Jul 2026· Italian National Conference on Sensors· Vol 26· 0 citations· 31 references
Medicine
Abstract
As intelligent connected vehicles (ICVs) integrate advanced driver-assistance systems (ADAS) and autonomous-driving functions, CAN bus attacks have become more diverse in mechanism and safety impact. Beyond flooding or direct command injection, state-inducing spoofing attacks inject falsified CAN frames to manipulate vehicle-state signals. Rather than directly controlling vehicle behavior, they mislead ADAS state estimation, potentially triggering inappropriate control responses and threatening driving safety. Existing intrusion detection methods mainly target conventional CAN attacks and limited operating states, leaving limited detection generalization in complex attack scenarios. Accordingly, this paper proposes MTFF, a multi-scale temporal feature fusion framework for CAN intrusion detection. MTFF builds two complementary CAN streams: an intra-ID kinematic sequence capturing short-term state continuity under the same identifier and an inter-ID scheduling sequence capturing timing relationships among neighboring frames, thereby characterizing CAN traffic from state-continuity and scheduling-relation perspectives. Multi-scale 1-D convolutions extract local temporal features, while positional self-attention and symmetric cross-attention model long-range dependencies and fuse the streams to detect contextual temporal and state inconsistencies. Experiments on multi-vehicle CAN datasets covering representative operating states show that, in the most challenging setting, MTFF achieves F1-scores above 0.94 on two production vehicles, with per-frame latency below 0.006 ms.
A DT-based IDS that jointly models physical relationships among decoded powertrain signals and identifies attacks through residuals between predicted and observed behavior shows promise for detecting stealthy payload-level CAN attacks that preserve normal communication patterns, supporting behavior-based cybersecurity for connected and automated vehicles.
Araf Rahman, M. Salek, Mashrur Chowdhury· 0 citations
Cloud-enabled Intelligent Transportation Systems (ITS) leverage Vehicle-to-Everything (V2X) communications to support scalable data processing and real-time traffic management. However, this integration significantly expands the cyber-physical attack surface. Conventional intrusion detection systems (IDSs) that rely on static signatures or offline-trained models are often ill-suited to counter adaptive attackers. This paper presents the Adaptive Stackelberg Defense Scheme (ASDS), a proactive intrusion detection system that models attacker-defender interactions as a hierarchical Bayesian Stackelberg game with incomplete information. ASDS employs Bayesian filtering to jointly estimate system states and attacker types in real time, enabling adaptive defense strategies. Evaluated against False Data Injection (FDI), Denial-of-Service (DoS), and spoofing attacks, ASDS achieves detection accuracy between 94% and 98%, false positive rates ranging from 0.02 to 0.08, and response latency under 50 ms. These results underscore its effectiveness in securing cloud-enabled ITS environments.
Emmanuel Kigmo Yonga, Mounirah Djam-Doudou, J. Emati et al.· 2026 6th International Confe...· 0 citations
Per-ID behavioral residualization is presented, a CAN-specific representation that extracts fourteen temporal, protocol, and payload features from sliding windows and residualizes them against each arbitration ID's normal baseline, which improves mean F1 in the majority of evaluations.
Vehicular Ad-Hoc Networks (VANETs) enable realtime communication for safety-critical applications including collision avoidance and traffic control. Their decentralized, dynamic architecture, however, makes them vulnerable to multiple attack classes, including Sybil, spoofing, Denial-of-Service (DoS), and other cyber threats. Existing defenses typically address cyber and physical layers independently, limiting their ability to capture the interplay between mobility patterns and attack propagation. This paper presents a cyber-physical simulation framework integrating vehicular mobility with the CybORG environment for multi-class attack mitigation. A Road Side Unit (RSU) acts as the infrastructure-based defender, monitoring vehicle behavior, maintaining trust scores, and executing defense actions via a Dueling Double Deep Q-Network with Prioritized Experience Replay (D3QN-PER). The agent learns optimal policies through environment interaction rather than static labeled data. Evaluation against two unsupervised baselines, Exponentially Weighted Moving Average (EWMA) and Trust-Gated Isolation Forest, demonstrates perfect detection performance (Recall = 100%, $\mathbf{F} \mathbf{1} \boldsymbol{=} \mathbf{1. 0 0 0 0})$ with zero false positives and zero false negatives, compared to 95.12% recall (EWMA) and 84.95% recall (Isolation Forest). The framework handles up to six concurrent attackers within the RSU's 200 m range with sub-millisecond latency, establishing a foundation for intelligent, adaptive security in vehicular networks.
Fasna Nadeera Irumpidamkandiyil Pocker, Farsana Ansari, Alexandre dos Santos Roque et al.· International Conference on...· 0 citations
Remote state estimation plays an important role in connected vehicle platoons, industrial automation systems, and other networked Cyber-Physical Systems (CPSs), where reliable state information is essential for monitoring, feedback control, and decision-making. However, due to the openness and unreliability of wireless communication links, remote estimation systems are vulnerable to eavesdropping and Denial-of-Service (DoS) attacks, which may cause information leakage, packet loss, and estimation performance degradation. This issue becomes more critical in time-varying wireless environments, where channel conditions and attack opportunities evolve dynamically over time, making conventional static or periodic attack models insufficient for characterizing practical security risks. To address this problem, this paper investigates a utility-aware event-triggered reinforcement learning framework for hybrid attack scheduling against remote state estimation over time-varying wireless channels. The attacker can select among eavesdropping, DoS, and silence actions to balance estimation disruption, information acquisition, and attack resource consumption. The hybrid attack scheduling problem is formulated as a partially observable Markov decision process (POMDP), and a utility-aware event-triggered mechanism is designed to activate attack decisions only when the estimated attack utility is sufficiently significant. At the triggered decision instants, a proximal policy optimization (PPO) algorithm is employed to learn an adaptive hybrid attack mode selection policy. The structural properties of the resulting policy are also analyzed theoretically, showing that the optimal belief-space policy has a piecewise constant structure and that the proposed adaptive threshold preserves a monotone triggering property with respect to the attack utility indicator. Simulation results in a connected vehicle platoon scenario demonstrate that, compared with several benchmark methods, the proposed method achieves a better trade-off among remote estimation degradation, attacker-side information acquisition, and energy consumption. These results indicate that the proposed event-triggered reinforcement learning framework can improve the adaptability and resource efficiency of hybrid attack scheduling under time-varying wireless channels. The study also provides useful insights for security vulnerability assessment, resilient estimation design, and defense strategy development for practical remote estimation systems.
Jieyao An, Heng Zhang· ISA transactions· 0 citations