arXiv:2606. 18599v1 Announce Type: cross Abstract: The Controller Area Network (CAN) protocol is the primary communication standard for Electronic Control Units (ECUs) in modern vehicles, but its lack of encryption and authentication exposes it to a range of security threats.
By Qiqi Liu, Runhan Song, Lei Cui, Heng Zhang, Yuyan Sun, Limin Sun
arXiv:2606. 30430v1 Announce Type: cross Abstract: The increasing connectivity of modern vehicles has made securing in-vehicle communication networks a critical challenge.
By Beatrix Koltai, Gergely Acs, Andras Gazdag
The paper presents a digital‑twin (DT) based intrusion detection system (IDS) for vehicle powertrain CAN bus traffic, modeling physical relationships among decoded signals to detect payload‑manipulation attacks that preserve normal timing and sequencing. Using a shared‑encoder LSTM trained on 17 Hyundai/Kia CAN signals, the DT flags anomalies when residuals exceed a threshold, achieving high detection rates (up to 94.6%) for stealthy attacks such as continuous drift and masquerade, while a range‑and‑plausibility baseline fails to detect them. The study demonstrates that learning coupled vehicle dynamics enables detection of payload‑level attacks that evade traditional timing‑based IDSs, though false positives remain a challenge.
By Araf Rahman, M Sabbir Salek, Mashrur Chowdhury
The paper introduces SPADE, a labelled, multi‑modal dataset for detecting attacks on Signal Phase and Timing (SPaT) messages from the perspective of connected vehicles. Generated via Eclipse MOSAIC, SPADE includes 1.89 million timestep records across six attack classes and one benign class, combining SPaT fields, camera confidence scores, and V2V peer data over 40 features. The dataset, along with generation code and scenario configurations, is publicly released on GitHub to enable reproducible deep‑learning intrusion detection research in C‑V2X security.
By James Di Novo, Hany Ragab, Sylvain P. Leblanc
Existing automotive intrusion detection systems (IDSs) for the Controller Area Network (CAN) largely target discrepancies in message timing, frequency, or sequencing and cannot detect attacks that pre...
SPADE is a labelled, multi‑modal, simulation‑based dataset for detecting attacks on Signal Phase and Timing (SPaT) messages from the perspective of connected vehicles. It contains 1.89 million timestep records generated by injecting six classes of application‑layer attacks and one benign class into the SAE J2735 SPaT protocol, across multiple intersection geometries, operating conditions, and random seeds. Each record fuses SPaT fields, onboard camera confidence scores, and cooperative V2V peer data into 40 features, enabling deep‑learning intrusion detection systems to distinguish deliberate attacks from environmental noise.
arXiv:2606. 11098v1 Announce Type: cross Abstract: Recent deep learning approaches for network intrusion detection increasingly incorporate temporal architectures such as recurrent networks and Transformers, often reporting near-perfect performance on CIC-IDS2017.
By Zach Moczkodan (Royal Military College of Canada, Kingston, Canada), Hany Ragab (Royal Military College of Canada, Kingston, Canada)
Recent deep learning approaches for network intrusion detection increasingly incorporate temporal architectures such as recurrent networks and Transformers, often reporting near-perfect performance on CIC-IDS2017. However, many existing studies neither supply their temporal modules with genuine sequence inputs nor evaluate under realistic, leakage-free conditions, making it unclear whether reported gains arise from true sequence-modeling capability.
The paper investigates how privacy guarantees, robustness to Byzantine attacks, and detection coverage for rare intrusion types interact in federated network intrusion detection systems. It introduces geometric indistinguishability to explain how privacy noise can obscure minority-class signals, and demonstrates through experiments on UNSW‑NB15 that combining differential privacy with robust aggregation can disproportionately harm detection of rare attacks. The study highlights that these properties cannot be treated as independently composable and calls for aggregation‑aware modeling and sample‑aware evaluation to build trustworthy federated NIDS.
By Adrita Rahman Tory, ABM Shawkat Ali, Md Abu Layek, Khondokar Fida Hasan
arXiv:2608.17445v2 Announce Type: replace-cross
Abstract: Most large language model services use stateless defenses, which judge only the current request, to refuse harmful tasks. Decomposition attac...
By Bowen Sun, Zhengyue Zhao, Xiaogeng Liu, Yinzhi Cao, Chaowei Xiao
arXiv:2606. 28439v1 Announce Type: cross Abstract: Deep neural networks (DNNs) are widely applied in Network-based Intrusion Detection System (NIDS) due to their high accuracy.
By Jinhao You, Zan Zhou, Shujie Yang, Yi Sun, Lei Zhang, Changqiao Xu
arXiv:2601. 00389v2 Announce Type: replace-cross Abstract: Timing and burst patterns can leak through encryption, and an adaptive adversary can exploit them.
By Muhammad Bilal, Omer Tariq, Hasan Ahmed