Skip to content
Conference

A Progressive Machine Learning Framework for Intrusion Prevention in Controller Area Networks: Multi-Scenario Evaluation for Secure Automotive Systems

Aug 2026 · 2026 6th International Conference on Emerging Smart Technologies and Applications (eSmarTA) · pp. 1-12 · 0 citations · 50 references

Abstract

Modern vehicles rely heavily on in-vehicle Controller Area Network (CAN) communication to coordinate safety-critical electronic control units (ECUs). However, the CAN protocol was not originally designed with authentication, encryption, or message integrity mechanisms, making it vulnerable to injection, spoofing, fuzzy, and denial-of-service attacks. Although machine learning-based intrusion detection systems have achieved high detection accuracy on CAN traffic, detection alone is not sufficient for safety-critical automotive environments where malicious messages may affect ECUs before a response is triggered. This paper presents a progressive machine learning-based framework for prevention-oriented CAN bus security. The framework analyzes statistical and temporal CAN traffic features and evaluates multiple machine learning models under three scenarios: binary attack detection, attack-type classification, and prevention-oriented allow/block decision evaluation. The study uses the Car-Hacking dataset and compares several supervised and anomaly-detection models, including tree-based ensembles, linear models, probabilistic models, neural models, and anomaly detectors. The results show that tree-based models achieve the strongest overall performance, with Random Forest reaching 99.6% accuracy in binary detection. The proposed prevention layer is evaluated as a software-level decision mechanism that converts model outputs into allow/block decisions, while CAN-aware blocking mechanisms are discussed only as architectural deployment options for future inline gateway implementation. The findings indicate that lightweight tree-based machine learning models can support real-time prevention-oriented decisions in CAN security, while further validation on hardware testbeds, realistic CAN bus-load conditions, and cross-dataset settings remains necessary.

View source

Similar papers

Review Open access Aug 2026

A Machine Learning-Based Intrusion Detection Framework for Enhanced Network Security

This review presents a comprehensive analysis of machine learning-based intrusion detection systems, covering a wide range of techniques including supervised learning, unsupervised learning, ensemble learning, and deep learning models, and discusses critical challenges affecting the deployment of ML-based IDS.

Ranobir Hasan, H. Jamal, Kamal Kamal et al. · 0 citations
Open access Jul 2026

Deep-Learning Intrusion Detection for Connected and Autonomous Vehicles

A hybrid deep-learning intrusion detection system (IDS) that combines one-dimensional convolutional layers, a bidirectional long short-term memory (BiLSTM) network, and a temporal attention mechanism to detect malicious activity directly from CAN frame streams is presented.

Ginne M James · 0 citations
Conference Jul 2026

SEPIV-IDS: A Structured Evaluation Pipeline for In-Vehicle Intrusion Detection Systems

Critical safety functions in modern vehicles rely heavily on intra-vehicle networks (IVNs), primarily via the Controller Area Network (CAN) protocol. The inherent vulnerabilities of CAN require robust intrusion detection systems (IDS) to mitigate adversarial threats. However, state-of-the-art IDS, especially AI-based approaches, often lack a comprehensive, well-defined performance analysis method. This work proposes and evaluates a structured pipeline for in-vehicle IDS, analyzing an autoencoder semi-supervised IDS as a practical case study. The method is validated on publicly available datasets, covering multiple attack types, with additional analysis of generalization capabilities. Performance is rigorously assessed using precision, recall, F1-score, and the Matthews Correlation Coefficient (MCC), chosen for its robustness in imbalanced scenarios. Results demonstrated highly efficient identification of DoS attacks (MCC 1.00), though Fuzzy DoS detection showed lower performance (MCC 0.214 in CAN-MIRGU and 0.074 in CAN-MODES). These findings support the viability of the proposed pipeline for IDS analysis focusing on enhancing CAN network security, consistent with recent research trends.

