覆盖所有主导异常结构。成对t检验表明,模型达到0.9987的AUC-ROC,表现出卓越的异常检测能力。空间模块使精确率提升约4%,时间模块弥补召回率损失,确保高真正例率。该框架在CAR-HACKING数据集上对所有攻击类型实现100%准确率,优于当前最先进方法。本研究为实际CAN安全挑战提供了验证过的鲁棒解决方案。
原文摘要 · Abstract (English)
Intelligent transportation systems (ITS) play a pivotal role in modern infrastructure but face security risks due to the broadcast-based nature of the in-vehicle Controller Area Network (CAN) buses. While numerous machine learning models and strategies have been proposed to detect CAN anomalies, existing approaches lack robustness evaluations and fail to comprehensively detect attacks due to shifting their focus on a subset of dominant structures of anomalies. To overcome these limitations, the current study proposes a cascade feature-level spatiotemporal fusion framework that integrates the spatial features and temporal features through a two-parameter genetic algorithm (2P-GA)-optimized cascade architecture to cover all dominant structures of anomalies. Extensive paired t-test analysis confirms that the model achieves an AUC-ROC of 0.9987, demonstrating robust anomaly detection capabilities. The Spatial Module improves the precision by approximately 4%, while the Temporal Module compensates for recall losses, ensuring high true positive rates. The proposed framework detects all attack types with 100% accuracy on the CAR-HACKING dataset, outperforming state-of-the-art methods. This study provides a validated, robust solution for real-world CAN security challenges.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。