用流量数据识别网络攻击,提升智能交通安全性
Explainable Machine Learning for Cyberattack Identification from Traffic Flows
- 基于深度学习分析流量模式,识别信号灯异常
- 发现最长停驶时间和总拥堵距离是关键攻击指标
- 结合可解释AI诊断误判原因,适合交通安全部门使用
交通管理系统自动化程度提高,易受网络攻击影响,威胁城市出行与公共安全。传统网络层防御对交通机构不可用,因此需仅依赖流量数据的机器学习方法。本研究在半真实环境中模拟攻击,通过虚拟交通网络分析扰动模式。开发基于深度学习的异常检测系统,证实最长停驶时间和总拥堵距离是信号灯被攻破的关键指标。为提升可解释性,采用可解释人工智能(XAI)技术,识别关键决策因素并诊断误分类错误。分析揭示两大挑战:过渡期数据不一致导致恢复阶段流量误标误导模型;低流量条件下隐蔽攻击难以被检测。该研究提升了基于AI的交通网络安全能力,增强检测准确率与系统可信度。
原文摘要 · Abstract (English)
The increasing automation of traffic management systems has made them prime targets for cyberattacks, disrupting urban mobility and public safety. Traditional network-layer defenses are often inaccessible to transportation agencies, necessitating a machine learning-based approach that relies solely on traffic flow data. In this study, we simulate cyberattacks in a semi-realistic environment, using a virtualized traffic network to analyze disruption patterns. We develop a deep learning-based anomaly detection system, demonstrating that Longest Stop Duration and Total Jam Distance are key indicators of compromised signals. To enhance interpretability, we apply Explainable AI (XAI) techniques, identifying critical decision factors and diagnosing misclassification errors. Our analysis reveals two primary challenges: transitional data inconsistencies, where mislabeled recovery-phase traffic misleads the model, and model limitations, where stealth attacks in low-traffic conditions evade detection. This work enhances AI-driven traffic security, improving both detection accuracy and trustworthiness in smart transportation systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。