LSF-IDM: Deep learning-based lightweight semantic fusion intrusion detection model for automotive
Cheng, Pengzhou
DOI: https://doi.org/10.1007/s12083-024-01679-x
IF: 3.488
2024-06-07
Peer-to-Peer Networking and Applications
Abstract:Controller Area Network (CAN) is increasing connectivity to the external environment for intelligent interconnection in autonomous vehicles, as well as posing serious vulnerability from various attacks due to the lack of CAN frame encryption and authentication. Existing Deep Learning (DL)-based intrusion detection models cannot satisfy the balance between detection performance and efficiency, and have higher false alarms when the attack is concealed within a contextual feature. In this paper, we propose a lightweight intrusion detection model that can detect various attacks in real time based on semantic fusion, named LSF-IDM. This model first captures the context as the semantic feature of messages by the Pre-trained Language Model (PLM). Afterward, the lightweight model (e.g., BiLSTM and DNN) learns the fused feature from an input packet's classification and its output distribution in PLM based on knowledge distillation. Also, a weight sampler and Focal Loss (FL) are applied in this work to alleviate the long tail effect spawned by the category imbalance. The extensive evaluation results on real-world car-hacking and ORNL intrusion datasets show that the proposed model provides enough performance and real-time competitiveness in attack detection.
computer science, information systems,telecommunications
What problem does this paper attempt to address?