详细信息
Federated Graph Neural Network for Fast Anomaly Detection in Controller Area Networks ( SCI-EXPANDED收录 EI收录)
文献类型:期刊文献
英文题名:Federated Graph Neural Network for Fast Anomaly Detection in Controller Area Networks
作者:Zhang, Hengrun[1];Zeng, Kai[2];Lin, Shuai[3]
机构:[1]East China Univ Sci & Technol, Dept Comp Sci & Engn, Shanghai, Peoples R China;[2]George Mason Univ, Dept Elect & Comp Engn, Fairfax, VA 22030 USA;[3]Shanghai Inst Technol, Sch Econ & Management, Shanghai, Peoples R China
年份:2023
卷号:18
起止页码:1566
外文期刊名:IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY
收录:;EI(收录号:20230813624439);WOS:【SCI-EXPANDED(收录号:WOS:000945173500002)】;
基金:This work was supported in part by the Commonwealth Cyber Initiative (CCI) (cyberinitiative.org) and its Northern Virginia (NOVA) Node, an Investment in the Advancement of Cyber Research and Development, Innovation, and Workforce Development.
语种:英文
外文关键词:Intrusion detection; Anomaly detection; Training; Electronic mail; Delays; Data privacy; Data models; CAN bus intrusion detection; graph neural network; two-stage classifier cascade; federated learning
摘要:Due to the lack of CAN frame encryption and authentication, CAN bus is vulnerable to various attacks, which can in general be divided into message injection, suspension, and falsification. Existing CAN bus anomaly detection mechanisms either can only detect one or two of these attacks, or require numerous CAN messages during predictions, which can hardly realize real-time performance. In this paper, we propose a CAN bus anomaly detection system that can detect all these attacks simultaneously in as short as 3 milliseconds (ms) based on Graph Neural Network (GNN). This work generates directed attributed graphs based on CAN message streams in given message intervals. Node attributes denote data contents in CAN messages while each edge attribute represents the frequency of a typical CAN ID pair in the given interval. Afterwards, a GNN is trained based on generated CAN message graphs. Considering highly imbalanced training data, a two-stage classifier cascade is developed in this paper, which is composed of a one-class classifier for anomaly detection and a multi-class classifier for attack classification. An openmax layer is further introduced to the multi-class classifier to tackle new anomalies from unknown classes. To take advantage of crowdsourcing while protecting user data privacy, we adopt federated learning to train a universal model that covers different driving scenarios and vehicle states. Extensive experiment results show the effectiveness and efficiency of our methodology.
参考文献:
正在载入数据...
