arXiv:2608.17093cs.CRcs.LG2026-08

用数字孪生检测车载网络隐藏攻击,能发现不改变通信规律的篡改行为。

Digital Twin-Based Intrusion Detection for Vehicle Powertrain CAN Bus Systems

  • 构建共享编码器LSTM数字孪生,联合预测动力系统信号
  • 对篡改数据检测率达89.2%,远超传统方法
  • 适合关注车辆网络安全的工程师与研究者

现有车载控制器局域网(CAN)入侵检测系统主要依赖消息时序、频率或顺序差异,无法识别在保持这些特征的同时篡改报文内容的攻击。数字孪生(DT)曾用于模拟CAN流量和生成攻击场景,但尚未用于实际检测。本文提出基于数字孪生的入侵检测系统,通过建模解码后动力系统信号间的物理关联,利用预测值与实测值之间的残差识别攻击。采用共享编码器LSTM模型,在17个来自现代/起亚真实CAN日志的信号上训练,联合预测7个数值型和2个类别型档位信号,时间窗口为24步。当残差超过校准阈值即标记异常,自适应滚动机制防止输入历史被持续污染。评估了四种攻击(平台、持续漂移、伪装、档位伪装),结果表明:该方法在持续漂移攻击中达到94.6%检测率,伪装攻击达89.2%,而基线方法几乎未能检测任何伪造报文攻击。误报率39.6%,显示在持续攻击下仍需提升鲁棒性。研究证明,学习耦合车辆动态可有效识别隐蔽的报文级攻击,支持车联网与自动驾驶车辆的行为安全防护。

原文摘要 · Abstract (English)

Existing automotive intrusion detection systems (IDSs) for the Controller Area Network (CAN) largely target discrepancies in message timing, frequency, or sequencing and cannot detect attacks that preserve these properties while manipulating the payload. Digital twins (DTs) have been used to emulate CAN traffic and generate attack scenarios for IDS evaluation, but their use for intrusion detection remains unexplored. This study develops a DT-based IDS that jointly models physical relationships among decoded powertrain signals and identifies attacks through residuals between predicted and observed behavior. A shared-encoder LSTM DT was trained on 17 decoded signals from a real Hyundai/Kia CAN log to jointly predict seven numeric and two categorical gear signals over a 24-step window. A timestep is flagged when a residual exceeds a calibrated threshold, while adaptive rollout protects the twin's input history from sustained contamination. Four attacks (plateau, continuous drift, masquerade, and gear masquerade) were evaluated against the twin and a range-and-plausibility baseline. The DT outperformed the baseline across all attacks, achieving detection rates of 94.6% for continuous drift and 89.2% for masquerade, while the baseline detected almost none of the fabricated payload attacks. These results demonstrate that learning coupled vehicle dynamics enables detection of stealthy payload manipulations that preserve normal CAN communication patterns. False positive rates reached 39.6%, highlighting the need for improved robustness under sustained attacks. The DT-based IDS shows promise for detecting stealthy payload-level CAN attacks that preserve normal communication patterns, supporting behavior-based cybersecurity for connected and automated vehicles.

数字孪生入侵检测车载网络安全防护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。