作者
Haihang Zhao,Yi Wang,Anyu Cheng,Shanshan Wang,Yuan Jing,Hongrong Wang
摘要
Intrusion detection systems (IDS) for control area network (CAN) bus communication using deep learning models face threats from adversarial closed-box. attacks in the Internet of Vehicles (IoVs). Although watermark techniques are proposed as defences, they lack concealment and are vulnerable. Current watermark methods for time-series data-based applications need cloud-based verification and terminal-based generation, and they cannot meet real-time requirements with large resources. To address these issues, we propose a real-time gated recurrent units (GRUs) based IDS with for CAN bus communication via a novel dynamic label watermark (DLW) method. In detail, we design a multitask learning structure at the terminal side only to detect conventional intrusion attacks. At the same time, we propose a novel DLW method applied to time-series data to defend against adversarial closed-box. attacks. Experimental results show that for the detection of Denial of Service (DoS), revolutions per minute (RPM) spoofing, and fuzzing attacks, our model achieves 1.00000, 1.00000, and close to 1.00000 with the recall, accuracy, F1 score, and precision, respectively. For detection of gear spoofing, our model with the same metrics achieves 1.00000, which are 0.0882, 0.0001, 0.0459, and 0.0208 better than CANLite and the same as ConvLSTM-GNB. Finally, we construct a new adversarial closed-box. attack embedded with four attacks above to validate the resistance and performance of our model (achieving 116 KB code size), which is 58% smaller, 0.9%–35.7% faster, and 1.52%–10.5% improvement of same metrics compared to the baseline model (LSTM).