arXiv:2506.10620cs.CRcs.LG2025-06被引 4

研究汽车入侵检测系统如何被对抗攻击绕过,揭示安全漏洞。

Assessing the Resilience of Automotive Intrusion Detection Systems to Adversarial Manipulation

  • 用梯度攻击模拟不同掌握程度的黑客,测试系统脆弱性。
  • 黑盒攻击仍可成功绕过主流检测模型,成功率与数据集质量相关。
  • 实测表明攻击可在车载网络实时部署,威胁真实车辆安全。

现代车辆的安全日益重要,控制器局域网(CAN)总线作为电子控制单元间通信的核心,因缺乏有效安全机制且连接性增强,易受网络攻击。尽管已开发入侵检测系统(IDS)应对威胁,但其仍存在缺陷。本文扩展前期工作,研究基于梯度的对抗攻击在不同知识掌握程度下对汽车IDS的有效性。考虑三种场景:白盒(完全了解系统)、灰盒(部分了解)和更现实的黑盒(无系统内部信息)。在两个公开数据集上评估攻击对先进IDS的效果,并分析对抗扰动对攻击影响,同时通过预计算可时序注入的逃避载荷,检验实时可行性。结果表明,攻击虽受车载环境约束难度较高,但有效性高度依赖数据集质量、目标检测模型及攻击者知识水平。

原文摘要 · Abstract (English)

The security of modern vehicles has become increasingly important, with the controller area network (CAN) bus serving as a critical communication backbone for various Electronic Control Units (ECUs). The absence of robust security measures in CAN, coupled with the increasing connectivity of vehicles, makes them susceptible to cyberattacks. While intrusion detection systems (IDSs) have been developed to counter such threats, they are not foolproof. Adversarial attacks, particularly evasion attacks, can manipulate inputs to bypass detection by IDSs. This paper extends our previous work by investigating the feasibility and impact of gradient-based adversarial attacks performed with different degrees of knowledge against automotive IDSs. We consider three scenarios: white-box (attacker with full system knowledge), grey-box (partial system knowledge), and the more realistic black-box (no knowledge of the IDS' internal workings or data). We evaluate the effectiveness of the proposed attacks against state-of-the-art IDSs on two publicly available datasets. Additionally, we study effect of the adversarial perturbation on the attack impact and evaluate real-time feasibility by precomputing evasive payloads for timed injection based on bus traffic. Our results demonstrate that, besides attacks being challenging due to the automotive domain constraints, their effectiveness is strongly dependent on the dataset quality, the target IDS, and the attacker's degree of knowledge.

汽车安全对抗攻击入侵检测黑盒攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。