CANEDERLI: On The Impact of Adversarial Training and Transferability on CAN Intrusion Detection Systems

Francesco Marchiori,Mauro Conti
DOI: https://doi.org/10.1145/3649403.3656486
2024-04-06
Abstract:The growing integration of vehicles with external networks has led to a surge in attacks targeting their Controller Area Network (CAN) internal bus. As a countermeasure, various Intrusion Detection Systems (IDSs) have been suggested in the literature to prevent and mitigate these threats. With the increasing volume of data facilitated by the integration of Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) communication networks, most of these systems rely on data-driven approaches such as Machine Learning (ML) and Deep Learning (DL) models. However, these systems are susceptible to adversarial evasion attacks. While many researchers have explored this vulnerability, their studies often involve unrealistic assumptions, lack consideration for a realistic threat model, and fail to provide effective solutions.
Cryptography and Security
What problem does this paper attempt to address?
The problem that this paper attempts to solve is that the intrusion detection systems (IDS) in modern vehicle internal networks (especially the Controller Area Network, CAN bus) are vulnerable to adversarial attacks. Specifically, the paper mainly focuses on the following aspects: 1. **Threats of Adversarial Attacks**: - The increased integration of modern vehicles with external networks has led to an increase in attacks on the CAN bus. - Although traditional machine - learning (ML) - and deep - learning (DL) - based IDS are effective, they are vulnerable to adversarial attacks. 2. **Limitations of Existing Research**: - Many studies rely on unrealistic assumptions when evaluating adversarial attacks and lack consideration of real - world threat models. - There is a lack of effective solutions to deal with these attacks, especially with unclear performance in practical applications. 3. **Transferability of Adversarial Attacks**: - The transferability problem of adversarial samples between different models and attack methods has not been fully studied, which poses a potential threat to the actually deployed IDS. 4. **Effectiveness of Adversarial Training**: - Existing adversarial training methods (such as fine - tuning) may reduce the basic performance of the model while improving its robustness, affecting normal operations. To solve these problems, the paper proposes a new framework named CANEDERLI, aiming to evaluate and enhance the ability of CAN - bus - based IDS to resist adversarial attacks. Specific contributions include: - Proposing a new framework for evaluating the transferability of adversarial attacks and the impact of adversarial training. - Introducing an adaptive online adversarial training technique that goes beyond the traditional fine - tuning method and improves the F1 score (up to 0.941) while maintaining high accuracy. - Conducting a comprehensive evaluation on real - world datasets, covering multiple state - of - the - art attack methods and model architectures. - Open - sourcing the framework code, enabling researchers and practitioners to better evaluate the robustness of IDS. Through these efforts, CANEDERLI aims to provide a more realistic and effective solution to deal with the threat of adversarial attacks faced by IDS in modern vehicle networks.