Lucas da Silva Alves, Alexandre dos Santos Roque, E. P. de Freitas · 0 citations
Jul 2026

Comparative Study of Machine Learning Models for Intrusion Detection in SCADA Communication Based on IEC 60870-5-104

IEC 60870-5-104 (IEC-104) is widely deployed in SCADA-based power systems to transport telecontrol messages over TCP/IP. While improving interoperability, this connectivity expands the cyber attack surface and enables threats targeting both availability and integrity. This paper presents a comparative evaluation of supervised machine learning (ML) models for intrusion detection on IEC-104 communication using a laboratory SCADA testbed and labeled datasets derived from packet captures. Three representative scenarios are considered: SYN Flood targeting TCP port 2404 (Layer 4 denial-of-service), APDU Flood at the application layer (Layer 7 denial-ofservice), and Control Command Injection Attack (CCIA) via man-in-the-middle command manipulation (integrity attack). Features are extracted using TShark and combine transport/network indicators with IEC-104-aware attributes (APDU length, I/S/U frame type, ASDU Type ID, Cause of Transmission, and IOA), consistent with the importance of protocol-aware inspection in IEC-104 IDS research. Evaluation uses stratified random record-level splitting for SYN Flood due to limited sample size and time-based hold-out validation for the combined APDU+CCIA dataset to assess temporal generalization. Results show that SYN Flood is detected reliably with tuned SVM achieving 85.57% accuracy and perfect recall (100%). Under time-based validation on APDU+CCIA, overall performance remains high (accuracy 98.54%-99.39%) and APDU Flood detection is near-perfect (accuracy 99.02%-99.87%), whereas CCIA detection accuracy $(\mathbf{5 2. 3 0 \% - 6 0. 6 2 \%})$ remains substantially lower, indicating the need for richer semantic and temporal features for integrity-focused anomalies in IEC-104 traffic.

Sofyan Asyzauri, A. Affandi, P. H. Mukti et al. · 0 citations
Open access Aug 2026

Hybrid lightweight machine learning framework for intrusion detection and mitigation in military wireless sensor networks

Modern militaries rely heavily on Wireless Sensor Networks (WSNs) for a variety of tasks, including border security, tactical communications, drone coordination, vital infrastructure protection, and combat observation. Such networks enable secure data transmission in hostile environments while providing real-time situational awareness. However, due to limited computational resources, memory constraints, and battery dependency, WSNs are highly vulnerable to security threats such as node impersonation, Sybil attacks, replay attacks, false data injection, and message tampering. These attacks can significantly disrupt mission-critical operations and compromise sensitive military information. To address these challenges, this article proposes a Hybrid Lightweight Machine Learning-Based Intrusion Detection and Mitigation System (HL-ML-IDS) for Military Wireless Sensor Networks (MWSNs). The proposed framework combines anomaly based and signature-based detection techniques to achieve high intrusion detection accuracy with low computational overhead, making it suitable for resource-constrained military environments. The framework incorporates energy-efficient preprocessing, lightweight feature selection, adaptive threat analysis, dynamic rule generation, and an intrusion mitigation mechanism that isolates compromised nodes to prevent attack propagation. Experimental results demonstrate the effectiveness of the proposed HL-ML-IDS framework, achieving a 35% reduction in energy consumption and a 28% decrease in the false-positive rate. The framework attains a detection rate of 97.2%, precision of 96.4%, recall of 95.8%, and an F1-score of 94.9%, confirming its capability to provide secure, reliable, and energy-efficient intrusion detection and mitigation in MWSNs.

Venkateswari P, S. N · 0 citations
Preprint Aug 2026

Behavioral Residualization for Unsupervised Intrusion Detection in Automotive CAN Networks

Per-ID behavioral residualization is presented, a CAN-specific representation that extracts fourteen temporal, protocol, and payload features from sliding windows and residualizes them against each arbitration ID's normal baseline, which improves mean F1 in the majority of evaluations.

Chandan Hegde, M. R. Reddy · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.