arXiv:2506.06556cs.LGcs.CR2025-06被引 1

用SDN+LSTM实时检测汽车网络假数据攻击并有效防御。

SDN-Based False Data Detection With Its Mitigation and Machine Learning Robustness for In-Vehicle Networks

  • 基于SDN架构与LSTM模型,实时监测刹车相关ECU通信
  • 在四种对抗攻击下仍保持90%以上检测准确率
  • 适合车联网安全研究者与汽车网络安全工程师

随着自动驾驶与网联汽车的发展,现代车辆中集成的电子控制单元(ECUs)数量激增。车载网络中各ECU通过控制器局域网(CAN)协议通信,保障其安全至关重要。本文提出一种基于软件定义网络(SDN)的假数据检测与缓解系统(FDDMS),用于在车载网络中实时检测假数据注入攻击。重点针对制动相关ECU,在SDN环境中构建攻击模型以分析假数据注入机制。系统采用基于长短期记忆(LSTM)的检测模型识别攻击行为,并引入一种改进的DeepFool攻击评估模型鲁棒性。为应对快速梯度法、基本迭代法、DeepFool及其变体等四类对抗攻击,提出基于阈值选择的再训练增强策略。最后,通过动态更新流规则实现攻击流量的实时重定向。实验表明,所提FDDMS在面对多种对抗攻击时仍具备高鲁棒性,能有效实现假数据攻击的实时检测与缓解。

原文摘要 · Abstract (English)

As the development of autonomous and connected vehicles advances, the complexity of modern vehicles increases, with numerous Electronic Control Units (ECUs) integrated into the system. In an in-vehicle network, these ECUs communicate with one another using an standard protocol called Controller Area Network (CAN). Securing communication among ECUs plays a vital role in maintaining the safety and security of the vehicle. This paper proposes a robust SDN-based False Data Detection and Mitigation System (FDDMS) for in-vehicle networks. Leveraging the unique capabilities of Software-Defined Networking (SDN), FDDMS is designed to monitor and detect false data injection attacks in real-time. Specifically, we focus on brake-related ECUs within an SDN-enabled in-vehicle network. First, we decode raw CAN data to create an attack model that illustrates how false data can be injected into the system. Then, FDDMS, incorporating a Long Short Term Memory (LSTM)-based detection model, is used to identify false data injection attacks. We further propose an effective variant of DeepFool attack to evaluate the model's robustness. To countermeasure the impacts of four adversarial attacks including Fast gradient descent method, Basic iterative method, DeepFool, and the DeepFool variant, we further enhance a re-training technique method with a threshold based selection strategy. Finally, a mitigation scheme is implemented to redirect attack traffic by dynamically updating flow rules through SDN. Our experimental results show that the proposed FDDMS is robust against adversarial attacks and effectively detects and mitigates false data injection attacks in real-time.

车载网络攻击检测SDN

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。